The Elephant in AppSec
Avsnitt

The Docker mistakes everyone's still making and how to fix them with Advait Patel

Dela

Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.


In this episode, we get into:

  • Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matter

  • The AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attacker

  • Why you should treat AI as an assistant on a leash, not an engineer with root access

  • the Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image)

…and much more!

Get ready, Advait doesn't hold back his opinions. Let's dive right in!

Connect with Advait: https://www.linkedin.com/in/advaitpatel93/

Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/

This podcast is brought to you by

Escape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions.

Mentioned

DockSec on GitHub (now the OWASP org repo): https://github.com/OWASP/DockSec

OWASP project page: https://owasp.org/www-project-docksec/

Open Policy Agent (his "open policy" reference): https://www.openpolicyagent.org/

OWASP Top 10 for LLM Applications: https://genai.owasp.org/

Podden och tillhörande omslagsbild på den här sidan tillhör The Elephant in AppSec. Innehållet i podden är skapat av The Elephant in AppSec och inte av, eller tillsammans med, Poddtoppen.