Episode 14: AI Risks, Threat Modeling, and The Future of Vibe Coding episode artwork

EPISODE · Jul 8, 2025 · 1H 22M

Episode 14: AI Risks, Threat Modeling, and The Future of Vibe Coding

from Distilled Security Podcast · host Justin Leapline, Joe Wynn, Rick Yocum and John Zeolla

Episode 14 of the Distilled Security Podcast is here!This week, the team welcomes guest John Zeolla, a cybersecurity expert and AI enthusiast, for a deep dive into the risks, realities, and potential of artificial intelligence.Topics include:Shadow AI in the Enterprise: Why business leaders are adopting AI faster than CISOs can assess the risks—and how features are outpacing controls.Third-Party AI Risk: Understanding vendor integrations with ChatGPT and others, and how contracts alone can’t guarantee security.Data Sprawl and Provenance: How uncontrolled data flows and poor identity scoping create dangerous exposure in generative AI platforms.Threat Modeling for AI: Why traditional frameworks like STRIDE still apply—and how techniques like “LLM as a judge” are reshaping modern risk analysis.Hallucinations, Misuse, and Insider Access: From AI-summarized HR documents to leaked board data, the team explores how improper permissions are amplified by intelligent agents.AI in Real Business Use: From customer support chatbots to code review tools, where AI adds value—and where it creates new points of failure.Governance and Culture: The role of CISOs, legal, and finance leaders in aligning AI ambition with responsible oversight.Bourbon Review – Elijah Craig Private Barrel Pick: A smooth 94-proof selection sponsored by Liberty Liquors (MD), bringing sweet caramel and balance to this week’s pour.BSides Pittsburgh Preview: With nearly 1,000 tickets sold, the team teases event highlights, panel interviews, and John's upcoming talk on "vibe coding."Timestamps00:00 – Welcome & Introductions02:20 – What’s “Shadow AI”?06:45 – Third-Party Risk & AI Integrations11:10 – Contracts ≠ Security14:00 – Data Sprawl & Identity Challenges19:05 – Threat Modeling for AI23:40 – “LLM as a Judge” in Risk Analysis28:15 – Hallucinations & Misuse Scenarios33:00 – Insider Access Amplified by AI36:30 – Real-World Use Cases (Chatbots, Code Review, etc.)41:55 – Governance, Culture & CISO Alignment48:20 – Bourbon Review: Elijah Craig Private Barrel52:30 – BSides PGH Preview & John’s “Vibe Coding” Talk57:00 – Final Thoughts & Wrap-UpHostsJustin Leapline – LinkedInJoe Wynn – LinkedInRick Yocum – LinkedInGuestJohn Zeolla – Zenable.ioConnect with UsWebsite: distilledsecuritypodcast.comTwitter: @DisSecPodEmail: [email protected]

Episode metadata supplied by the publisher feed · Published Jul 8, 2025

Embed this episode

Ready to play

Episode 14: AI Risks, Threat Modeling, and The Future of Vibe Coding

0:00 1:22:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Distilled Security Podcast?

This episode is 1 hour and 22 minutes long.

When was this Distilled Security Podcast episode published?

This episode was published on July 8, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Distilled Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!