ConversingLabs Podcast

ReversingLabs

ConversingLabs Podcast brings you conversations with the best and brightest minds in malware analysis, threat hunting, and software supply chain security. Hosted by Paul Roberts, director of editorial and content at ReversingLabs, ConversingLabs digs into cutting edge topics that are most pressing in the world of cybersecurity.

  1. Building Secure AI - A Conversation With Steve Wilson of Exabeam

    Jun 4

    Building Secure AI - A Conversation With Steve Wilson of Exabeam

    Host Paul Roberts welcomes Conversing Labs  guest Steve Wilson, Chief AI and Product Officer at Exabeam and co-chair of the OWASP GenAI Security Project. Steve discusses his path from early programming to AppSec at Contrast Security and leading the OWASP Top 10 for LLMs, which grew into a large community and later an Agentic Top 10. Wilson explains AI’s recent leap via transformer architecture, cloud scale, and GPUs, and describes Exabeam’s evolution from SIEM and behavior analytics to generative and agentic AI with multiple security agents. He summarizes his 2024 O’Reilly book expanding OWASP risks into case studies and secure development practices, emphasizing that AppSec alone is insufficient for autonomous agents, requiring monitoring and “agent behavior analytics.” The conversation highlights AI supply chain risks (models, plugins/MCP, OpenClaw skills, fake Chrome extensions), scoping/least privilege, and the practical impact of tools like Claude Code on AppSec and security operations. 00:00 Welcome and Guest Intro02:35 Steve’s Cyber Journey04:13 OWASP LLM Top 10 Origins06:21 From LLMs to Agents06:59 Tron and AI History09:32 Why Transformers Changed Everything11:35 What Exabeam Actually Does16:08 Writing the LLM Security Book20:27 Agent Risks Beyond AppSec22:05 What Changed Since 202423:30 Reasoning Models and Strawberry26:18 Agentic Top 10 and Supply Chain27:11 Hallucinated Dependencies27:47 Model Supply Chain Trust28:57 Plugins And Agent Exploits29:58 MCP And Skills Risks31:01 Chrome Plugin Trap33:47 RAISE Framework Overview35:12 Monitoring Digital Workers38:40 Scoping And RAG41:44 Excessive Agency Controls43:02 Sandboxed Assistant Build45:16 AI Impact On Infosec49:15 Closing And Contact

    50 min

Ratings & Reviews

About

ConversingLabs Podcast brings you conversations with the best and brightest minds in malware analysis, threat hunting, and software supply chain security. Hosted by Paul Roberts, director of editorial and content at ReversingLabs, ConversingLabs digs into cutting edge topics that are most pressing in the world of cybersecurity.

You Might Also Like