The MonkCast

RedMonk

Join the developer-focused industry analysts at RedMonk as they discuss news and trends in the software space with leaders and practicioners in cloud, AI, IaC, security, DevOps, developer relations, observability, data, and more. Can't get enough of the Monks? Visit the RedMonk YouTube channel or check out our research at RedMonk.com. You can also follow RedMonk on Bluesky, Twitter (X), and LinkedIn. Meet RedMonk's AnalystsJames Governor, Principal Analyst & Co-founder @monkchips, LinkedIn, Blog Stephen O'Grady, Principal Analyst & Co-founder @sogrady, LinkedIn, Blog Rachel Stephens, Research Director @rstephensme, LinkedIn, Blog Kate Holterhoff, Senior Industry Analyst @KateHolterhoff, LinkedIn, Blog

  1. May 21

    Tanya Janca on AI Slop, Vibe Coding, & the Future of AppSec

    Kate Holterhoff sits down with Tanya Janca, Secure Coding and AI Trainer at SheHacksPurple, to talk about what AI is doing to application security. Tanya's take: we're driving a car at three times the speed limit after 25 beers. AI writes huge portions of production code, most developers were never taught to review code for security in the first place, and release velocity keeps climbing. The conversation gets into the difference between using AI to help you code and full-on vibe coding, why context collapse trips up LLMs on security decisions, and what's wrong with bolting AI onto legacy AppSec tools instead of building new ones. Tanya also weighs in on Anthropic's Mythos vulnerability-finding model, argues that the bug bounty economy is heading for collapse, discusses supply chain security and the future of the SDLC, and wraps by explaining Canada's Petition E-7115, which Janca helped draft to require secure coding standards across the Canadian federal government. Show notes: https://redmonk.com/videos/tanya-janca/ Chapters 00:00 Introduction to AI and Security 02:58 The Current Security Landscape 05:49 Understanding Context Collapse in AI 09:51 The Role of Vibe Coding 13:50 Teaching Security in the Age of AI 16:45 The Need for New Security Tools 25:02 The Evolving Role of Bug Bounties 27:50 The Future of Pen Testing in an AI World 30:01 The Evolving Role of Application Security 31:46 Reimagining the Software Development Lifecycle 40:54 Rethinking Supply Chain Security 48:37 Advocating for Secure Coding Legislation

    57 min
  2. Apr 16

    Beyond the Hypervisor: Developing with Ubuntu on VCF

    Infrastructure gets written off as table stakes, but if you've actually shipped software, you know how much pain comes from the friction between layers of the stack. In this RedMonk Conversation, Rachel Stephens sits down with Jay Thontakudi, Principal Product Marketing Manager at Broadcom, to dig into why the partnership between VMware Cloud Foundation (VCF) and Canonical is more than "Linux runs on VMware." The conversation gets at a problem most enterprises quietly live with: developers build on Ubuntu, then watch their code land on a different Linux distribution in staging and production. Jay and Rachel talk through what it means to close that gap, and why treating the hypervisor and the OS as one supported thing rather than two vendors pointing fingers is as much a security story as it is a developer experience one. For additional information please visit: - https://vmware.com/products/cloud-infrastructure/vmware-cloud-foundation - https://canonical.com This RedMonk conversation is sponsored by VMware by Broadcom. Show notes: https://redmonk.com/videos/ubuntu-on-vcf/ Chapters: 00:00 - Introduction 02:06 - What is VCF? 03:55 - The Broadcom & Canonical Partnership 05:58 - Why Ubuntu? Bridging the Dev-to-Production Disconnect 08:18 - Security & Stability: A Unified Stack and Support Model 10:12 - Why Developer Experience is Security 11:21 - VMware's Open Source Strategy 15:24 - Conclusion & Upcoming Technical Deep Dive

