This week on Absolute AppSec. Seth (@sethlaw) and Ken (@cktricky) have finally returned after back-to-back trainings at Black Hat and DEF CON. To kick off their return, they’re once again joined by Jeevan Singh to discuss his new approach to methodically fixing vulnerabilities in this new AI world. He calls this concept “Vulnerability Jail”. To find this episode, or to tune back in to our regularly scheduled programming, head over to https://www.youtube.com/@AbsoluteAppSec/streams. Catch us live there at 9:00 AM PST/12:00 PM EST, or you can find us on your favorite podcast streaming programs.
Jeevan is a prominent figure in the AppSec community, known for his work in democratizing vulnerability management and his leadership within OWASP, where he runs the Vancouver chapter. Singh built his reputation at Segment and Twilio, where he developed a pragmatic approach to threat modeling for developers, before moving into a directorial role following Segment’s acquisition by Twilio. He now leads the security engineering team at Rippling. Throughout his career, he has focused on the intersection of technical excellence and organizational culture, advocating for personal growth over merely climbing the corporate ladder.
“I think I’m more fearful [of AI] now than I was three years ago. Things are moving so fast and [I’m] just trying to stay on top of things. I think that’s the biggest challenge in itself.”
Jeevan opened by describing how his product security org at Rippling has grown from five engineers to eighteen or nineteen over roughly three years, sitting inside a fifty-person security engineering group and landing at close to a one-to-sixty ratio against the broader engineering headcount. He credited that ratio, and genuine executive buy-in, for letting his team write real production code rather than just flag issues, including an internally built SSRF-prevention library rolled out company-wide, something both hosts singled out as the ideal version of product security. Ken contrasted that with his own consulting experience, where he regularly sees five or six hundred developers backed by only two security staff trying to cover DevSecOps, AppSec, and GRC at once, calling Rippling's setup a rare change of pace. Even with a well-resourced team, Jeevan said he feels more fearful now than he did three years ago, pointing to faster-moving threats like malicious open-source packages and vague new pressure to prove "agentic readiness," which he suspects is as much a manufactured expectation as a genuine technical risk.
The episode's centerpiece was vulnerability jail, born after Rippling's democratized vulnerability management approach stalled under sheer volume; that model, which worked well at Segment and Twilio, let engineering managers approve extensions for low and medium bugs while VPs or the CEO signed off on highs and criticals, but Rippling's VPs couldn't keep pace with requests. Vulnerability jail raises the stakes: once a bug blows past its SLA, the responsible team can still open pull requests but is blocked from merging into Rippling's monolithic default branch, halting their ability to ship until the fix lands. Jeevan stressed this only worked because he secured CTO and CISO alignment first, having the CTO announce it at an all-hands to take the heat off security. Ken called it "an extreme version" of democratization, and both hosts liked that it rolled out manually at first, with safety nets like auto-extending SLAs when ownership was assigned late and auto-closing tickets once scans confirmed a fix. After the Mythos wake-up call and the OpenAI and Hugging Face story, Rippling tightened SLAs from seven/thirty/ninety/one-eighty days to three/five/seven/ten and ran leadership-attended war rooms that cleared as many as 430 vulnerabilities in one week.
“It’s much easier to teach an engineer security than a security person how to do engineering work.”
Both hosts and Jeevan agreed security teams no longer have a choice about using AI, since vulnerabilities surfaced partly by AI-assisted bug bounty researchers now outpace what humans can triage manually; Rippling routes SLA extension requests to an AI reviewer that judges whether a plan and timeline are aggressive enough before a human sees it. Seth pushed back hard on auto-generated pull requests that fix vulnerabilities unattended, saying he's "never seen it work" and would need a case study to change his mind; Jeevan's own numbers backed that up, with only fifty to sixty percent of AI-drafted fixes merged as-is, so Rippling still prefers framework-level fixes. Jeevan also described using abstraction layers so the team can swap frontier and open-weight models as pricing shifts, noting one major model actually disappeared mid build-out. Recalling a Black Hat talk on the OpenAI and Hugging Face incident, everyone marveled at agents that, after losing file-upload access, began communicating through directory names instead. Jeevan predicted his own job is safe for two more years given the chaotic agentic landscape, and advised newcomers to become real engineers first, build open-source projects, and be ready to discuss how they've used AI to solve hard problems.
Think about your mobile app’s source code. Once it hits the app store, it’s out in the wild. And without the right protection, decompiling is easy for malicious actors looking to steal your IP or tamper with your software.
That’s where Guardsquare comes in. Guardsquare provides the highest level of mobile app security for Android and iOS applications and SDKs. Their advanced tools integrate seamlessly into your CI/CD pipeline. We're talking polymorphic multi-layered code hardening techniques and automated runtime application self-protection, paired with mobile application security testing and real-time threat monitoring, to deliver the highest level of mobile app security without compromise.
Don't leave your hard work exposed. Secure your mobile applications today. Go to guardsquare.com to learn more.
Someone was rocking our Unicorn Tee at our meetup in Vegas this year. Jealous? You can find it here:

* Unicorn sounds *
Join us in our Slack; just send us a note to join the channel. As long as you promise not to impersonate us (again), you can sit down, relax, and stay a while.
Stay Secure,
Seth & Ken
https://youtube.com/live/gYSh2lFKj74 – Episode 224 w/ Jeevan Singh - Threat Modeling — Jeevan is a long-time friend of the pod. Tune into his previous episodes.
https://youtube.com/live/R5Eca_H7mxA – Episode 327 w/ Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization — A more tactical companion piece to the points on SLA-tiering and severity-based enforcement mechanics.
https://youtube.com/live/ySRYhAjc05I – Episode 320 w/ @lojikill - LLM Bug Hunting, AI OffSec, Defender Burnout - If you wanted to hear more about Jeevan’s point that bug bounty researchers are increasingly leaning on AI, tune in to here what @lojikill has to say.
Absolute AppSec Happenings
Smile, You’re on Camera: A Live Stream from Inside Lazarus Group’s IT Workers Scheme — Haven’t stopped thinking about this article since I saw the coordinating talk at DEF CON this year. Worth going into it blind!
The ‘Breaking’ News: The OpenAI-Hugging Face Incident — Straight from the horse’s mouth: OpenAI security team walks Black Hat attendees through the recent Hugging Face security incident. We want to hear your thoughts on this one.
Upcoming Events
Where in the world are Seth and Ken?
Stay tuned!

