ABOUT THIS EPISODE
In this episode, Nico Waisman, CISO at XBOW, explains how XBOW uses autonomous AI agents to run continuous, incremental penetration testing without triggering false-positive avalanches or taking down production systems. Joining him are Jacob Combs, CISO at Tandem Diabetes Care, and Davi Ottenheimer, president at Flying Penguin.
Want to know:- Why can't traditional pen tests keep up with modern attack surfaces?
- How XBOW's attack credit model maps to the way security teams already size testing effort?
- What stops an autonomous pen testing agent from causing real damage in production?
- How incremental testing works when a new pull request changes the application?
- Where XBOW is headed on prompt injection and LLM-specific vulnerabilities?
- How you audit what the AI actually did during an assessment?
- What novel vulnerability chains are emerging as AI reasoning models get more capable?
Check out the episode for the answers you need.
Huge thanks to our sponsor, XBOW
English
United States
TRANSCRIPT 🔗
Are you the producer of this podcast?
Add a podcast transcript
Need Audio-to-Text?
Transcribe with Listen411 in Just 60 Seconds
SEARCH PAST EPISODES
Search past episodes of Security You Should Know.
OTHER EPISODES IN THIS PODCAST
In this episode, Grant Oviatt, vp of product and co-founder at Prophet Security, explains how his platform deploys AI agents to investigate and respond to alerts the way a skilled analyst would, using REST API integrations across existing security tools rather than absorbing all your data into an…
In this episode, Cassio Goldschmidt, co-founder and CTO at Reflex Security, explains how Reflex replaces static, script-driven tabletops with adaptive AI-driven simulations that fight back, measure real human behavior under pressure, and surface the gaps that scripted exercises never reach. Joining…
In this episode, Ryan Lloyd, Chief Product Officer at Guardsquare, explains how the platform combines code obfuscation, runtime integrity checks, and real-time threat monitoring to secure mobile apps at the binary level, integrated directly into the CI/CD pipeline. Joining him are TC Niedzialkowski…
In this episode, Venkat Siva, co-founder and CEO at CompFly AI, explains how his platform gives security, engineering, and business teams a control plane for autonomous AI agents across their full lifecycle. CompFly discovers agents, assigns each one a verifiable distributed identity, runs adversar…
Disclaimer: The podcast and artwork embedded on this page are from CISO Series, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
EDIT
Thank you for helping to keep the podcast database up to date.