    16 min
  3. Apr 7

    "Absolute AI Maximalist" Adam Jacob on Building Software That Builds Software

    Stephen O'Grady sits down with Adam Jacob, CEO and Co-Founder of System Initiative, for a candid conversation about what it actually feels like to build software in the age of AI agents. Adam describes his team's decision to go "absolute AI maximalist," letting a five-person crew produce 150,000 lines of TypeScript that no human has fully read, and why that experience broke every assumption he had about estimation, trust, risk, and team dynamics. The two trace the emergence of three distinct camps in the developer world: skeptics, cautious adopters still treating AI as fancy autocomplete, and a growing third group who are no longer writing the software they ship but instead building the systems that build it. Adam argues the shift is less about cost reduction than raw velocity—an orders-of-magnitude increase in pressure that will burst every existing process, compliance framework, and social norm in software development. Along the way, they explore why the old practice of user acceptance testing is suddenly relevant again, why domain-driven design matters more than ever when you can't read every line of code, and why the magnitude of this transition may rival the transistor. Adam closes with practical career advice for engineers: learn software architecture, study systems design, and start building agents at home, because the people who understand how to construct the machine that constructs the software will define the next era. Show notes: https://redmonk.com/videos/adam-jacob-ai-maximalist Chapters 00:00 Introduction to AI and Reality 01:42 Adam's Journey with AI 05:19 The Shift to AI Maximalism 09:49 The Three Camps of AI Users 12:41 Building Software with AI 19:23 Implications of AI on Software Development 23:52 Navigating the Evolving Landscape of Software Development 29:38 The Impact of AI on Software Engineering 35:15 The Infinite Demand for Software 43:41 Career Advice for Aspiring Engineers

    50 min
  4. Apr 3

    Sovereignty Meets Simplicity for VMware by Broadcom at KubeCon EU 2026 w Timmy Carr & Himanshu Singh

    At KubeCon EU 2026 in Amsterdam, James Governor sits down with VMware by Broadcom's Timmy Carr and Himanshu Singh to unpack how VMware is tackling two of the biggest challenges facing European enterprises today: complexity and sovereignty. The conversation explores how VCF and VKS are designed to simplify Kubernetes adoption for IT and platform teams, offering a fully declarative API that unifies the management of VMs, containers, and AI workloads under one consistent operational model. The discussion then turns to digital sovereignty, where Timmy and Himanshu explain how VCF's flexible deployment options—from on-prem data centers to sovereign cloud providers—help organizations keep data and workloads within regulatory boundaries. They also dig into VMware's ecosystem strategy, emphasizing CNCF-certified compatibility and recent validations with partners aimed at ensuring VKS can serve as a drop-in replacement for any Kubernetes runtime. This RedMonk conversation is sponsored by VMware by Broadcom. Show notes: https://redmonk.com/videos/sovereignty-meets-simplicity-for-vmware-by-broadcom-at-kubecon-eu-2026 Chapters: 00:00 Introductions from KubeCon EU Amsterdam 00:47 Cloud-Native Complexity Needs Simplification 01:44 VCF and VKS Simplify Kubernetes 04:04 Declarative APIs for Platform Teams 05:21 Digital Sovereignty in Europe Today 05:55 Deploying VCF for Sovereign Clouds 07:47 Private AI, Security, and Compliance 09:36 Building the Partner Ecosystem 10:05 Bring Your Own CNI 12:09 Validations with F5, Tigera, Kong 14:16 Drop-In Kubernetes Runtime Replacement 14:45 Wrap-Up and Final Thoughts

    16 min

About

Join the developer-focused industry analysts at RedMonk as they discuss news and trends in the software space with leaders and practicioners in cloud, AI, IaC, security, DevOps, developer relations, observability, data, and more. Can't get enough of the Monks? Visit the RedMonk YouTube channel or check out our research at RedMonk.com. You can also follow RedMonk on Bluesky, Twitter (X), and LinkedIn. Meet RedMonk's AnalystsJames Governor, Principal Analyst & Co-founder @monkchips, LinkedIn, Blog Stephen O'Grady, Principal Analyst & Co-founder @sogrady, LinkedIn, Blog Rachel Stephens, Research Director @rstephensme, LinkedIn, Blog Kate Holterhoff, Senior Industry Analyst @KateHolterhoff, LinkedIn, Blog

You Might Also Like