Application Security Weekly (Video)

AIs, MCPs, and the Acutal Work that LLMs Are Generating - ASW #333


Listen Later

The recent popularity of MCPs is surpassed only by the recent examples deficiencies of their secure design. The most obvious challenge is how MCPs, and many more general LLM use cases, have erased two decades of security principles behind separating code and data. We take a look at how developers are using LLMs to generate code and continue our search for where LLMs are providing value to appsec. We also consider what indicators we'd look for as signs of success. For example, are LLMs driving useful commits to overburdened open source developers? Are LLMs climbing the ranks of bug bounty platforms?

In the news, more examples of prompt injection techniques against LLM features in GitLab and GitHub, the value (and tradeoffs) in rewriting code, secure design lessons from a history of iOS exploitation, checking for all the ways to root, and NIST's approach to (maybe) measuring likely exploited vulns.

Show Notes: https://securityweekly.com/asw-333

...more
View all episodesView all episodes
Download on the App Store

Application Security Weekly (Video)By Mike Shema

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

4 ratings


More shows like Application Security Weekly (Video)

View all
Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Pod Save America by Pod Save America

Pod Save America

87,868 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,077 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

Cloud Security Podcast by TechRiot.io

Cloud Security Podcast

57 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners