Skip to main content
Qubicweb logo

Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

August 11, 2026

Description

Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: - https://projectdiscovery.io/research/ai-coding-impact-report - https://projectdiscovery.io/blog/oh-my-rogue-agent Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-395

About

Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: - https://projectdiscovery.io/research/ai-coding-impact-report - https://projectdiscovery.io/blog/oh-my-rogue-agent Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-395
Watch on Original Source

Trust cues for videos

Internal ReadExternal SourceCuratedCommunity signalMixedSource-only
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395 - Qubicweb