When AI Ships the Code, Who Owns the Risk with Varun Badhwar and Henrik Plate

When AI Ships the Code, Who Owns the Risk with Varun Badhwar and Henrik Plate

AI isn’t quietly changing software development… it’s rewriting the rules while most security programs are still playing defense. When agents write code at machine speed, the real risk isn’t velocity, it’s invisible security debt compounding faster than teams can see it.

In this episode, Ron Eddings sits down with Varun Badhwar, Co-Founder & CEO of Endor Labs, and Henrik Plate, Principal Security Researcher of Endor Labs, to break down how AI-assisted development is reshaping the software supply chain in real time. From MCP servers exploding across GitHub to agents trained on insecure code patterns, they analyze why traditional AppSec controls fail in an agent-driven world and what must replace them.

This conversation pulls directly from Endor Labs’ 2025 State of Dependency Management Report, revealing why most AI-generated code is functionally correct yet fundamentally unsafe, how malicious packages are already exploiting agent workflows, and why security has to exist inside the IDE, not after the pull request.

Impactful Moments 00:00 – Introduction 02:00 – Star Wars meets cybersecurity culture 03:00 – Why this report matters now 04:00 – MCP adoption explodes overnight 10:00 – Can you trust MCP servers 12:00 – Malicious packages weaponize agents 14:00 – Code works, security fails 22:00 – Hooks expose agent behavior 28:30 – 2026 means longer lunches 33:00 – How Endor Labs fixes this

Links Connect with our Varun on LinkedIn: https://www.linkedin.com/in/vbadhwar/

Connect with our Henrik on LinkedIn: https://www.linkedin.com/in/henrikplate/

Check out Endor Labs State of Dependency Management 2025: https://www.endorlabs.com/lp/state-of-dependency-management-2025

Check out our upcoming events: https://www.hackervalley.com/livestreams

Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio

Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

Continue the conversation by joining our Discord: https://hackervalley.com/discord

Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(437)

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigatio...

19 Aug 34min

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in ...

14 Aug 23min

Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open?...

12 Aug 30min

Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from h...

7 Aug 38min

Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White

Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White

What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations,...

28 Juli 34min

What AI Agents Should Own in Your SOC, And What Happens If You Wait with Tim Leehealey

What AI Agents Should Own in Your SOC, And What Happens If You Wait with Tim Leehealey

What happens when the adversary moves at machine speed, and your SOC is still responding at human speed? Why does nearly every security team say AI should handle L1 work, while 64% of organizations st...

21 Juli 35min

We Shipped a Tool That Acts Like You. Meet Interceptor.

We Shipped a Tool That Acts Like You. Meet Interceptor.

Think about everything you could accomplish if you don’t have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of softwar...

14 Juli 30min

How to Turn Cybersecurity Customers into Lifelong Advocates with Antu Buck

How to Turn Cybersecurity Customers into Lifelong Advocates with Antu Buck

What if the same psychology that threat actors use to manipulate their targets is the same psychology that marketers use to earn your trust?  In this episode, Ron sits down with Antu Buck, Senior Dir...

7 Juli 30min

Populärt inom Utbildning

det-skaver
historiepodden-se
rss-bara-en-till-om-beroende-medberoende
nu-blir-det-historia
not-fanny-anymore
allt-du-velat-veta
harrisons-dramatiska-historia
johannes-hansen-podcast
rss-viktmedicinpodden
roda-vita-rosen
i-vantan-pa-katastrofen
rikatillsammans-om-privatekonomi-rikedom-i-livet
sa-in-i-sjalen
rss-basta-livet
rss-max-tant-med-max-villman
rss-traningsklubben
sektledare
vi-gar-till-historien
kan-jag-sa-kan-du-podden
rss-autismandan