Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395
About this episode
Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task.
And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts.
Episode Resources:
- https://projectdiscovery.io/research/ai-coding-impact-report
- https://projectdiscovery.io/blog/oh-my-rogue-agent
Show Notes: https://securityweekly.com/asw-395
Get every episode summarized
Each time Security Weekly Podcast Network (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Security Weekly Podcast Network (Video)
Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marp...
Security Weekly Podcast Network (Video)
Linux Threat Hunting - PSW #942
Security Weekly Podcast Network (Video)
Preventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and...
Security Weekly Podcast Network (Video)
Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Le...
Security Weekly Podcast Network (Video)