Uploaded October 2025 | Updated September 2026, 2 weeks ago
➡ Minimize security debt & operational overhead while accelerating software delivery with OX Security: https://www.ox.security/
VibeSecCon conference registration page
https://hubs.li/Q03P0t1p0
In this conversation we discuss the failure of "shift left" security and demonstrates how the VibeSec "vibe coding" AI agent, powered by a rich organizational and threat context model, integrates security directly into the development workflow for better, real-time code construction.
What we talk about:
The failure of "Shift Left" security
Discussion on why the "shift left" security approach was fundamentally flawed, solving AppSec's problem but not the developer's, leading to bloated backlogs and loss of developer trust.
Introducing specialized agents as the solution
How AI-driven "vibe coding" agents can replace "shift left" by injecting the necessary security context directly to the coding agent, rather than communicating with the developer.
Building and leveraging a massive security context (Threat Model)
Details on collecting all relevant organizational data—code, build, APIs, cloud, threat intelligence, and organizational goals—into a graph-based data lake to create a dynamic threat model for real-time security guidance.
Real-time, contextual security fixes
Demonstration of how the "vibe coding" agent uses this context to offer instant, organization-specific suggestions for secure coding (e.g., preventing hardcoded secrets and enforcing corporate libraries), resulting in fundamentally different, secure code.
Focus on measurable improvement and campaigns
The strategy of defining security goals and running "campaigns" (e.g., eliminating all code secrets) to systematically reduce backlog and improve quantifiable KPIs like remediation within SLA.
Chapters:
00:53 Analyzing the Failure of "Shift Left"
02:29 Current Problem Focus and Strategy
06:40 Details on Context Sources
10:34 Organizational Visibility and Developer Interaction
11:11 How Context is Injected into the Agent
16:49 Other Context Pieces from the Organization
22:47 Dynamics and Speed of Context Updates
23:43 Interaction with Other AI Models and Agents
27:40 New Releases and Future Excitement
28:45 Integrating Corporate Coding Policies
33:45 Finding More Information and Research
34:32 Location of the Upcoming Event
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler
➡ Minimize security debt & operational overhead while accelerating software delivery with OX Security: https://www.ox.security/
VibeSecCon conference registration page
https://hubs.li/Q03P0t1p0
In this conversation we discuss the failure of "shift left" security and demonstrates how the VibeSec "vibe coding" AI agent, powered by a rich organizational and threat context model, integrates security directly into the development workflow for better, real-time code construction.
What we talk about:
The failure of "Shift Left" security
Discussion on why the "shift left" security approach was fundamentally flawed, solving AppSec's problem but not the developer's, leading to bloated backlogs and loss of developer trust.
Introducing specialized agents as the solution
How AI-driven "vibe coding" agents can replace "shift left" by injecting the necessary security context directly to the coding agent, rather than communicating with the developer.
Building and leveraging a massive security context (Threat Model)
Details on collecting all relevant organizational data—code, build, APIs, cloud, threat intelligence, and organizational goals—into a graph-based data lake to create a dynamic threat model for real-time security guidance.
Real-time, contextual security fixes
Demonstration of how the "vibe coding" agent uses this context to offer instant, organization-specific suggestions for secure coding (e.g., preventing hardcoded secrets and enforcing corporate libraries), resulting in fundamentally different, secure code.
Focus on measurable improvement and campaigns
The strategy of defining security goals and running "campaigns" (e.g., eliminating all code secrets) to systematically reduce backlog and improve quantifiable KPIs like remediation within SLA.
Chapters:
00:53 Analyzing the Failure of "Shift Left"
02:29 Current Problem Focus and Strategy
06:40 Details on Context Sources
10:34 Organizational Visibility and Developer Interaction
11:11 How Context is Injected into the Agent
16:49 Other Context Pieces from the Organization
22:47 Dynamics and Speed of Context Updates
23:43 Interaction with Other AI Models and Agents
27:40 New Releases and Future Excitement
28:45 Integrating Corporate Coding Policies
33:45 Finding More Information and Research
34:32 Location of the Upcoming Event
Subscribe to the newsletter at:
danielmiessler.com/subscribe
Join the UL community at:
danielmiessler.com/upgrade
Follow on X:
https://x.com/danielmiessler
Follow on LinkedIn:
linkedin.com/in/danielmiessler




