Absolute AppSec

Episode 313 - AppSec Role Evolution, AI Skills & Risks, Phishing AI Agents


Listen Later

Ken Johnson and Seth Law examine the intensifying pressure on security practitioners as AI-driven development causes an unprecedented acceleration in industry velocity. A primary theme is the emergence of "shadow AI," where developers utilize unauthorized AI coding assistants and personal agents, introducing significant data classification risks and supply chain vulnerabilities. The discussion dives into technical concepts like AI agent "skills"—markdown files providing specialized directions—and the corresponding security risks found in new skill registries, such as malicious tools designed to exfiltrate credentials and crypto assets. The hosts also review 1Password’s SCAM (Security Comprehension Awareness Measure), highlighting broad performance gaps in an AI's ability to detect phishing, with some models failing up to 65% of the time. To manage these unpredictable systems, the hosts advocate for a shift toward high-level validation roles, emphasizing the need for Subject Matter Expertise to combat "reasoning drift" and maintain safety through test-driven development and periodic "checkpoints". Ultimately, they conclude that while AI can simulate expertise, human oversight remains vital to secure the probabilistic nature of modern agentic workflows.
...more
View all episodesView all episodes
Download on the App Store

Absolute AppSecBy Ken Johnson and Seth Law

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

17 ratings


More shows like Absolute AppSec

View all
Stuff You Should Know by iHeartPodcasts

Stuff You Should Know

78,789 Listeners

Planet Money by NPR

Planet Money

30,679 Listeners

Risky Business by Patrick Gray

Risky Business

373 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,103 Listeners

Application Security Weekly (Audio) by Security Weekly Productions

Application Security Weekly (Audio)

12 Listeners