read-only demo

Videos 7JgIS42mz7U

The AI bugpocalypse is here. Now what? - Jack Cable, Corridor

index_state ready data_status ok

AI Engineer· published 2026-07-12· 0:19:43· en-US· indexed 2026-08-11 03:19

Open on YouTube

Scene timeline

  1. Shot 0, 0:00 to 0:36, 1 of 1 keyframes kept
  2. Shot 1, 0:36 to 1:01, 1 of 1 keyframes kept
  3. Shot 2, 1:01 to 1:27, 0 of 1 keyframes kept
  4. Shot 3, 1:27 to 2:11, 1 of 1 keyframes kept
  5. Shot 4, 2:11 to 2:41, 1 of 1 keyframes kept
  6. Shot 5, 2:41 to 3:11, 0 of 1 keyframes kept
  7. Shot 6, 3:11 to 3:48, 1 of 1 keyframes kept
  8. Shot 7, 3:48 to 4:25, 0 of 1 keyframes kept
  9. Shot 8, 4:25 to 4:54, 1 of 1 keyframes kept
  10. Shot 9, 4:54 to 5:24, 0 of 1 keyframes kept
  11. Shot 10, 5:24 to 5:46, 1 of 1 keyframes kept
  12. Shot 11, 5:46 to 6:13, 1 of 1 keyframes kept
  13. Shot 12, 6:13 to 6:39, 0 of 1 keyframes kept
  14. Shot 13, 6:39 to 7:06, 1 of 1 keyframes kept
  15. Shot 14, 7:06 to 7:33, 0 of 1 keyframes kept
  16. Shot 15, 7:33 to 8:01, 0 of 1 keyframes kept
  17. Shot 16, 8:01 to 8:28, 1 of 1 keyframes kept
  18. Shot 17, 8:28 to 8:54, 0 of 1 keyframes kept
  19. Shot 18, 8:54 to 9:21, 0 of 1 keyframes kept
  20. Shot 19, 9:21 to 9:48, 0 of 1 keyframes kept
  21. Shot 20, 9:48 to 10:15, 0 of 1 keyframes kept
  22. Shot 21, 10:15 to 10:42, 0 of 1 keyframes kept
  23. Shot 22, 10:42 to 11:20, 1 of 1 keyframes kept
  24. Shot 23, 11:20 to 11:45, 1 of 1 keyframes kept
  25. Shot 24, 11:45 to 12:10, 0 of 1 keyframes kept
  26. Shot 25, 12:10 to 12:36, 0 of 1 keyframes kept
  27. Shot 26, 12:36 to 13:09, 1 of 1 keyframes kept
  28. Shot 27, 13:09 to 13:43, 0 of 1 keyframes kept
  29. Shot 28, 13:43 to 14:17, 1 of 1 keyframes kept
  30. Shot 29, 14:17 to 14:51, 0 of 1 keyframes kept
  31. Shot 30, 14:51 to 15:18, 1 of 1 keyframes kept
  32. Shot 31, 15:18 to 15:45, 0 of 1 keyframes kept
  33. Shot 32, 15:45 to 16:12, 0 of 1 keyframes kept
  34. Shot 33, 16:12 to 16:40, 0 of 1 keyframes kept
  35. Shot 34, 16:40 to 17:05, 1 of 1 keyframes kept
  36. Shot 35, 17:05 to 17:30, 0 of 1 keyframes kept
  37. Shot 36, 17:30 to 17:55, 0 of 1 keyframes kept
  38. Shot 37, 17:55 to 18:20, 0 of 1 keyframes kept
  39. Shot 38, 18:20 to 18:45, 0 of 1 keyframes kept
  40. Shot 39, 18:45 to 19:11, 0 of 1 keyframes kept
  41. Shot 40, 19:11 to 19:36, 0 of 1 keyframes kept
  42. Shot 41, 19:36 to 19:43, 1 of 1 keyframes kept

42 shot(s).

keyframes kept every frame deduplicated

What was stored

cues
157
whisperx 157
chunks
34
from 157 cues
keyframes
17
kept of 42 captured
frames with text
17
291 lines read
chapters
10
from the source metadata
keyframe bytes
4.4 MB
word timings on 157 cues

Provenance

Each pipeline stage, its state and the model that produced it
stage state model started took
fetch done 2026-08-11 03:17 1m 07s
stt done 2026-08-11 03:18 24s
chunk done 2026-08-11 03:19 0s
text_embed done 2026-08-11 03:19 1s
keyframe done 2026-08-11 03:19 34s
ocr done 2026-08-11 03:19 6s
frame_embed done 2026-08-11 03:19 3s

