Uploaded May 2026 | Updated September 2026, 9 hours ago
AI lets us find more vulnerabilities, faster than ever. That's good news. You want to know what's broken, and you want to patch it. The hard part is the volume. How do you handle it without drowning?
This week on Tanzu Catsup, @thecote and David Zendzian walk through a four-item playbook for what to actually do about it: take the patches and stop deferring them, don't let older releases become a liability, make continuous patching part of the architecture, and scale it across the org. There's even more in a recent post from Purnima Padmanabhan: blogs.vmware.com/tanzu/how-to-prepare-for-the-world-of-ai-driven-exploits
David adds the field detail: hand-drawn firewall diagrams that had to go on a plot printer at Wells Fargo, multi-million-line vuln dumps from customers, why the interesting state-of-the-art is the gating step in continuous-patching pipelines (not the patching itself), and why a registry is really a security tool wearing a developer-tool hat. The episode closes on David's "Council of Elders" - a persona-based agent rig with shared episodic memory and ephemeral build agents - which is the same architectural argument applied to coding instead of patching.
Interested in a platform that can help you with enterprise-y excellence? Just TryTanzu.ai
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote and David Zendzian
Index:
0:00 Morning-drive
1:30 Hockey-puck CVE growth and the bug-discovery flood
4:30 Lucy in the chocolate factory
5:00 The four-item security playbook
6:00 Where do you start? The core of security is inventory
10:30 Plot-printer firewall diagrams at Wells Fargo
15:30 Dashboard wars and how that worked out for Frodo
17:00 API-first when your next user is an agent
22:00 What continuous patching actually looks like in production
26:00 Supply chain attacks and AI-designed exploits
28:00 Live kernel patching and immutable rebuilds
32:00 Registries are really security tools wearing a developer-tool hat
36:00 The Council of Elders agent rig
43:30 Wrap-up
AI lets us find more vulnerabilities, faster than ever. That's good news. You want to know what's broken, and you want to patch it. The hard part is the volume. How do you handle it without drowning?
This week on Tanzu Catsup, @thecote and David Zendzian walk through a four-item playbook for what to actually do about it: take the patches and stop deferring them, don't let older releases become a liability, make continuous patching part of the architecture, and scale it across the org. There's even more in a recent post from Purnima Padmanabhan: blogs.vmware.com/tanzu/how-to-prepare-for-the-world-of-ai-driven-exploits
David adds the field detail: hand-drawn firewall diagrams that had to go on a plot printer at Wells Fargo, multi-million-line vuln dumps from customers, why the interesting state-of-the-art is the gating step in continuous-patching pipelines (not the patching itself), and why a registry is really a security tool wearing a developer-tool hat. The episode closes on David's "Council of Elders" - a persona-based agent rig with shared episodic memory and ephemeral build agents - which is the same architectural argument applied to coding instead of patching.
Interested in a platform that can help you with enterprise-y excellence? Just TryTanzu.ai
Tanzu Catsup is a weekly conversation about platform engineering, cloud-native operations, and building software in large organizations...and, of course, AI.
Check us out Fridays at 10am US Eastern/4pm Amsterdam time! In YouTube: youtube.com/playlist?list=PLAdzTan_eSPSlg3nySSAI7DjrbN2Bt56r
Hosts: @thecote and David Zendzian
Index:
0:00 Morning-drive
1:30 Hockey-puck CVE growth and the bug-discovery flood
4:30 Lucy in the chocolate factory
5:00 The four-item security playbook
6:00 Where do you start? The core of security is inventory
10:30 Plot-printer firewall diagrams at Wells Fargo
15:30 Dashboard wars and how that worked out for Frodo
17:00 API-first when your next user is an agent
22:00 What continuous patching actually looks like in production
26:00 Supply chain attacks and AI-designed exploits
28:00 Live kernel patching and immutable rebuilds
32:00 Registries are really security tools wearing a developer-tool hat
36:00 The Council of Elders agent rig
43:30 Wrap-up










