SE Radio 733: Max Corbridge on Securing AI Agents

SE Radio 733: Max Corbridge on Securing AI Agents

Max Corbridge, an ethical hacker and red teamer who is co-founder and CEO of Secure Agentics, speaks with SE Radio host Amey Ambade about how AI agents get attacked and what engineers can actually do to defend them. Drawing on years of offensive security work, Corbridge frames agents as a new and largely undefended attack surface: the industry has handed AI systems autonomy and the ability to act in the real world while carrying forward prompt injection, a flaw the frontier labs themselves describe as effectively unsolvable. He likens the moment to the early, lawless days of the web, when SQL injection was everywhere and adoption ran far ahead of security.

The conversation builds from first principles as Corbridge explains what separates an agent from ordinary software and why three properties make them hard to secure: they are non-deterministic, their language-model core can be coerced, and they are increasingly interconnected through MCP servers, other agents, databases, and email. Turning to the attack surface, Corbridge lays out his "lethal trifecta" (a vulnerable core, dense interconnection, and security tooling that has not caught up) and contrasts the decades of layered defenses protecting an ordinary email inbox with the thin protection around agents that take autonomous actions on critical systems.

The heart of the episode is defense. Corbridge orders practices by leverage: least-privilege access and privilege separation, sandboxing where feasible, imperfect-but-useful guardrails as one layer of defense in depth, and human-in-the-loop for irreversible actions (which he notes is contentious and does not scale). The discussion closes on detecting a compromised or drifting agent, the value of watching an agent's chain-of-thought reasoning alongside its actions, the open-source tooling landscape (including Corbridge's own project, Adrian), and his central advice: build security in proactively, define what good agent behavior looks like up front, and avoid bolting it on after agents have already spread across the business.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(739)

SE Radio 734: Sathiesh Veera on Engineering Data-Protection Guardrails with LLMs

SE Radio 734: Sathiesh Veera on Engineering Data-Protection Guardrails with LLMs

Sathiesh Veera, a GenAI Solutions Architect at At&T, speaks with host Brijesh Ammanath about the data-protection guardrails required when using LLMs. The core issue is that LLMs sit outside the cloud ...

19 Aug 42min

SE Radio 732: Jason Gorman on The Effective Use of AI For Software Development

SE Radio 732: Jason Gorman on The Effective Use of AI For Software Development

Jason Gorman, a software development expert and founder of Codemanship, joins host Giovanni Asproni to explore how best to use AI in software development. They start by considering how established tec...

5 Aug 57min

SE Radio 731: Sonali Varde on AI and the Engineering Manager Role

SE Radio 731: Sonali Varde on AI and the Engineering Manager Role

Sonali Varde, Senior Software Engineering Manager at LinkedIn, joins host Kanchan Shringi to discuss how AI is changing the role of the engineering manager. They explore how AI is showing up in day-to...

29 Jul 50min

SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents

SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents

Birgitta Boeckeler, a Distinguished Engineer and consultant focused on AI-assisted software delivery at Thoughtworks, joins host Priyanka Raghavan for a deep dive into harnesses for AI agents. The epi...

22 Jul 54min

SE Radio 729: Garth Mollett on AI Supply Chain Security

SE Radio 729: Garth Mollett on AI Supply Chain Security

Garth Mollet, Senior Principal Product Security Engineer and Technical Advisor for Product Security at Red Hat, joins host Robert Blumen for a discussion of AI supply chain security. They start with t...

15 Jul 48min

SE Radio 728: Clare Liguori on AWS Strands SDK for AI Agents

SE Radio 728: Clare Liguori on AWS Strands SDK for AI Agents

Clare Liguori, a Senior Principal Engineer who works on developer tooling and agentic AI at Amazon Web Services, speaks with host Sri Panyam about the Amazon Strands Agents SDK. This episode explores ...

8 Jul 1h 8min

SE Radio 727: Jeroen Janssens and Thijs Nieuwdorp on Using Polars

SE Radio 727: Jeroen Janssens and Thijs Nieuwdorp on Using Polars

Jeroen Janssens, Head of Developer Relations at Posit, and Thijs Nieuwdorp, a developer relations engineer at Polars, speak with host Gregory M. Kapfhammer about Polars, a Python package for transform...

2 Jul 1h 2min

Populært innen Fakta

fastlegen
dine-penger-pengeradet
relasjonspodden-med-dora-thorhallsdottir-kjersti-idem
treningspodden
rss-orjasater
foreldreradet
jakt-og-fiskepodden
rss-strid-de-norske-borgerkrigene
rss-kunsten-a-leve
tomprat-med-gunnar-tjomlid
rss-var-forste-kaffe
smart-forklart
fryktlos
mikkels-paskenotter
hverdagspsyken
sinnsyn
gravid-uke-for-uke
rss-impressions-2
hr-podden-2
dopet