Uploaded August 2026 | Updated September 2026, 2 weeks ago
Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task.
And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts.
Episode Resources:
- projectdiscovery.io/research/ai-coding-impact-report
- projectdiscovery.io/blog/oh-my-rogue-agent
Visit securityweekly.com/asw for all the latest episodes!
Show Notes: securityweekly.com/asw-395
00:00:00 Episode Introduction and Threat Intelligence Sponsor
00:02:06 Automating Vulnerability Management with Open Source Tools
00:04:54 Automating Vulnerability Identification and Regression Cycles
00:06:54 How AI Prevents Vulnerabilities from Reappearing
00:09:37 Understanding LLM Behavior and Scope Limitations
00:12:52 Refining Prompts and Environment Controls for LLMs
00:15:52 Implementing Environment Controls and Cost Management for LLMs
00:19:53 Comparing LLM Brute-Force to Human Pen Tester Methodology
00:24:29 Merging Human and AI Strengths for Offensive Security
00:29:54 Open-Weight Models, Cost, and Securing Every Software Release
00:37:08 James Kettle's HTTP Terminator and AI-Assisted Discovery
00:47:55 Gareth Hayes on CSS Attacks and Email Inbox Exploits
00:51:47 Debating Input Validation and the Value of Community Research
01:00:30 Apple's Private Relay Exposes User IP Addresses
Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task.
And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts.
Episode Resources:
- projectdiscovery.io/research/ai-coding-impact-report
- projectdiscovery.io/blog/oh-my-rogue-agent
Visit securityweekly.com/asw for all the latest episodes!
Show Notes: securityweekly.com/asw-395
00:00:00 Episode Introduction and Threat Intelligence Sponsor
00:02:06 Automating Vulnerability Management with Open Source Tools
00:04:54 Automating Vulnerability Identification and Regression Cycles
00:06:54 How AI Prevents Vulnerabilities from Reappearing
00:09:37 Understanding LLM Behavior and Scope Limitations
00:12:52 Refining Prompts and Environment Controls for LLMs
00:15:52 Implementing Environment Controls and Cost Management for LLMs
00:19:53 Comparing LLM Brute-Force to Human Pen Tester Methodology
00:24:29 Merging Human and AI Strengths for Offensive Security
00:29:54 Open-Weight Models, Cost, and Securing Every Software Release
00:37:08 James Kettle's HTTP Terminator and AI-Assisted Discovery
00:47:55 Gareth Hayes on CSS Attacks and Email Inbox Exploits
00:51:47 Debating Input Validation and the Value of Community Research
01:00:30 Apple's Private Relay Exposes User IP Addresses










