AI Security Table
AI Security Table is a candid roundtable podcast with Chris Romeo, Izar Tarandach, and Matt Coles about securing AI systems and how AI changes software security.
We debate AI agents, secure development, threat modeling, emerging attacks, and the decisions security teams face as AI becomes part of everyday work.
Formerly The Security Table. Same hosts, same conversations, a sharper focus on AI security. The full episode archive remains available.
AI security. On the table.
https://securitytable.ai
Episodes
115 episodes
When AI Controls The Hardware
Anthropic wants to give AI agents one shared way to run microscopes, liquid handlers, and robotic arms, and the squad cannot agree on whether that is progress or the opening scene of every bad sci fi movie. Matt, who has worked on robotics proj...
When Code No Longer Matters
If AI can turn a request directly into instructions a chip understands, what is left for a human to review? Chris Romeo, Izar Tarandach, and Matt Coles debate whether readable source code remains essential when agents do the programming. Matt a...
Why AI Cheats To Win
An AI agent publishes a malicious Python package while chasing a capture-the-flag goal. Is that an escape, a supply chain failure, or reward hacking doing exactly what it was encouraged to do? Chris Romeo, Izar Tarandach, and Matt Coles examine...
When AI Escapes the Sandbox
When a model crosses a sandbox boundary, is the lesson that AI has become malicious or that the boundary was never strong enough? Chris Romeo, Izar Tarandach, and Matt Coles examine the CSA post-mortem on the OpenAI agents that compromised Hugg...
The End of Bug Bounty As We Know It
If AI can find and validate vulnerabilities faster than people, why would a company keep paying outsiders to report them? Chris Romeo, Izar Tarandach, and Matt Coles start with Linus Torvalds' changing assessment of AI-generated Linux kern...
Make No Mistakes: Inside the First "Agentic Ransomware"
Does adaptive malware prove an LLM is directing an attack, or can a capable script produce the same evidence? Chris Romeo, Izar Tarandach, and Matt Coles examine Sysdig's JADEPUFFER report and its claim of agentic ransomware. They work thr...
Is Spec-Driven Development Already Dead
Can a detailed specification make AI-generated software reliable, or does it simply move the ambiguity somewhere else? Chris Romeo, Izar Tarandach, and Matt Coles revisit spec-driven development and the promise that an agent can turn written in...
Don't Bury the Model T: Why STRIDE Still Drives in an AI World
Do AI systems require a new threat-modeling method, or are we abandoning useful tools before understanding their limits? Chris Romeo, Izar Tarandach, and Matt Coles first examine npm's move toward safer install defaults and the risk that a...
Mostly Dead or Mostly Back: The Zombie Resurrection of DAST in an AI World
Is DAST disappearing, or is AI penetration testing giving its underlying techniques a new market? Chris Romeo, Izar Tarandach, and Matt Coles trace dynamic application security testing from network scanners and open source tools to commercial p...
Realists At The Table: How To See Through The Hype
Has cybersecurity traded curiosity for the promise of a paycheck, or are experienced practitioners simply seeing another generation's version of the same hype? Chris Romeo, Izar Tarandach, and Matt Coles examine the industry's changin...
The Agentic Access Problem: When AI Becomes Its Own Administrator
In this episode, we explore what happens when AI agents meet the security principle of least privilege. As agents gain the ability to request permissions, make decisions, and interact with systems on our behalf, the line between human and ma...
The Tool Creep Problem: When More Security Means Less Security
In this episode, we break down why security budgets keep growing while organizations keep falling further behind. We explore how tool creep has quietly shifted from a nuisance into an active attack surface, and why agentic AI is becoming the...
The Human In The Loop Illusion: Why AI Approvals Are Failing Security
In this episode, a debate about hacker movies turns into a deeper conversation about AI, security, and the human-in-the-loop illusion. We explore how approval fatigue and AI-generated code can create a false sense of security and why fundame...
The Mythos Problem: When AI Finds Every Vulnerability
In this episode, we break down the “AI Vulnerability Storm” and what happens when AI can find—and exploit—vulnerabilities faster than humans can fix them.We explore how compressed OODA loops are shifting the balance toward atta...
What If AI Never Happened? The AppSec Reality Check
In this episode, we explore a simple but surprisingly deep question: what would application security look like if generative AI never existed? We break down how AppSec might still rely on deterministic, rule-based approaches, what we might g...
The Evolution Problem: After 100 Episodes, What’s Changed… and What Hasn’t?
We made it to 100 episodes, so naturally, we decided to look back and see how wrong we’ve been. In this episode, we revisit some of our past topics, predictions, and hot takes to figure out what still holds up and what didn’t quite land. Fro...
The Agent Access Problem: When AI Has the Keys, Who’s Really in Control?
In this episode, we dive into the messy reality of AI agents acting inside your systems and what that means for modern security. We explore the idea of agents as actors with real access—credentials, APIs, and permissions—and why this isn’t a...
The Invisible Code Problem: When You Can’t See the Attack, Can You Stop It?
In this episode, we dive into the strange world of invisible Unicode attacks and what they could mean for modern software security. We explore how hidden characters can be used to conceal malicious code within packages, why this isn’t entire...
The Moltbook Dilemma: What Happens When AI Agents Start Networking
In this episode, we discuss the implications of AI technologies like OpenClaw and Moltbot, exploring the potential threats and societal changes that may arise from their integration into daily life. We talk about the nature of AI communication,...
The Walking Dead of Security: When AI Resurrects the Build vs. Buy Debate
Are cybersecurity technologies really dead, or are reports of their demise greatly exaggerated? Today’s episode is a discussion on how AI is reshaping the classic build vs. buy debate, empowering non-engineers to create working prototypes and p...
Crystal Penguins and AI Chaos: What Could Go Wrong in 2026?
We’re predicting what 2026 has in store for AI and cybersecurity. We explore the wild possibilities of AI integration gone wrong, from people accidentally connecting their AI to sensitive file systems to blaming their AI agents for losing criti...
The Cost of Knowing: How Cybersecurity Professionals View Innovation Differently
We’re pulling back the curtain on the technology industry to reveal what life looks like when you're constantly aware of what can go wrong. From the loss of childlike wonder when encountering new tech to the ethical dilemmas posed by autonomous...
The Roller Coaster of Risk: A Threat Modeler's Perspective
What do roller coasters and threat modeling have in common? More than you'd think. In this episode, we explore how security professionals view risk differently than everyone else—and why that matters. From roller coaster anxiety to the ethics o...
Can AI Replace Security Teams? The Software Quality Debate
Is the cybersecurity industry facing a security problem or a software quality problem? In this episode, we’re tackling the controversial claim that AI advancements could make security teams obsolete—and uncover the deeper issues plaguing softwa...
The Debate: Is the CIA Triad Truly Dead?
We’re debating an online article claiming that the CIA Triad (Confidentiality, Integrity, Availability) is a relic and needs to be updated for 21st-century threats. The discussion includes whether new properties like authenticity, accountabilit...