Securing the Apps Everyone Is Building with Roi Nisimi and Yonatan Levi

Securing the Apps Everyone Is Building with Roi Nisimi and Yonatan Levi

What happens when your marketing team, your sales team, and the person down the hall can all ship a full app from a single prompt? And what is that app quietly connected to? In this episode, Ron sits down with Roi Nisimi, Principal Security Researcher, and Yonatan Levi, AI Security Researcher, of Orca Security. They built apps on the most popular AppGen platforms and then tried to break into them. Ron, Roi, and Yonatan get into what's really running behind a prompt-built app, and what Orca's team found when they went looking for trouble. In one case, a single misconfigured app gave them a way into every integration connected to the workspace. They also explain why Supabase has become a favorite of builders and attackers alike, and share the security questions they ask before sending a prompt. The bigger tension is speed. With no code review between the prompt and production, Roi argues that velocity has broken the threat models that security relied on for years. And when the agent makes every decision, nobody fully understands what was built, not even the security researchers.

Impactful Moments

00:00 - Introduction 02:15 - Busting the vibe coding myth 04:40 - Inside Orca's State of AI report 05:55 - The unpatched AI SDK problem 07:40 - What is AppGen? 10:20 - Who builds the backend? 12:25 - Inside Orca's AppGen hackathon 14:10 - Thinking like a citizen developer 15:15 - Who's really building these apps 19:25 - One misconfigured app, every integration exposed 20:45 - Why Supabase is the holy grail 23:00 - Checking your own exposure 24:30 - Why the SDLC is breaking down 26:55 - Prompting for a secure app 28:15 - Don't hand the agent every decision 31:20 - Staying sharp by never stopping learning 33:35 - From protecting environments to protecting apps

Links

Connect with Roi Nisimi on LinkedIn: https://www.linkedin.com/in/roinisimi/

Connect with Yonatan Levi on LinkedIn: https://www.linkedin.com/in/yonatan-levi-b22168258/

Register for Orca’s virtual Builder Exchange: https://orca.security/builder-exchange/?utm_source=HVN&utm_medium=3rd-part

Read the security findings in Orca’s 2026 State of AI Security Report: https://orca.security/lp/2026-state-of-ai-security-report/?utm_source=HVN&utm_medium=3rd-party

–

Check out our upcoming events: https://www.hackervalley.com/livestreams

Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

Become a sponsor of the show: https://hackervalley.com/work-with-us/

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(444)

Giving Your AI Agent Its Own Identity with Ashish Rajan

Giving Your AI Agent Its Own Identity with Ashish Rajan

Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techri...

30 Sep 32min

From Read Access to Admin with just an AI Agent

From Read Access to Admin with just an AI Agent

What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really ...

23 Sep 31min

Do You Know What Your Agent is Doing at 3AM? with Amir Ofek

Do You Know What Your Agent is Doing at 3AM? with Amir Ofek

Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to ma...

16 Sep 38min

Cloud Broke My World Before AI Did with Dr. Jay Abdullah

Cloud Broke My World Before AI Did with Dr. Jay Abdullah

Cybersecurity has survived cloud, mobile, and a dozen other "biggest disruptions of our lifetime," and each one felt unprecedented in the moment. In this episode, Ron sits down with Alyssa "Dr. Jay" A...

9 Sep 36min

The Dashboard Is Dead, Long Live the Harness with Myke Lyons

The Dashboard Is Dead, Long Live the Harness with Myke Lyons

Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode,...

1 Sep 35min

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and...

25 Aug 35min

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigatio...

19 Aug 34min

Populært innen Fakta

fastlegen
dine-penger-pengeradet
relasjonspodden-med-dora-thorhallsdottir-kjersti-idem
rss-strid
treningspodden
foreldreradet
rss-bisarr-historie
jakt-og-fiskepodden
rss-orjasater
rss-kunsten-a-leve
takk-og-lov-med-anine-kierulf
rss-impressions-2
fryktlos
gravid-uke-for-uke
sinnsyn
hverdagspsyken
mikkels-paskenotter
gode-dager
lederskap-nhhs-podkast-om-ledelse
rss-var-forste-kaffe