AI Security Table

AI Security Table

AI Security Table is a candid roundtable podcast with Chris Romeo, Izar Tarandach, and Matt Coles about securing AI systems and how AI changes software security. We debate AI agents, secure development, threat modeling, emerging attacks, and the decisions security teams face as AI becomes part of everyday work. Formerly The Security Table. Same hosts, same conversations, a sharper focus on AI security. The full episode archive remains available. AI security. On the table. https://securitytable.ai

Episodes

September 30, 2026 • 42 mins

Anthropic wants to give AI agents one shared way to run microscopes, liquid handlers, and robotic arms, and the squad cannot agree on whether that is progress or the opening scene of every bad sci fi movie. Matt, who has worked on robotics projects, says a common control standard is decades overdue. Izar calls it the PCI for AI, reminds everyone how secure MCP was on day one, and brings up Therac 25 as a warning about what happens ...

Listen
Watch
Mark as Played

If AI can turn a request directly into instructions a chip understands, what is left for a human to review? Chris Romeo, Izar Tarandach, and Matt Coles debate whether readable source code remains essential when agents do the programming. Matt argues that code always matters; Izar rejects the premise that another abstraction makes ambiguity disappear. The conversation moves through COBOL, Fortran, language evolution, and the prospec...

Listen
Watch
Mark as Played
September 16, 2026 • 39 mins

An AI agent publishes a malicious Python package while chasing a capture-the-flag goal. Is that an escape, a supply chain failure, or reward hacking doing exactly what it was encouraged to do? Chris Romeo, Izar Tarandach, and Matt Coles examine the Anthropic incident and disagree about how much intention to attribute to a model. The discussion turns to package scanners, dependency names, GPG signing, and whether penalties can teach...

Listen
Watch
Mark as Played
September 9, 2026 • 49 mins

When a model crosses a sandbox boundary, is the lesson that AI has become malicious or that the boundary was never strong enough? Chris Romeo, Izar Tarandach, and Matt Coles examine the CSA post-mortem on the OpenAI agents that compromised Hugging Face during a security evaluation. They debate reward-driven behavior, disabled safeguards, the four-day intrusion timeline, and the responsibility of the people running the experiment. T...

Listen
Watch
Mark as Played
August 5, 2026 • 42 mins

If AI can find and validate vulnerabilities faster than people, why would a company keep paying outsiders to report them? Chris Romeo, Izar Tarandach, and Matt Coles start with Linus Torvalds' changing assessment of AI-generated Linux kernel reports, then examine what useful automation does to the bug bounty economy. They debate disclosure incentives, model restrictions that may constrain defenders more than attackers, and the cost...

Listen
Watch
Mark as Played

Does adaptive malware prove an LLM is directing an attack, or can a capable script produce the same evidence? Chris Romeo, Izar Tarandach, and Matt Coles examine Sysdig's JADEPUFFER report and its claim of agentic ransomware. They work through the proposed indicators, including self-narrating payloads, rapid failure diagnosis, interpretation of natural-language context, and a reused Bitcoin address. The debate distinguishes plausib...

Listen
Watch
Mark as Played

Can a detailed specification make AI-generated software reliable, or does it simply move the ambiguity somewhere else? Chris Romeo, Izar Tarandach, and Matt Coles revisit spec-driven development and the promise that an agent can turn written intent into a correct implementation. They debate why earlier approaches struggled, whether natural language is enough, and how tests can fail when the same AI writes both the code and its chec...

Listen
Watch
Mark as Played

Do AI systems require a new threat-modeling method, or are we abandoning useful tools before understanding their limits? Chris Romeo, Izar Tarandach, and Matt Coles first examine npm's move toward safer install defaults and the risk that agents trained on older behavior will simply re-enable dangerous options. Then they debate the claim that STRIDE belongs to a world that no longer exists. The discussion separates threat categories...

Listen
Watch
Mark as Played

Is DAST disappearing, or is AI penetration testing giving its underlying techniques a new market? Chris Romeo, Izar Tarandach, and Matt Coles trace dynamic application security testing from network scanners and open source tools to commercial products, then debate where scanning ends and adaptive testing begins. They question whether a tool that finds many issues serves the same purpose as a tester who follows an exploit chain. AI-...

