EPISODE · May 4, 2026 · 57 MIN
A Conversation with AI Security Pro Steve Wilson
from Live with Tim O’Reilly · host O'Reilly
Steve Wilson’s day job is at cybersecurity firm Exabeam, where he’s the chief AI and product officer. He also founded and cochairs OWASP’s Gen AI Security Project and wrote The Developer’s Playbook for Large Language Model Security. So he knows a thing or two about the ways AI is creating entirely new attack surfaces that most developers don’t even know exist. On this episode of Live with Tim O’Reilly, Steve shared some eye-opening warnings about the security risks we may be missing.Steve and Tim started with the hidden dangers of “vibe coding”—the emerging practice of using AI to generate software. “We are in an AI arms race at this point,” he explained, where “every hacker group from Russia to North Korea to a script kitty in his basement in South Africa now has access to world-leading AI.” The conversation then turned to how hackers are exploiting AI hallucinations to convince unwary devs to open malicious packages, the dangers of exposing secrets while livestreaming to thousands of viewers (they’re called “secrets” for a reason), and why running “open source” AI models locally might actually bring foreign adversaries inside your firewall.But it wasn’t all risks. Steve also discussed practical methods for defending against sophisticated AI-enabled attackers, like using ChatGPT to audit code security and integrating traditional security scanners with AI development workflows. Along the way, he and Tim explored the emergence of new roles like “agent engineers,” and Steve weighed the relative security strengths and weaknesses of various major AI players.
Embed this episode
NOW PLAYING
A Conversation with AI Security Pro Steve Wilson
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.