Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402
Sep 29, 2026 · 1h 2m
Summary
In this episode of Application Security Weekly, host Mike Shima and guest Adrian Sinabria discuss the evolving landscape of bug bounties in the AI era. They explore how LLMs and automated agents are changing the economics of vulnerability discovery, shifting focus from simple CVE hunting to creative, system-level flaws and parser differentials. The conversation highlights the limitations of traditional vulnerability management queues and argues for a more proactive, structural approach to security that addresses root causes rather than just patching individual tickets. The segment concludes…
Topics discussed
Intro: AppSec, CVSS, and the problem of wasted bug tracking
Episode 402 intro and guest Shom Liow background
The evolving economics and creativity required in bug bounties
LLMs, obscurity, and finding an edge in modern security
Anecdote: Creative data exfiltration via email hashing
The explosion of CVEs and the shift from CVSS to exploitability
Sponsor: Guardsquare mobile app security
The controversy of CVE drops and the value of proactive hunting
Rethinking vulnerability management and prioritization strategies
Building systems assuming zero-days and no patches
The limits of automated vulnerability scanning and LLMs
Targeted vs. opportunistic breaches in the AI era
Systemic root cause analysis and contextualizing security data
LLM-generated code, integration complexity, and parser differentials
Advice for researchers: Predictability, legacy code, and curiosity
Defining AppSec in three words and closing the interview
News: Meta Muse local privilege escalation on macOS
News: Rust Miri caching secrets in GitHub Actions
News: Pre-auth RCE in legacy TAC+ via format string
News: Google's PageBreak, bug age, and the 'right once' myth
Listen ad-free on Castria