Frames, and what the machine read

  • 0:31 #0 done4 line(s)

    shot 0·sharpness 700.4

    1. The Al bugpocalypse is here. Now1.00
    2. what?1.00
    3. Jack Cable0.99
    4. Corridor1.00
  • 0:58 #1 done9 line(s)

    shot 1·sharpness 1353.9

    1. whoami1.00
    2. Corridor1.00
    3. Now: Founder & CEO at Corridor0.97
    4. Before: Senior Technical Advisor at CISA1.00
    5. Top 100 Bug Bounty Hunter0.97
    6. DESIGN1.00
    7. SECUREBY1.00
    8. CS @ Stanford, Vanta, TechCongress, Pentagon0.99
    9. 1Corridor0.97
  • 1:04 #2 skipped

    shot 2·duplicate of #1

  • 2:01 #3 done9 line(s)

    shot 3·sharpness 1247.6

    1. THE MARKET OPPORTUNITY0.99
    2. Al coding tools are scaling faster than any1.00
    3. software category in history.1.00
    4. CURSOR -ANNUALIZED REVENUE0.97
    5. CLAUDE CODE-ANNUALIZED RUN-RATE0.97
    6. $O → $2B ARR in 13 months0.96
    7. $0 → $2.5B ARR in 9 months0.96
    8. HCRUNCH, FORTUNE - REPORTED ARR0.98
    9. SOURCE: ANTHROPIC, CNBC - REPORTED RUN-RATE0.97
  • 2:34 #4 done10 line(s)

    shot 4·sharpness 1384.9

    1. Al coding is changing everything1.00
    2. 2025:1.00
    3. 84% of developers now use Al coding tools1.00
    4. 30-40% of companies encourage use of Al coding1.00
    5. assistants1.00
    6. 40.68
    7. 2026:1.00
    8. 99.99%of developers?0.99
    9. 99% of companies?1.00
    10. 1Corridor0.98
  • 3:02 #5 skipped

    shot 5·duplicate of #4

  • 3:30 #6 done25 line(s)

    shot 6·sharpness 1675.4

    1. Frontier models are increasingly powerful1.00
    2. Model exploit capability0.98
    3. ExploitBench: V8 bugs0.99
    4. Enunvi ove0.66
    5. 401.00
    6. MythosPreview1.00
    7. Opus 4.71.00
    8. Opus 4.61.00
    9. Sonnet 4.60.98
    10. 301.00
    11. Haiku 4.50.97
    12. GPT 5.50.94
    13. KimiK2.61.00
    14. MiniMaxM2.71.00
    15. 201.00
    16. 101.00
    17. 01.00
    18. idor1.00
    19. T51.00
    20. T41.00
    21. T31.00
    22. T21.00
    23. T11.00
    24. Capability tier threshold from coverage (T5) to full code execution (T1)0.98
    25. T1 = full control, hardest0.99
  • 4:03 #7 skipped

    shot 7·duplicate of #6

  • 4:31 #8 done3 line(s)

    shot 8·sharpness 1058.2

    1. How can we make sure frontier Al models doesn't0.99
    2. lead to exponentially more vulnerabilities?1.00
    3. Corridor1.00
  • 5:01 #9 skipped

    shot 9·duplicate of #8

  • 5:33 #10 done21 line(s)

    shot 10·sharpness 2056.8

    1. WHAT WE'RE SEEING0.98
    2. Al coding can address decades of software insecurity, but it1.00
    3. won't come by default.1.00
    4. The Risk: code volume0.99
    5. The opportunity: With1.00
    6. is exploding, and1.00
    7. the right help, Al can1.00
    8. security can't keep up.1.00
    9. write code that's more1.00
    10. secure by default.0.99
    11. Enterprises are shipping at1.00
    12. Coding agents ar1.00
    13. least 10x as much code as0.97
    14. following secure1.00
    15. least year, with the same0.98
    16. that are defined f1.00
    17. security processes.1.00
    18. but these are heavily1.00
    19. Security can't inhibit0.99
    20. contextual.1.00
    21. velocity.1.00
  • 6:05 #11 done31 line(s)

