Cloud Security Podcast Cloud Security Podcast

How Adobe Uses AI Agents for building a WAF Pipeline?

Aug 4, 2026 · 47m

Summary

Ammar Aleem from Adobe discusses building an agentic AI pipeline to automate Web Application Firewall rule generation for new CVEs. He explains how this system reduces the vulnerability exploitation window from weeks to hours by creating virtual patches faster than manual patching. The episode details the technical architecture, including using AI agents for research, rule creation, and testing, while emphasizing the critical need for speed in modern cloud security.

Topics discussed

Intro: Speed as the currency of security and AI in WAF Guest intro: Ammar's journey from cloud to AppSec to AI The complexity of managing multiple WAF vendors AI's role in reducing false positives and negatives Rising threat speed: From months to hours for exploits WAF as '911': Virtual patching vs. long-term fixes Automated pipeline: Detecting CVEs and generating rules Building the AI harness: Context, memory, and agents Reinforcement learning and training the agent system Applying AI to industry standards like OWASP Top 10 Advice: Start with 10% automation for tedious tasks Outro: Connect with Ammar and show resources
Listen ad-free on Castria