Secure Code Reviews, LLM Coding Assistants, and Trusting Code - Rey Bango, Karim Toubba, Gal Elbaz - ASW #330
开发者依赖LLMs作为编码助手,但应用安全领域仍需建立对AI生成代码的信任。中小企业在快速拥抱SaaS和AI应用时面临技术复杂性和应用蔓延的挑战。LastPass通过“Secure Access Experiences”提供解决方案,而Cloud Application Detection and Response (CADR)技术则为应用安全带来新变革。 2025-5-13 09:0:0 Author: sites.libsyn.com(查看原文) 阅读量:8 收藏

May 13, 2025

Developers are relying on LLMs as coding assistants, so where are the LLM assistants for appsec? The principles behind secure code reviews don't really change based on who write the code, whether human or AI. But more code means more reasons for appsec to scale its practices and figure out how to establish trust in code, packages, and designs. Rey Bango shares his experience with secure code reviews and where developer education fits in among the adoption of LLMs.

As businesses rapidly embrace SaaS and AI-powered applications at an unprecedented rate, many small-to-medium sized businesses (SMBs) struggle to keep up due to complex tech stacks and limited visibility into the skyrocketing app sprawl. These modern challenges demand a smarter, more streamlined approach to identity and access management. Learn how LastPass is reimagining access control through “Secure Access Experiences” - starting with the introduction of SaaS Monitoring capabilities designed to bring clarity to even the most chaotic environments. Secure Access Experiences - https://www.lastpass.com/solutions/secure-access

This segment is sponsored by LastPass. Visit https://securityweekly.com/lastpassrsac to learn more about them!

Cloud Application Detection and Response (CADR) has burst onto the scene as one of the hottest categories in security, with numerous vendors touting a variety of capabilities and making promises on how bringing detection and response to the application-level will be a game changer. In this segment, Gal Elbaz, co-founder and CTO of Oligo Security, will dive into what CADR is, who it helps, and what the future will look like for this game changing technology. Segment Resources - https://www.oligo.security/company/whyoligo

To see Oligo in action, please visit https://securityweekly.com/oligorsac

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-330


文章来源: http://sites.libsyn.com/18678/secure-code-reviews-llm-coding-assistants-and-trusting-code-rey-bango-karim-toubba-gal-elbaz-asw-330
如有侵权请联系:admin#unsafe.sh