    shot 11·sharpness 939.3

    1. DESIGN1.00
    2. SECURE BY1.00
    3. ASD1.00
    4. ACSCE0.97
    5. 1+10.73
    6. Security Establishment1.00
    7. Communications1.00
    8. des télécommunications0.98
    9. Centre de la sécurité1.00
    10. Canadian Centre0.99
    11. for Cyber Security0.98
    12. pour la cybersécurité0.95
    13. Centre canadien1.00
    14. National Cyber1.00
    15. Security Centre1.00
    16. Network1.00
    17. CSIRTAmericas1.00
    18. NISC0.99
    19. certnz1.00
    20. SHIFTING THE BALANCE OF1.00
    21. CYBERSECURITY RISK:0.99
    22. WEGTAN NATIONAL0.97
    23. National Cyber1.00
    24. PRINCIPLES AND APPROACHES FOR0.98
    25. CYBER SECURITY CENTRE0.99
    26. Security Agency1.00
    27. SECURE BY DESIGN SOFTWARE1.00
    28. KISASECURITY AGENCY0.99
    29. KOREAINTERNET &0.98
    30. JPCERTCC1.00
    31. Corridor1.00
  • 6:31 #12 skipped

    shot 12·duplicate of #11

  • 7:00 #13 done25 line(s)

    shot 13·sharpness 2083.3

    1. Most vulnerabilities aren't anything complicated1.00
    2. 11.00
    3. Use After Free0.98
    4. CWE-416 | Analysis score: 73.99 | # CVE Mappings in KEV: 44 | Avg. CVSS: 8.540.98
    5. 21.00
    6. Heap-based Buffer Overflow1.00
    7. CWE-122 | Analysis score: 56.56 | # CVE Mappings in KEV: 32 | Avg. CVSS: 8.790.98
    8. Out-of-bounds Write0.99
    9. CWE-78Z | Analysis score: 51.96 | # CVE Mappings in KEV: 34 | Avg. CVSS: 8.190.98
    10. Improper Input Validation1.00
    11. CWE-20 | Analysis score: 51.38 | # CVE Mappings in KEV: 33 | Avg. CVSS: 8.270.97
    12. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')0.99
    13. CWE-78 | Analysis score: 49.44 | # CVE Mappings in KEV: 25 | Avg. CVSS: 9.360.97
    14. Deserialization of Untrusted Data0.97
    15. CWE-502 | Analysis score: 29.00 | # CVE Mappings in KEV: 16 | Avg. CVSS: 9.060.99
    16. Server-Side Request Forgery (SSRF)0.99
    17. CWE-918 | Analysis score: 27.33 | # CVE Mappings in KEV: 16 | Avg. CVSS: 8.720.99
    18. Access of Resource Using Incompatible Type ('Type Confusion')0.99
    19. 81.00
    20. CWE-843 | Analysis score: 26.24 | # CVE Mappings in KEV: 16 | Avg. CVSS: 8.610.99
    21. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')0.99
    22. CWE-22 | Analysis score: 19.90 | # CVE Mappings in KEV: 14 | Avg. CVSS: 8.090.98
    23. Missing Authentication for Critical Function0.99
    24. Corridor1.00
    25. CWE-306 I Analysis score: 12.98 | # CVE Mappings in KEV: 8 | Avg. CVSS: 8.860.98
  • 7:30 #14 skipped

    shot 14·duplicate of #13

  • 7:39 #15 skipped

    shot 15·duplicate of #13

  • 8:24 #16 done24 line(s)

    shot 16·sharpness 2913.1

    1. Many common classes of vulnerabilities can be1.00
    2. eliminated1.00
    3. 60-70% of vulnerabilities in1.00
    4. Memory unsafe code and Memory safety vulnerabilities0.99
    5. New memory unsafe code1.00
    6. Memory safety vulns0.98
    7. products written in unsafe1.00
    8. 1001.00
    9. programming languages can be1.00
    10. eliminated by using a memory0.98
    11. 751.00
    12. safe language.1.00
    13. 501.00
    14. Companies like Google,1.00
    15. Microsoft, and Amazon have0.98
    16. 251.00
    17. documented successes in using0.99
    18. memory safe languages.0.99
    19. 2019 (10)0.97
    20. 2020 (11)0.99
    21. 2021 (12)0.98
    22. 20.0.98
    23. Year (Android release)1.00
    24. Corridor1.00
  • 8:31 #17 skipped

    shot 17·duplicate of #16

  • 9:00 #18 skipped

    shot 18·duplicate of #16

  • 9:30 #19 skipped

    shot 19·duplicate of #16

  • 10:02 #20 skipped

    shot 20·duplicate of #16

  • 10:33 #21 skipped

    shot 21·duplicate of #16

  • 11:01 #22 done37 line(s)

