How Adobe Uses AI Agents for building a WAF Pipeline?
Aug 4, 2026 · 47m
Summary
Ammar Aleem from Adobe discusses building an agentic AI pipeline to automate Web Application Firewall rule generation for new CVEs. He explains how this system reduces the vulnerability exploitation window from weeks to hours by creating virtual patches faster than manual patching. The episode details the technical architecture, including using AI agents for research, rule creation, and testing, while emphasizing the critical need for speed in modern cloud security.
Topics discussed
Intro: Speed as the currency of security and AI in WAF
Guest intro: Ammar's journey from cloud to AppSec to AI
The complexity of managing multiple WAF vendors
AI's role in reducing false positives and negatives
Rising threat speed: From months to hours for exploits
WAF as '911': Virtual patching vs. long-term fixes
Automated pipeline: Detecting CVEs and generating rules
Building the AI harness: Context, memory, and agents
Reinforcement learning and training the agent system
Applying AI to industry standards like OWASP Top 10
Advice: Start with 10% automation for tedious tasks
Outro: Connect with Ammar and show resources
Listen ad-free on Castria