On Absolute AppSec’s 335th episode this week, Seth (@sethlaw) and Ken (@cktricky) join Ron Perris to discuss integrating AI into secure software development and AppSec workflows. Perris details his work with Manicode.ai, founded alongside Jim Manico, which addresses LLM code generation defects by embedding language- and framework-specific positive security guidance directly into the AI's context window. To find this episode, head over to youtube.com/@AbsoluteAppSec/streams, or find us wherever you get your podcasts. Please leave us 5 stars on Apple Podcasts or Spotify.  If you want to catch us outside of 9am Pacific/12pm Eastern— we’re gonna be in London this winter for Black Hat Europe. Come catch our AI-Enhanced AppSec training on December 7th and 8th. 

❝

“We’ve installed this thing on people’s computers that’s a ventriloquist dummy for some remote intelligence. […] You can configure these harnesses. It’s code on your computer. It’s not AI attacking you from afar.”

Ron

Ron Perris worked on npm’s security team and at Reddit, and now works with Jim Manico at Manicode.ai. He opened with a point he thinks gets lost in the AI hype: LLMs never actually do anything. They return a stream of predicted tokens, and a harness like Claude Code decides whether to act on them. His example was a robot that tells a model where its joints are and asks how to cut an apple. The model happily plays along, but it’s the robot’s own code that moves the knife. Ron said this matters because the security teams he meets are mostly worried about agents running on developers’ computers. That fear grew after harnesses like OpenClaw took off in early 2026 by giving models broad access to Linux tools. Ken added that the hardest case isn’t shadow AI but approved use, like a marketing team running its own automations that no one in engineering owns. Ron’s take was reassuring: this is old system-security work. Sandboxes, virtual machines and SELinux-style policies already exist. Still, no company he’s talked to, from startups to banks, has fully figured out how to govern AI use yet.

❝

“Looking for known bad is not a valid security control, typically. It’s like having a house [with] a list of known criminals in your neighborhood on a list next to your door.”

Ron

The core of the episode was getting AI to write secure code. Ron described hearing Manico lecture in 2015 about defensive coding patterns and becoming a believer. Those patterns include parameterized queries to stop SQL injection and context-aware output encoding to stop cross-site scripting. Eleven years later, he admits developers haven’t really changed how they write code. But AI creates a choke point: if a model writes most of the code, you can teach the model. He doubted Manico’s claim that his AI guidance improved results, so he tested it with Meta’s open-source CyberSecEval framework. He saw a 30 to 40 percent drop in security-related mistakes. Manicode now uses harness hooks to detect a project’s language, framework and version, then loads the matching guidance into the model’s context. Its benchmark checks whether code follows the secure patterns. SAST tools instead scan for known bad patterns, which Ron says is still needed but is a separate check. Seth noted that models learned from a lot of insecure code, which only the major AI labs can fix. Ron added that the labs promote their offensive “cyber” skills, which amount to AI script kiddies, while avoiding their weak secure coding.

❝

“In my heart of hearts, I’d like to believe that [to target low-hanging fruit is] to reduce risk through eliminating defects that are easily avoided. In my actual professional experience, […] it’s just a risk blanket to say, we do something. We’re not totally negligent.

Ron

The last stretch turned to the security industry itself. Ron described walking the RSA show floor and offering vendors $50,000 a year for one valid, exploitable finding per quarter. Booth staff kept passing him up to architects and co-founders, and the answer was always the same: they could give him a thousand findings but couldn’t promise one real one. Ken picked up the thread with a rant about tool bake-offs where buyers pick whichever product produces the most alerts. He argued that a whole generation of AppSec practitioners now thinks managing bugs is the job, when the real goal is preventing them. Ron pointed to Reddit, where Matt Johansen kept asking why the same kinds of bugs kept showing up through bug bounty. Matt treated every repeat as a gap in the company’s libraries and tooling. Seth noted that few companies work that way, since most sit below the “security poverty line” with one AppSec person at best. That’s why both are hopeful that AI tools could bring secure defaults to teams that never had them. The group also agreed there’s still room for practitioner-focused events, and Ron plans to bring back LocoMocoSec in 2027.

Think about your mobile app’s source code. Once it hits the app store, it’s out in the wild. And without the right protection, decompiling is easy for malicious actors looking to steal your IP or tamper with your software.

That’s where Guardsquare comes in. Guardsquare provides the highest level of mobile app security for Android and iOS applications and SDKs. Their advanced tools integrate seamlessly into your CI/CD pipeline. We're talking polymorphic multi-layered code hardening techniques and automated runtime application self-protection, paired with mobile application security testing and real-time threat monitoring, to deliver the highest level of mobile app security without compromise.

Don't leave your hard work exposed. Secure your mobile applications today. Go to guardsquare.com to learn more.

Neiiiighhh. You can find it here:

* Unicorn sounds *

If you’re looking for a community, come join us on our Slack!

Stay Secure,

Seth & Ken

Episode 326 — AppSec Jobs, Benchmarking LLMs, Open Web Standards.  — Pairs well with the secure coding discussion. Seth and Ken talked about how LLM feedback loops can make code quality worse over time. 

Episode 328 — WordPress RCE, Vuln Prioritization, AI Memory Exfiltration. — Seth and Ken discussed eliminating whole classes of vulnerabilities and argued about how to prioritize findings. They also covered a prompt injection that steals data from Claude’s memory.

Episode 272 — New AI Tools, True Cost of False Positives — In this episode, which aired almost 2 years ago, Seth and Ken looked at the AI-integrated code review tools that were new at the time and at what false positives really cost AppSec teams. A good background listen for Ron’s RSA story about vendors offering a thousand findings but not one guaranteed valid one, and Ken’s rant about bake-offs won by the noisiest tool.

Absolute AppSec Happenings

Napoleon’s 217-year-old coded message ‘cracked by AI’ — OpenAI’s GPT-6 Astra was able to decrypt a 1,300-character letter—the contents of which have been unknown for more than two centuries. Turns out it contained details of the French and Austrian forces. 

CVEs Published per Day, One Turn per Year — Sometimes a good data visualization method will say more than words ever could.

Meta Rushed to Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch — According to 404 Media, Meta found several flaws in its Muse AI agent shortly before launch, including at least one that could let a user escape Muse’s isolated virtual machine and reach Meta’s internal systems. Security teams rushed out quick fixes to keep the early-September launch on schedule. An internal source called the fixes half-baked, and researcher Patrick Wardle said putting production one KVM escape away is irresponsible 

Upcoming Events

Where in the world are Seth and Ken?

SaintCon - October 27-30, 2026 - AppSec Community, Speaking - https://saintcon.org/

Black Hat Europe 2026 - December 7-8, 2026 - AI-Enhanced AppSec: Black Hat Edition - https://blackhat.com/