    shot 22·sharpness 1083.7

    1. Al can introduce bugs...0.99
    2. pashov1.00
    3. ∅ ..0.60
    4. @pashov1.00
    5. Claude Opus 4.6 wrote vulnerable code, leading to a smart contract0.99
    6. exploit with $1.78M loss1.00
    7. cbETH asset's price was set to $1.12 instead of ~$2,200. The PRs of the0.99
    8. project show commits were co-authored by Claude - Is this the first0.99
    9. hack of vibe-coded Solidity code?0.99
    10. Add MIP-X43: Activate OEV wrappers for all remaining market:1.00
    11. main rom nip-x43last wook0.85
    12. Checks 280.94
    13. Files changed0.95
    14. Q. Fiter fles.0.88
    15. Add MIP-X43: Activate OEV wrappers fror all remaining markets0.99
    16. proposals0.94
    17. Co-Authored-By: Claude Opus 4.6 «noreplyenthropic.com>0.94
    18. mips1.00
    19. < Prew Next >0.72
    20. mip-x430.96
    21. mip-x43.sol0.94
    22. anajuliabit and claude committed 2 weeks ago · × 17 /280.93
    23. ChainlinkOracleConfis.sol0.94
    24. mips json0.87
    25. ☑ x43.md0.87
    26. proposals/eips/nip-s43/nip-s43.sol0.89
    27. + // SPOX-Licemse-Sdentifier:0.87
    28. 00-0,0+1,621000.90
    29. + pragna soladity 8.8.29;0.87
    30. 1:29 PM - Feb 17, 2026 - 1.4M Views0.94
    31. Corridor1.00
    32. Q2950.95
    33. t 8410.90
    34. 4.1K1.00
    35. 1.3K0.92
    36. 0.60
    37. Corridor1.00
  • 11:30 #23 done63 line(s)

    shot 23·sharpness 845.0

    1. BaxBench: Can LLMs Generate Secure and1.00
    2. Correct Backends?0.99
    3. Mark Vero1, Niels Mūndler1, Victor Chibotaru². Veselin Raychev², Maximilian Baader1, Nikola Jovanović0.97
    4. Jingxuan He³, Martin Vechev1.40.94
    5. SRI Lab@ETH Zurich, ²LogicStar.ai, UC Berkeley, 4INSAIT0.98
    6. Rank1.00
    7. Model1.00
    8. Correct &1.00
    9. Secure ↓0.98
    10. Correct1.00
    11. % Insecure0.95
    12. of Correct1.00
    13. 11.00
    14. Claude Opus 4.5 Thinking1.00
    15. 56.1%1.00
    16. 86.2%1.00
    17. 34.9%1.00
    18. 21.00
    19. GPT-51.00
    20. 54.3%1.00
    21. 70.7%1.00
    22. 23.1%1.00
    23. 31.00
    24. OpenAI 030.93
    25. 46.4%1.00
    26. 67.6%1.00
    27. 31.3%1.00
    28. 41.00
    29. Claude 4 Sonnet Thinking1.00
    30. 45.7%1.00
    31. 75.0%1.00
    32. 39.1%1.00
    33. 51.00
    34. GPT-4.10.99
    35. 40.8%1.00
    36. 56.4%1.00
    37. 27.7%1.00
    38. 61.00
    39. Claude 3.7 Sonnet Thinking0.99
    40. 37.0%1.00
    41. 63.3%1.00
    42. 41.5%1.00
    43. 71.00
    44. DeepSeek R10.96
    45. 34.4%1.00
    46. 58.4%1.00
    47. 41.0%1.00
    48. 81.00
    49. OpenA o3-mini0.95
    50. 34.4%1.00
    51. 63.0%1.00
    52. 45.3%1.00
    53. 91.00
    54. Grok 41.00
    55. 33.4%1.00
    56. 57.7%1.00
    57. 42.0%1.00
    58. Corridor1.00
    59. 101.00
    60. Gemini 2.5 Pro0.99
    61. 32.0%1.00
    62. 49.8%1.00
    63. 35.8%1.00

