Videos 7JgIS42mz7U
The AI bugpocalypse is here. Now what? - Jack Cable, Corridor
Scene timeline
42 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 157
- whisperx 157
- chunks
- 34
- from 157 cues
- keyframes
- 17
- kept of 42 captured
- frames with text
- 17
- 291 lines read
- chapters
- 10
- from the source metadata
- keyframe bytes
- 4.4 MB
- word timings on 157 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-11 03:17 | 1m 07s |
stt |
done | — | 2026-08-11 03:18 | 24s |
chunk |
done | — | 2026-08-11 03:19 | 0s |
text_embed |
done | — | 2026-08-11 03:19 | 1s |
keyframe |
done | — | 2026-08-11 03:19 | 34s |
ocr |
done | — | 2026-08-11 03:19 | 6s |
frame_embed |
done | — | 2026-08-11 03:19 | 3s |
Frames, and what the machine read
-
- The Al bugpocalypse is here. Now1.00
- what?1.00
- Jack Cable0.99
- Corridor1.00
-
- whoami1.00
- Corridor1.00
- Now: Founder & CEO at Corridor0.97
- Before: Senior Technical Advisor at CISA1.00
- Top 100 Bug Bounty Hunter0.97
- DESIGN1.00
- SECUREBY1.00
- CS @ Stanford, Vanta, TechCongress, Pentagon0.99
- 1Corridor0.97
-
- THE MARKET OPPORTUNITY0.99
- Al coding tools are scaling faster than any1.00
- software category in history.1.00
- CURSOR -ANNUALIZED REVENUE0.97
- CLAUDE CODE-ANNUALIZED RUN-RATE0.97
- $O → $2B ARR in 13 months0.96
- $0 → $2.5B ARR in 9 months0.96
- HCRUNCH, FORTUNE - REPORTED ARR0.98
- SOURCE: ANTHROPIC, CNBC - REPORTED RUN-RATE0.97
-
- Al coding is changing everything1.00
- 2025:1.00
- 84% of developers now use Al coding tools1.00
- 30-40% of companies encourage use of Al coding1.00
- assistants1.00
- 40.68
- 2026:1.00
- 99.99%of developers?0.99
- 99% of companies?1.00
- 1Corridor0.98
-
- Frontier models are increasingly powerful1.00
- Model exploit capability0.98
- ExploitBench: V8 bugs0.99
- Enunvi ove0.66
- 401.00
- MythosPreview1.00
- Opus 4.71.00
- Opus 4.61.00
- Sonnet 4.60.98
- 301.00
- Haiku 4.50.97
- GPT 5.50.94
- KimiK2.61.00
- MiniMaxM2.71.00
- 201.00
- 101.00
- 01.00
- idor1.00
- T51.00
- T41.00
- T31.00
- T21.00
- T11.00
- Capability tier threshold from coverage (T5) to full code execution (T1)0.98
- T1 = full control, hardest0.99
-
- How can we make sure frontier Al models doesn't0.99
- lead to exponentially more vulnerabilities?1.00
- Corridor1.00
-
- WHAT WE'RE SEEING0.98
- Al coding can address decades of software insecurity, but it1.00
- won't come by default.1.00
- The Risk: code volume0.99
- The opportunity: With1.00
- is exploding, and1.00
- the right help, Al can1.00
- security can't keep up.1.00
- write code that's more1.00
- secure by default.0.99
- Enterprises are shipping at1.00
- Coding agents ar1.00
- least 10x as much code as0.97
- following secure1.00
- least year, with the same0.98
- that are defined f1.00
- security processes.1.00
- but these are heavily1.00
- Security can't inhibit0.99
- contextual.1.00
- velocity.1.00
-
- DESIGN1.00
- SECURE BY1.00
- ASD1.00
- ACSCE0.97
- 1+10.73
- Security Establishment1.00
