Jim Manico ❤️ Threat Modeling: The Untold Story

Jim Manico ❤️ Threat Modeling: The Untold Story

Jim Manico joins Chris, Matt, and Izar at the Security Table for a rousing discussion on his Threat Modeling journey. They also learn about each other's thoughts about DAST, SAST, SCA, Security in AI, and several other topics. Jim is an educator at heart, and you learn quickly that he loves application security. Jim is not afraid to drop a few controversial opinions and even a rap! Jim discusses the importance of static application security testing (SAST) and how it is becoming increasingly ...

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(114)

When Code No Longer Matters

When Code No Longer Matters

When AI can translate what we want directly into instructions a chip understands, does human readable code still matter? Matt argues it always will. Izar calls the whole premise one of the stupidest t...

23 Sep 36min

Why AI Cheats To Win

Why AI Cheats To Win

When Anthropic's Mythos 5 model believed it was working inside an isolated test environment, it built and published a real malicious Python package to PyPI while chasing a capture-the-flag goal — and ...

16 Sep 39min

When AI Escapes the Sandbox

When AI Escapes the Sandbox

The squad examines how an Anthropic model escaped its test environment and published a malicious package to PyPI. The conversation explores reward hacking, AI ethics, and why stronger security control...

9 Sep 49min

The End of Bug Bounty As We Know It

The End of Bug Bounty As We Know It

We dig into Linus Torvalds' claim that AI is now a legitimate tool for the Linux kernel, and what it means for bug bounty platforms drowning in submissions, with Bug Crowd reporting a fourfold spike i...

5 Aug 42min

Make No Mistakes: Inside the First "Agentic Ransomware"

Make No Mistakes: Inside the First "Agentic Ransomware"

We dig into Sysdig's Jade Puffer report, the so-called first agentic ransomware, and argue about whether the evidence actually proves an LLM was driving the attack or if it's just a well-trained scrip...

22 Jul 43min

Is Spec-Driven Development Already Dead

Is Spec-Driven Development Already Dead

In this episode, we take on spec-driven development, the resurgent idea that writing a detailed spec and letting AI implement it will finally give us the precision engineering promised us since the 19...

15 Jul 41min

Don't Bury the Model T: Why STRIDE Still Drives in an AI World

Don't Bury the Model T: Why STRIDE Still Drives in an AI World

In this episode, we dig into two things the security community loves to argue about: npm finally doing the right thing and whether STRIDE has any business being called dead. The npm v12 changes gate d...

1 Jul 59min

Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World

Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World

In this episode, we dig into whether DAST is dead, mostly dead, or quietly making a comeback dressed in an AI trench coat. The conversation traces the origins of dynamic application security testing f...

24 Jun 42min

Populært innen Teknologi

teknisk-sett
tomprat-med-gunnar-tjomlid
lydartikler-fra-aftenposten
energi-og-klima
elektropodden
rss-ki-praten
hans-petter-og-co
nasjonal-sikkerhetsmyndighet-nsm
shifter
smart-forklart
rss-alt-som-gar-pa-strom
rss-ai-forklart
teknologi-og-mennesker
rss-snakk-om-sikkerhet
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
fornybaren
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
pedagogisk-intelligens
rss-alt-vi-kan
rss-heis