Jon Green

speaker
145 appearances 1 recordings 1 series first heard Aug 2026 last heard 6 Aug

Jon Green’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
1 · Aug OctJan 26AprJulnow

Recordings per month over the last 12 months — 1 in all, peaking in Aug 2026 with 1.

Appearances

newest first · ▶ plays the moment
When I talked about these models being good at creating exploits, that's key to it because it will produce false positives.
It will look at something and not understand the context of what that code is necessarily doing.
There are limits in terms of just context window of how much of the code base it can pull in and reason over at any given time.
So the ability to put it into an agentic loop to say, this agent here is gonna do an analysis of the code.
This other one's going to try to create an exploit to trigger the vulnerability that the first agent thinks it found.
And then we're gonna test it live against a real product and see if something happens.
And if nothing happens, it goes back through that loop again and says, let's try again.
And so when we come out of something, if we've got an actual finding,
something did take place.
Now the human still needs to look at that because the AI is only as smart as it's training and it's going to encounter conditions, especially with network hardware, server hardware, storage hardware that it hasn't seen before.
And so it may interpret an action that took place as being a vulnerability when it actually isn't.
So we're not going full cycle into, well, the AI found the vulnerability.
Now the AI will go auto patch the vulnerability, right?
That I think we're still a little bit far off from, but we've greatly accelerated the discovery cycle.
Absolutely.
We've tended to approach this vulnerability management in the past of let's apply automated scanners and there's various tools out there that we can get.
And we'll wind up with some degree of findings and they'll all have scores attached to them, low, medium, high, etc.,
And there's often a pressure to ship a product and people say, OK, well, we're going to take care of the criticals and the highs, but the rest we're going to push down the line because we don't think they matter all that much.
This changes all of that.
I think things like CVSS scores, which are what we use to rate the severity of a vulnerability, I think they become nearly worthless at this point because the AI has shown it can take severity vulnerabilities and chain them together and get something that's much more powerful.
Showing 41–60 of 145 · page 3 of 8 ← Previous Next →