- What: Discussion on AI-generated code and security
- Impact: Experts debate the implications of AI in software development and security assurance
Subscribe Share Full episode and show notes Application security , AI/ML , AI benefits/risks Why Does It Matter Who or What Created the Code? – Matias Madou – ASW #387 Agents and LLMs are creating and reviewing code. They’re a new tool to help developers write software and they’re a new abstraction layer for expressing what code should do. But if we’re focused on determining whether code is secure, where do we focus our attention on ensuring a secure outcome? Matias Madou talks about the challenges of finding metrics to help answer these questions. We walk through many of the questions we’d like to see answered and our desire to see appsec (finally?) shift out of a find-and-fix mode into a future of secure design. June 16, 2026 Full Segment Notes Agents and LLMs are creating and reviewing code. They're a new tool to help developers write software and they're a new abstraction layer for expressing what code should do. But if we're focused on determining whether code is secure, where do we focus our attention on ensuring a secure outcome? Matias Madou talks about the challenges of finding metrics to help answer these questions. We walk through many of the questions we'd like to see answered and our desire to see appsec (finally?) shift out of a find-and-fix mode into a future of secure design. Guest Matias Madou Co-Founder and CTO at Secure Code Warrior Matias is the co-founder and CTO of Secure Code Warrior. SCW provides a fully hands-on gamified experience with metrics, leaderboards and badging that enables developers to master secure coding in different development languages and frameworks. Our customers are able track their skills and progress, and benchmark different teams, including assessing potential suppliers and new recruits. SCW is truly the first global platform developers want to learn on and allows you to ensure a minimum baseline of security skills in your organization. Matias has over a decade of hands-on software security experience. From the research to improve existing solutions to scoping and building new solutions. A dozen patents and a bunch of papers are the result of his research that eventually led to a hand full of commercial products. Matias holds a Ph.D. in computer engineering from Ghent University, where he studied application security through program obfuscation to hide the inner workings of an application. With his Ph.D. in application security, he joined Fortify as an intern and moved up to being the research architect of all runtime solutions within crossing Fortify and ArcSight within HP. He presented at conferences including RSA Conference, BlackHat and DefCon. Hosts Mike Shema https://dangerouserrors.com Tyler Shields https://www.90degree.vc/ List of Articles Mike Shema Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement Pythagora-io/gpt-pilot Compromised on GitHub – Shai-Hulud Credential Stealer Blocked by Python Linter – StepSecurity Also note that the packages can have valid SLSA signatures, but that doesn't mean that SLSA has failed. It just means that consuming and implementing SLSA require attention to detail . A human in control | daniel.haxx.se Mythos Doesn’t Deploy Itself | Bishop Fox Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments DevSecOps AI-Generated Code Security Risks: Why “Vibe Coding” Can Break Your App – WC #1 Application security Scanner Results Are a Starting Point. Here’s What Comes Next. – Federico Kirschbaum – ASW #386 Application security BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR – ASW #385 Related Content Exposure management Securing the model: Protecting AI systems from compromise Application security Docker security scanner uses AI to help explain, fix vulnerabilities AI/ML Guardrails for agents: How to secure AI at runtime You can skip this ad in 5 seconds