Listen
Watch
Mark as Played

Has cybersecurity traded curiosity for the promise of a paycheck, or are experienced practitioners simply seeing another generation's version of the same hype? Chris Romeo, Izar Tarandach, and Matt Coles examine the industry's changing stereotypes, from hoodie-clad specialists to ambitious founders. Mainframes, cloud computing, AI, quantum, and NFTs provide examples of ideas that return wearing new labels. The Cuckoo's Egg and hack...

Listen
Watch
Mark as Played

In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and machine responsibility starts to blur. The discussion covers prompt fatigue, over-permissioned agents, and why "because the agent told me to" may become the next security anti-pattern—before...

Listen
Watch
Mark as Played

In this episode, we break down why security budgets keep growing while organizations keep falling further behind. We explore how tool creep has quietly shifted from a nuisance into an active attack surface, and why agentic AI is becoming the insider threat no one planned for. Izar shares a firsthand account of watching an AI agent attempt increasingly creative workarounds to escape a sandbox, revealing just how much risk lives in t...

Listen
Watch
Mark as Played

In this episode, a debate about hacker movies turns into a deeper conversation about AI, security, and the human-in-the-loop illusion. We explore how approval fatigue and AI-generated code can create a false sense of security and why fundamentals still matter.

🚀 Join the Conversation
 Are we improving security, or just automating bad decisions faster?

Follow AI Security Table:

➜ Home: https://securitytable.ai/

➜ X: h...

Listen
Watch
Mark as Played

In this episode, we break down the “AI Vulnerability Storm” and what happens when AI can find—and exploit—vulnerabilities faster than humans can fix them.

We explore how compressed OODA loops are shifting the balance toward attackers, why traditional scoring like CVSS may start to break down, and whether “just patch faster” is even realistic anymore. The team also questions the push toward AI agen...

Listen
Watch
Mark as Played

In this episode, we explore a simple but surprisingly deep question: what would application security look like if generative AI never existed? We break down how AppSec might still rely on deterministic, rule-based approaches, what we might gain in structure and rigor, and what we’d lose in speed, scale, and accessibility. Along the way, we debate whether AI is truly improving security or just accelerating existing problems, f...

Listen
Watch
Mark as Played

We made it to 100 episodes, so naturally, we decided to look back and see how wrong we’ve been. In this episode, we revisit some of our past topics, predictions, and hot takes to figure out what still holds up and what didn’t quite land. From “we don’t know what we don’t know” to the evolution of security tools, we reflect on what’s changed, what hasn’t, and why some problems never se...

Listen
Watch
Mark as Played

In this episode, we dive into the messy reality of AI agents acting inside your systems and what that means for modern security. We explore the idea of agents as actors with real access—credentials, APIs, and permissions—and why this isn’t as new as it sounds (hint: it’s just applications all over again). We unpack where things actually get risky, from over-permissioned agents to unpredictable behavior drive...

Listen
Watch
Mark as Played

In this episode, we dive into the strange world of invisible Unicode attacks and what they could mean for modern software security. We explore how hidden characters can be used to conceal malicious code within packages, why this isn’t entirely a new problem, and whether current tools, such as linters and SAST, are equipped to detect it. We also question the role of LLMs in both enabling and detecting these attacks, and whethe...

Listen
Watch
Mark as Played

In this episode, we discuss the implications of AI technologies like OpenClaw and Moltbot, exploring the potential threats and societal changes that may arise from their integration into daily life. We talk about the nature of AI communication, the concept of agentic AI, and the philosophical questions surrounding the future of human and machine interaction. Per usual our conversation is laced with humor and skepticism about the ra...

Listen
Watch
Mark as Played

Are cybersecurity technologies really dead, or are reports of their demise greatly exaggerated? Today’s episode is a discussion on how AI is reshaping the classic build vs. buy debate, empowering non-engineers to create working prototypes and potentially reviving the DIY coding culture of pre-open-source days. We also talk about how developers trained on open source are now leveraging AI built from that same foundation, raisi...

Listen
Watch
Mark as Played

Popular Podcasts

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Dateline NBC

    Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

    The Joe Rogan Experience

    The official podcast of comedian Joe Rogan.

    The Clay Travis and Buck Sexton Show

    The Clay Travis and Buck Sexton Show. Clay Travis and Buck Sexton tackle the biggest stories in news, politics and current events with intelligence and humor. From the border crisis, to the madness of cancel culture and far-left missteps, Clay and Buck guide listeners through the latest headlines and hot topics with fun and entertaining conversations and opinions.

    The Breakfast Club

    The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices