Using LLMs for Vuln Discovery – Rishi Sharma – ASW #395
Rishiraj Sharma is Co-Founder and CEO of ProjectDiscovery.
Sharma has over 10 years of experience in cybersecurity, starting as a pentester and security engineer. He worked at several companies including Cox Automotive, handling AppSec, infrastructure, and compliance security.
ProjectDiscovery is an open source cybersecurity company that created Nuclei, an open source vulnerability scanner with over 10 billion scans run, along with a suite of modular tools, including Subfinder, httpx, and Naabu, that security teams use to map attack surfaces and identify exploitable vulnerabilities across their organizations. Building on that foundation, ProjectDiscovery offers Neo, an AI-powered security testing platform that unifies SAST, DAST, and automated penetration testing to help teams move from finding vulnerabilities to verifying and fixing them.
- Threat intelligence should help you decide what to fix, but most of the time it’s disconnected from your code, your pipelines, and your actual risk.So how do you make it relevant to AppSec?At the Threat Intelligence Virtual Cybersecurity Summit on August 26th, learn how to apply intel to vulnerability prioritization and focus on what’s truly exploitable.Security Weekly listeners can register for free at https://securityweekly.com/threatintel using the promo code: CSS26-SW
- InfoSec World brings cybersecurity professionals together across industries, from healthcare and financial services to government and the Fortune 500. Join the community in Orlando, October 12–14, for practical education, new perspectives, and cybersecurity research unveiled live. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Mike Shema
- Can AI do novel security research? Meet the HTTP Terminator
- CSS:the bomb inside your inbox | PortSwigger Research
- Apple’s ‘Private Relay’ Is Exposing Users’ Real IP Addresses
And be sure to read the technical write-up.
- FYI: Off-by-1 Labs Research: AI-generated vulnerability patches require human review | 1Password
Here's the research we talked about last week with Keith Hoodlet in episode 394.
- FYI: Zenity Labs Discloses PleaseFix Vulnerability Family in Perplexity Comet and Other Agentic Browsers
We didn't cover this when it first came out, but it won a Pwnie at this year's DEF CON. AI-driven browsers are a bad idea and this research essentially shows how to turn social engineering against humans (i.e. ClickFix) into prompt injection against browsers (aka PleaseFix).
