Skip to content
TrackPodcasts
technologyOct 7, 202553:52pending

Finding Large Bounties with Large Language Models - Nico Waisman - ASW #351

About this episode

Software has forever had flaws and humans have forever been finding and fixing them. With LLMs generating code, appsec has also been trying to determine how well LLMs can find flaws. Nico Waisman talks about XBOW's LLM-based pentesting, how it climbed a bug bounty leaderboard, how it uses feedback loops for better pentests, and how they handle (and even welcome!) hallucinations.

In the news, using LLMs to find flaws, directory traversal in an MCP, another resource for learning cloud and AI security, spreadsheets and appsec, and more!

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-351

Get every episode summarized

Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

Finding Large Bounties with Large Language Models - Nico Waisman - ASW #351

Security Weekly Podcast Network (Audio)

0:00
53:52

More episodes

More from Security Weekly Podcast Network (Audio)

View all episodes →