
Vulnerability Research, AI Slop, and Why Fundamentals Still Win with Stephen Sims
About this episode
AI can now hand someone a working Linux kernel privilege escalation exploit, even if that person cannot explain a single line of how it works. Stephen Sims joined the show to talk about what that shift means for offensive security, and why the fundamentals matter more now, not less.Stephen is the curriculum lead for SANS Institute's Offensive Operations program, where he has spent more than 15 years as an author and instructor, and he is a co-founder of Off by One Security. He is a longtime exploit developer and vulnerability researcher who came up through game hacking, network engineering, and years of binary exploitation, reverse engineering, and weaponizing bugs in browsers and the kernel.In this episode, Stephen and Phillip get into how AI is reshaping vulnerability research and exploit development. Stephen explains why human validation is still doing the heavy lifting behind the big vulnerability-count headlines, how AI tends to overstate or understate severity, and why so many submissions are now AI slop or duplicates. He makes the case that logic bugs remain the hardest thing for AI to find, walks through his roadmap for anyone serious about learning exploit development, and shares why he tells students to do the work manually before letting AI do it for them. Stephen also offers grounded advice for breaking into the field, from building a real technology foundation first to staying curious and paying your dues, and gives his honest read on where the opportunity is heading.=========================Connect with Stephen Sims:LinkedIn: https://www.linkedin.com/in/stephen-sims-2788091/X: https://x.com/Steph3nSimsOff by One Security: https://offbyonesecurity.com/YouTube: https://www.youtube.com/@OffByOneSecurity=========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie
Get every episode summarized
Each time Phillip Wylie Show publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Phillip Wylie Show

Purple Teaming with Sarah Hume: Turning Threat Intelligence Into Actionable Test...
Phillip Wylie Show

From English Teacher to OSINT Investigator: Lindsey Yagi-Hatake on Breaking Into...
Phillip Wylie Show

AI, Automation, and the Future of Penetration Testing with Herman Zubenko
Phillip Wylie Show

From First-Generation Graduate to DEF CON Speaker: Moo's Cybersecurity Journey
Phillip Wylie Show
