Mona Lisa graffiti

Photo by T on Unsplash

In the beginning was command injection. So developers created functions to declare explicit parameter names and values.

Then came SQL injection, so developers created functions with parameter placeholders.

Then came HTML injection, so developers created XSS-avoidant frameworks.

That was followed by prompt injection, so developers created more prompts.

Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 (ep. 399)

We took the first Monday off to showcase four interviews recorded at this year's Black Hat.

  • The Hidden Risks of the AI Supply Chain – with an expanding attack surface of skills and prompts that recommend malicious packages.
  • After Mythos: Securing Frontier AI as Attack and Defense Accelerate – why vuln volumes require more proactive security controls.
  • The Perfect Storm: When AI Writes the Code and Sharpens the Attacks – how to succeed when agents write and review code.
  • Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack – on the importance of building context about systems and their environment as part of the context given to LLMs.

Unsurprisingly, agents, LLMs, and MCPs dominated Black Hat discussions.

The AI Threat Multiplier: Securing Mobile Apps in the Automated Era (ep. 400)

Agents and LLMs haven't fundamentally changed mobile vuln classes, but they have supercharged attacks against those vulns — democratizing threats like phishing (of many flavors), synthetic identity fraud, and (still!?) finding hard-coded secrets.

Ryan Lloyd and Jason Cortlund broke down how threat actors leverage LLMs for efficiency and scale in decidedly familiar attacks. Then we discussed practical defense strategies, from considering agents as active adversaries to managing server-side threat telemetry to drawing on client-side attestation.

This segment was sponsored by Guardsquare.

Understanding Prompt Injection In Order to Contain It (ep. 401)

Prompt injection continues the long tradition of allowing user-supplied text to change the behavior of developer-intended code. It doesn't need the syntax of SQL or the DOM of XSS, just some content that gets turned into tokens.

Julie Brunias joined us to talk through examples of injections, how their consequences can go beyond information leaks, and why trying to mitigate them with other LLMs is insufficient. Prompt injections are a challenge that reinforces why standard appsec principles of isolation, granular access controls, and monitoring remain relevant to agents, MCPs, and all the other places where LLMs are lurking.

Going From Bug Bounty Bugs to More Secure Systems (ep. 402)

Finding flaws with LLMs and agents is changing bug bounty programs, but it's not always changing how orgs fix those flaws.

Shlomie Liberow shared his experience across a decade of bug bounty programs and how they have changed for researchers and orgs. He explained why fixing the bug reported through a bug bounty is more about understanding interconnected systems than fixing a single piece of software.

Then we discussed how orgs can be more effective at securing their environment and the role of LLMs in evaluating appsec controls. Plus, we looked to the future of these programs, talking about how researchers can still excel through curiosity and expertise on a topic rather than relying on scanners, prompts, and luck.

Subscribe to catch these episodes and more! Then go check out the previous recap.