- Communications1.00
- des télécommunications0.98
- Centre de la sécurité1.00
- Canadian Centre0.99
- for Cyber Security0.98
- pour la cybersécurité0.95
- Centre canadien1.00
- National Cyber1.00
- Security Centre1.00
- Network1.00
- CSIRTAmericas1.00
- NISC0.99
- certnz1.00
- SHIFTING THE BALANCE OF1.00
- CYBERSECURITY RISK:0.99
- WEGTAN NATIONAL0.97
- National Cyber1.00
- PRINCIPLES AND APPROACHES FOR0.98
- CYBER SECURITY CENTRE0.99
- Security Agency1.00
- SECURE BY DESIGN SOFTWARE1.00
- KISASECURITY AGENCY0.99
- KOREAINTERNET &0.98
- JPCERTCC1.00
- Corridor1.00
-
- Most vulnerabilities aren't anything complicated1.00
- 11.00
- Use After Free0.98
- CWE-416 | Analysis score: 73.99 | # CVE Mappings in KEV: 44 | Avg. CVSS: 8.540.98
- 21.00
- Heap-based Buffer Overflow1.00
- CWE-122 | Analysis score: 56.56 | # CVE Mappings in KEV: 32 | Avg. CVSS: 8.790.98
- Out-of-bounds Write0.99
- CWE-78Z | Analysis score: 51.96 | # CVE Mappings in KEV: 34 | Avg. CVSS: 8.190.98
- Improper Input Validation1.00
- CWE-20 | Analysis score: 51.38 | # CVE Mappings in KEV: 33 | Avg. CVSS: 8.270.97
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')0.99
- CWE-78 | Analysis score: 49.44 | # CVE Mappings in KEV: 25 | Avg. CVSS: 9.360.97
- Deserialization of Untrusted Data0.97
- CWE-502 | Analysis score: 29.00 | # CVE Mappings in KEV: 16 | Avg. CVSS: 9.060.99
- Server-Side Request Forgery (SSRF)0.99
- CWE-918 | Analysis score: 27.33 | # CVE Mappings in KEV: 16 | Avg. CVSS: 8.720.99
- Access of Resource Using Incompatible Type ('Type Confusion')0.99
- 81.00
- CWE-843 | Analysis score: 26.24 | # CVE Mappings in KEV: 16 | Avg. CVSS: 8.610.99
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')0.99
- CWE-22 | Analysis score: 19.90 | # CVE Mappings in KEV: 14 | Avg. CVSS: 8.090.98
- Missing Authentication for Critical Function0.99
- Corridor1.00
- CWE-306 I Analysis score: 12.98 | # CVE Mappings in KEV: 8 | Avg. CVSS: 8.860.98
-
- Many common classes of vulnerabilities can be1.00
- eliminated1.00
- 60-70% of vulnerabilities in1.00
- Memory unsafe code and Memory safety vulnerabilities0.99
- New memory unsafe code1.00
- Memory safety vulns0.98
- products written in unsafe1.00
- 1001.00
- programming languages can be1.00
- eliminated by using a memory0.98
- 751.00
- safe language.1.00
- 501.00
- Companies like Google,1.00
- Microsoft, and Amazon have0.98
- 251.00
- documented successes in using0.99
- memory safe languages.0.99
- 2019 (10)0.97
- 2020 (11)0.99
- 2021 (12)0.98
- 20.0.98
- Year (Android release)1.00
- Corridor1.00
-
- Al can introduce bugs...0.99
- pashov1.00
- ∅ ..0.60
- @pashov1.00
- Claude Opus 4.6 wrote vulnerable code, leading to a smart contract0.99
- exploit with $1.78M loss1.00
- cbETH asset's price was set to $1.12 instead of ~$2,200. The PRs of the0.99
- project show commits were co-authored by Claude - Is this the first0.99
- hack of vibe-coded Solidity code?0.99
- Add MIP-X43: Activate OEV wrappers for all remaining market:1.00
- main rom nip-x43last wook0.85
- Checks 280.94
- Files changed0.95
- Q. Fiter fles.0.88
- Add MIP-X43: Activate OEV wrappers fror all remaining markets0.99
- proposals0.94
- Co-Authored-By: Claude Opus 4.6 «noreplyenthropic.com>0.94
- mips1.00
- < Prew Next >0.72
- mip-x430.96
- mip-x43.sol0.94
- anajuliabit and claude committed 2 weeks ago · × 17 /280.93
- ChainlinkOracleConfis.sol0.94
- mips json0.87
- ☑ x43.md0.87
- proposals/eips/nip-s43/nip-s43.sol0.89
- + // SPOX-Licemse-Sdentifier:0.87
- 00-0,0+1,621000.90
- + pragna soladity 8.8.29;0.87
- 1:29 PM - Feb 17, 2026 - 1.4M Views0.94
- Corridor1.00
- Q2950.95
- t 8410.90
- 4.1K1.00
- 1.3K0.92
- ↑0.60
- Corridor1.00
-
- BaxBench: Can LLMs Generate Secure and1.00
- Correct Backends?0.99
- Mark Vero1, Niels Mūndler1, Victor Chibotaru². Veselin Raychev², Maximilian Baader1, Nikola Jovanović0.97
- Jingxuan He³, Martin Vechev1.40.94
- SRI Lab@ETH Zurich, ²LogicStar.ai, UC Berkeley, 4INSAIT0.98
- Rank1.00
- Model1.00
- Correct &1.00
- Secure ↓0.98
- Correct1.00
- % Insecure0.95
- of Correct1.00
- 11.00
- Claude Opus 4.5 Thinking1.00
- 56.1%1.00
- 86.2%1.00
- 34.9%1.00
- 21.00
- GPT-51.00
- 54.3%1.00
- 70.7%1.00
- 23.1%1.00
- 31.00
- OpenAI 030.93
- 46.4%1.00
- 67.6%1.00
- 31.3%1.00
- 41.00
- Claude 4 Sonnet Thinking1.00
- 45.7%1.00
- 75.0%1.00
- 39.1%1.00
- 51.00
- GPT-4.10.99
- 40.8%1.00
- 56.4%1.00
- 27.7%1.00
- 61.00
- Claude 3.7 Sonnet Thinking0.99
- 37.0%1.00
- 63.3%1.00
- 41.5%1.00
- 71.00
- DeepSeek R10.96
- 34.4%1.00
- 58.4%1.00
- 41.0%1.00
- 81.00
- OpenA o3-mini0.95
- 34.4%1.00
- 63.0%1.00
- 45.3%1.00
- 91.00
- Grok 41.00
- 33.4%1.00
- 57.7%1.00
- 42.0%1.00
- Corridor1.00
- 101.00
- Gemini 2.5 Pro0.99
- 32.0%1.00
- 49.8%1.00
- 35.8%1.00
Transcript
157 cues· 3,004 words· 17,284 chars
- 0:01 Hey there, I'm Jack Cable, and today I'm going to be talking about the effects of the AI bugpocalypse.
- 0:06 As you may have seen, frontier models are getting better than ever before at discovering and exploiting vulnerabilities in our software.
- 0:14 This is leading to what many are calling a bugpocalypse,
- 0:18 where we're finding more and more vulnerabilities, particularly in the open source libraries that power all of the software we rely upon, right?
- 0:27 So today I want to break down what exactly is happening and how defenders can get ahead of the exploitation that is occurring.
- 0:35 as far as my background right now i'm the co-founder and ceo at corridor a company i started about 18 months ago focused on securing ai coding before this i served as a senior technical advisor in government at cisa the cyber security and infrastructure security agency where i worked with top software companies to help them
- 0:56 build their products to be more secure by design.
- 0:59 I'm also an ethical hacker.
- 1:00 I got into the top 100 rank of hackers on HackerOne when I was in high school and studied computer science at Stanford.
- 1:07 So I've seen firsthand how these simple repeat classes of vulnerabilities can be introduced and exploited and have been a close participant in many of the most recent advancements and seeing just what this means for both
- 1:25 our adversaries as well as defenders.
- 1:28 Just to set the stage, right, as everyone here knows, I imagine AI coding tools are scaling faster than any software category in history.
- 1:36 We've seen Cursor, Cloud Code grow exponentially.
- 1:41 And with that, right, also comes these improvements in how frontier models can find and exploit vulnerabilities.
- 1:48 So we're seeing, right, both ends of the equation shifting.
- 1:51 On one hand,
- 1:53 Models can do a better job finding vulnerabilities.
- 1:55 On the other hand, our attack surfaces are growing immensely as AI becomes the default code writer.
- 2:03 What I want to explore in this talk is how do we balance that?
- 2:06 How do we make sure that we're not going to have immensely more vulnerabilities
- 2:10 than we've ever had before, right?
- 2:12 And just to give some sense, I'll move myself here of some of the statistics, right?
- 2:19 Pulled some from last year where about 84% of developers were using AI coding tools, 30 to 40% of companies encouraging use of AI coding assistance.
- 2:28 That was from Stack Overflow, right?
- 2:30 I haven't seen the latest numbers this year, but what I would expect once those come out, right, is that is the vast, vast majority of developers and companies
- 2:39 We're using coding agents, right?
- 2:42 And part of this is the increasing level of autonomy by which these coding agents are being used.
- 2:48 It's no longer, you know, auto complete often.
- 2:50 It's not even a developer synchronously within cursor.
- 2:54 Um, right when we do our own development right now, it's, um, spinning up agents from within slack or wherever folks are working.
- 3:02 and having many agents run at once in the background.
- 3:06 This is a tremendous shift in how software is being built.
- 3:10 And at the same time, like I mentioned, the frontier models are getting significantly better.
- 3:16 And you can look at it from pretty much any part of the cyber attack chain, ranging from finding vulnerabilities where models can now do significantly better than even I could.
- 3:28 And I've reported hundreds of vulnerabilities to various companies.
- 3:32 So everything from finding vulnerabilities to exploiting them.
- 3:35 This is a chart here that comes from Anthropic, showing mythos compared to a number of other models that they and others have put out.
- 3:46 And we can see that we're seeing quite rapid advancements in models capabilities, and particularly to execute more kind of autonomous attack chains.
- 3:58 As we think about adversaries who are using these models, they're not just going to be discovering vulnerabilities, but they're going to be automating every part of the attack process.
- 4:09 It's our job as defenders to understand, what are the points where we can make software systems more resilient to all of these attacks?
- 4:19 To me, this brings back a lot of the work that I was doing in government around the Secure by Design initiative.
- 4:26 And so the overall question that I'm worried about is, how can we make sure that frontier AI models aren't introducing exponentially more vulnerabilities over time?
- 4:37 Even pre-AI, we've had this
- 4:40 you know, a heavy increase in common, relatively simple classes of vulnerabilities that are being exploited by adversaries.
- 4:49 AI is making this significantly easier, right?
- 4:52 So I think the only way that we're going to win as defenders is if we use the same techniques, right, to harden our systems.
- 5:00 And I would say that there is good news here, right?
- 5:02 That a lot of the
- 5:04 vulnerabilities, pretty much all of the vulnerabilities that even frontier AI models are finding aren't anything new.
- 5:10 Yes, it's new that a given vulnerability was found in a specific file within a piece of software, but that vulnerability class isn't necessarily novel.
loading
Chapters
- 0:00 Introduction to AI risks
- 1:27 AI coding tool growth
- 2:11 Cyber attack chain evolution
- 5:24 Secure by design principles
- 5:46 Mitigating common bugs
- 6:39 AI vulnerability benchmarks
- 11:20 Autonomous agent security
- 12:36 Corridor security solutions
- 13:43 Policy and export controls
- 14:51 Recommendations for Congress