Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395 @SecurityWeekly
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395  @SecurityWeekly
Uploaded August 2026 | Updated September 2026, 2 weeks ago
Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task.

And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts.

Episode Resources:
- projectdiscovery.io/research/ai-coding-impact-report
- projectdiscovery.io/blog/oh-my-rogue-agent

Visit securityweekly.com/asw for all the latest episodes!

Show Notes: securityweekly.com/asw-395

00:00:00 Episode Introduction and Threat Intelligence Sponsor
00:02:06 Automating Vulnerability Management with Open Source Tools
00:04:54 Automating Vulnerability Identification and Regression Cycles
00:06:54 How AI Prevents Vulnerabilities from Reappearing
00:09:37 Understanding LLM Behavior and Scope Limitations
00:12:52 Refining Prompts and Environment Controls for LLMs
00:15:52 Implementing Environment Controls and Cost Management for LLMs
00:19:53 Comparing LLM Brute-Force to Human Pen Tester Methodology
00:24:29 Merging Human and AI Strengths for Offensive Security
00:29:54 Open-Weight Models, Cost, and Securing Every Software Release
00:37:08 James Kettle's HTTP Terminator and AI-Assisted Discovery
00:47:55 Gareth Hayes on CSS Attacks and Email Inbox Exploits
00:51:47 Debating Input Validation and the Value of Community Research
01:00:30 Apple's Private Relay Exposes User IP Addresses
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598Can employees safely use AI agents? AI pentesting agent liabilities, and the news - ESW #473Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462Randomness, Grey, Deepseek, Sonicwall, Spice, CaptiveCrunch, eBay, and Aaran Leyland  - SWN #604AI Agents Dont Respect Every BoundaryBorg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet & More - SWN #597What If Ransomware Never Encrypts Anything?You Ruled Yourself Out Too SoonCyberRisk TV Live Coverage from Black Hat 2026 - Day 1Defense Gap in AI Security Race
Security Weekly - A CRA Resource |

Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER