Ga naar de inhoud
PodcastsCarrièresRelating to DevSecOps

Relating to DevSecOps

Ken Toler and Mike McCabe
Relating to DevSecOps
Nieuwste aflevering

85 afleveringen

  • Relating to DevSecOps

    Episode #084: No Humans Required: Agentic Attackers vs. Automated Defenders

    24-07-2026 | 46 Min.
    Send us Fan Mail
    AI is changing the economics of cyberattacks by making them faster, cheaper, and easier to scale. In this episode of Relating to DevSecOps, Ken is joined by Conor Sherman, Chief Security Officer at Sysdig and host of the Zero Signal podcast, to explore what the rise of agentic threat actors means for defenders.

    Using the Jade Puffer ransomware attack as a real-world example, they discuss how autonomous attackers can discover vulnerabilities, compromise environments, move laterally, adapt their code, identify valuable data, and deploy ransomware with little human involvement.

    The conversation also looks at how defenders can respond through stronger security architecture, automated patching, real-time detection, automatic response, and AI-assisted modernization. Rather than replacing security fundamentals, AI can help teams apply them faster, handle difficult edge cases, and build more resilient systems.

    For security teams wondering where to begin, the message is simple: start small, automate one meaningful workflow, and build from there.
  • Relating to DevSecOps

    Episode #083: AI Mythos, Security Fundamentals, and the Zero-Day Panic Cycle

    29-04-2026 | 43 Min.
    Send us Fan Mail
    Ken and Mike are back in the AI trenches, this time unpacking the hype, fear, and practical security implications surrounding Anthropic’s Mythos preview. As the industry reacts to claims around AI-driven vulnerability discovery and exploit generation, the hosts ask a more important question: are we actually ready to fix what we already know is broken?
    The conversation cuts through the zero-day panic and focuses on the fundamentals that still matter: patching, hardening, reducing attack surface, validating AI-generated code, and keeping deterministic security checks in place. From supply chain attacks and GitHub Actions misconfigurations to agentic development workflows and the future of CI/CD, Ken and Mike explore where AI may genuinely change the threat landscape and where security teams are still fighting the same old battles.
    If your organization is rushing to build faster with AI, this episode is a reminder to also use it to build better.
  • Relating to DevSecOps

    Episode #082: AI Hype, Human Cost

    17-03-2026 | 44 Min.
    Send us Fan Mail
    Ken and Mike are back from the grave to kick off 2026 with a timely debate on the AI panic cycle hitting software and security. They dig into the biggest questions flying around the industry right now: Is AI taking developer and security jobs? Is SaaS dying? Is software engineering being replaced by vibe coding and agents? From maker-checker workflows and token costs to AI-generated bugs, false positives, and attackers using autonomous tooling to move faster, this episode cuts through the hype from both the doomer and evangelist camps. The conclusion: software isn’t dead, security definitely isn’t solved, and the teams that adapt their craft instead of abandoning it will be the ones that keep up.
  • Relating to DevSecOps

    Episode #081: Burnout by Budget Season: Surviving Q4 in Security

    29-10-2025 | 21 Min.
    Send us Fan Mail
    In this candid and cathartic episode, Ken and Mike unpack the chaos that is Q4 for security professionals. From budget burnouts to end-of-year pentesting sprints, they explore why the final months of the year feel like a perfect storm for stress. Tune in as they share hard-earned lessons, practical advice for maintaining your sanity, and some gentle reminders that not everything needs to ship before Christmas. Whether you’re a tired vendor, an overwhelmed engineer, or just trying to make it to PTO, this episode is for you.
  • Relating to DevSecOps

    Episode #080: Patch Me If You Can: Compliance, SLAs, and Other Fairytales

    25-08-2025 | 34 Min.
    Send us Fan Mail
    In this no-punches-pulled return from hiatus, Ken and Mike dig deep into the messy middle of vulnerability management, SLA fatigue, and the illusion of compliance. Are we building secure systems or just passing audits? From legacy cruft to exploitable CVEs, this episode unpacks the real-world pressures of SOC 2, the auditor dance, and whether fixing every “critical” is even feasible.

    Perfect for practitioners trying to balance the checkbox culture with actual risk reduction, this one’s got stories, strategies, and spicy takes. Bonus: tips on managing auditors without losing your mind—or your security posture.
Meer Carrières podcasts
Over Relating to DevSecOps
A Podcast dedicated to forging iron clad relationships between developers, engineers, operations, and security practitioners by discussing hot topics in the world of DevSecOps. This podcast aims to air out some of the common gripes, misconceptions, and hardships that these teams face in the real world every day.
Podcast website

Luister naar Relating to DevSecOps, 180 Graden en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies