Security News

Cybersecurity news aggregator

INFO News SC Media

Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

  • What: Discussion on using LLMs for vulnerability discovery
  • Impact: Application security teams and developers
Read Full Article →

Subscribe Share Full episode and show notes Vulnerability Management , Application security , Generative AI Using LLMs for Vuln Discovery – Rishi Sharma – ASW #395 Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it’s more important to care about vuln clas... August 11, 2026 Full Segment Notes Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: https://projectdiscovery.io/research/ai-coding-impact-report https://projectdiscovery.io/blog/oh-my-rogue-agent Guest Rishi Sharma Co-founder & CEO at ProjectDiscovery Rishiraj Sharma is Co-Founder and CEO of ProjectDiscovery. Sharma has over 10 years of experience in cybersecurity, starting as a pentester and security engineer. He worked at several companies including Cox Automotive, handling AppSec, infrastructure, and compliance security. ProjectDiscovery is an open source cybersecurity company that created Nuclei, an open source vulnerability scanner with over 10 billion scans run, along with a suite of modular tools, including Subfinder, httpx, and Naabu, that security teams use to map attack surfaces and identify exploitable vulnerabilities across their organizations. Building on that foundation, ProjectDiscovery offers Neo, an AI-powered security testing platform that unifies SAST, DAST, and automated penetration testing to help teams move from finding vulnerabilities to verifying and fixing them. Hosts Mike Shema https://dangerouserrors.com Tyler Shields https://www.90degree.vc/ Announcements Threat intelligence should help you decide what to fix, but most of the time it’s disconnected from your code, your pipelines, and your actual risk. So how do you make it relevant to AppSec? At the Threat Intelligence Virtual Cybersecurity Summit on August 26th, learn how to apply intel to vulnerability prioritization and focus on what’s truly exploitable. Security Weekly listeners can register for free at https://securityweekly.com/threatintel using the promo code: CSS26-SW InfoSec World brings cybersecurity professionals together across industries, from healthcare and financial services to government and the Fortune 500. Join the community in Orlando, October 12–14, for practical education, new perspectives, and cybersecurity research unveiled live. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026. List of Articles Mike Shema Can AI do novel security research? Meet the HTTP Terminator CSS:the bomb inside your inbox | PortSwigger Research Apple’s ‘Private Relay’ Is Exposing Users’ Real IP Addresses And be sure to read the technical write-up . FYI: Off-by-1 Labs Research: AI-generated vulnerability patches require human review | 1Password Here's the research we talked about last week with Keith Hoodlet in episode 394 . FYI: Zenity Labs Discloses PleaseFix Vulnerability Family in Perplexity Comet and Other Agentic Browsers We didn't cover this when it first came out, but it won a Pwnie at this year's DEF CON. AI-driven browsers are a bad idea and this research essentially shows how to turn social engineering against humans (i.e. ClickFix) into prompt injection against browsers (aka PleaseFix). Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments Vulnerability Management Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet – SWN #605 Vulnerability Management After Mythos: Securing Frontier AI as Attack and Defense Accelerate – Sean Murphy – BH26 #2 Vulnerability Management Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting – Braden Russell – BH26 #2 Related Content Vulnerability Management Progress LoadMaster bug added to CISA list of exploited vulnerabilities Vulnerability Management Metabase SQL injection vulnerability exploited in zero-day attacks Vulnerability Management WordPress ‘XSS2Shell’ flaw allows admin takeover and remote code execution You can skip this ad in 5 seconds

Share this article