Transcript

157 cues· 3,004 words· 17,284 chars

  1. 0:01 Hey there, I'm Jack Cable, and today I'm going to be talking about the effects of the AI bugpocalypse.
  2. 0:06 As you may have seen, frontier models are getting better than ever before at discovering and exploiting vulnerabilities in our software.
  3. 0:14 This is leading to what many are calling a bugpocalypse,
  4. 0:18 where we're finding more and more vulnerabilities, particularly in the open source libraries that power all of the software we rely upon, right?
  5. 0:27 So today I want to break down what exactly is happening and how defenders can get ahead of the exploitation that is occurring.
  6. 0:35 as far as my background right now i'm the co-founder and ceo at corridor a company i started about 18 months ago focused on securing ai coding before this i served as a senior technical advisor in government at cisa the cyber security and infrastructure security agency where i worked with top software companies to help them
  7. 0:56 build their products to be more secure by design.
  8. 0:59 I'm also an ethical hacker.
  9. 1:00 I got into the top 100 rank of hackers on HackerOne when I was in high school and studied computer science at Stanford.
  10. 1:07 So I've seen firsthand how these simple repeat classes of vulnerabilities can be introduced and exploited and have been a close participant in many of the most recent advancements and seeing just what this means for both
  11. 1:25 our adversaries as well as defenders.
  12. 1:28 Just to set the stage, right, as everyone here knows, I imagine AI coding tools are scaling faster than any software category in history.
  13. 1:36 We've seen Cursor, Cloud Code grow exponentially.
  14. 1:41 And with that, right, also comes these improvements in how frontier models can find and exploit vulnerabilities.
  15. 1:48 So we're seeing, right, both ends of the equation shifting.
  16. 1:51 On one hand,
  17. 1:53 Models can do a better job finding vulnerabilities.
  18. 1:55 On the other hand, our attack surfaces are growing immensely as AI becomes the default code writer.
  19. 2:03 What I want to explore in this talk is how do we balance that?
  20. 2:06 How do we make sure that we're not going to have immensely more vulnerabilities
  21. 2:10 than we've ever had before, right?
  22. 2:12 And just to give some sense, I'll move myself here of some of the statistics, right?
  23. 2:19 Pulled some from last year where about 84% of developers were using AI coding tools, 30 to 40% of companies encouraging use of AI coding assistance.
  24. 2:28 That was from Stack Overflow, right?
  25. 2:30 I haven't seen the latest numbers this year, but what I would expect once those come out, right, is that is the vast, vast majority of developers and companies
  26. 2:39 We're using coding agents, right?
  27. 2:42 And part of this is the increasing level of autonomy by which these coding agents are being used.
  28. 2:48 It's no longer, you know, auto complete often.
  29. 2:50 It's not even a developer synchronously within cursor.
  30. 2:54 Um, right when we do our own development right now, it's, um, spinning up agents from within slack or wherever folks are working.
  31. 3:02 and having many agents run at once in the background.
  32. 3:06 This is a tremendous shift in how software is being built.
  33. 3:10 And at the same time, like I mentioned, the frontier models are getting significantly better.
  34. 3:16 And you can look at it from pretty much any part of the cyber attack chain, ranging from finding vulnerabilities where models can now do significantly better than even I could.
  35. 3:28 And I've reported hundreds of vulnerabilities to various companies.
  36. 3:32 So everything from finding vulnerabilities to exploiting them.
  37. 3:35 This is a chart here that comes from Anthropic, showing mythos compared to a number of other models that they and others have put out.
  38. 3:46 And we can see that we're seeing quite rapid advancements in models capabilities, and particularly to execute more kind of autonomous attack chains.
  39. 3:58 As we think about adversaries who are using these models, they're not just going to be discovering vulnerabilities, but they're going to be automating every part of the attack process.
  40. 4:09 It's our job as defenders to understand, what are the points where we can make software systems more resilient to all of these attacks?
  41. 4:19 To me, this brings back a lot of the work that I was doing in government around the Secure by Design initiative.
  42. 4:26 And so the overall question that I'm worried about is, how can we make sure that frontier AI models aren't introducing exponentially more vulnerabilities over time?
  43. 4:37 Even pre-AI, we've had this
  44. 4:40 you know, a heavy increase in common, relatively simple classes of vulnerabilities that are being exploited by adversaries.
  45. 4:49 AI is making this significantly easier, right?
  46. 4:52 So I think the only way that we're going to win as defenders is if we use the same techniques, right, to harden our systems.
  47. 5:00 And I would say that there is good news here, right?
  48. 5:02 That a lot of the
  49. 5:04 vulnerabilities, pretty much all of the vulnerabilities that even frontier AI models are finding aren't anything new.
  50. 5:10 Yes, it's new that a given vulnerability was found in a specific file within a piece of software, but that vulnerability class isn't necessarily novel.

Chapters

  1. 0:00 Introduction to AI risks
  2. 1:27 AI coding tool growth
  3. 2:11 Cyber attack chain evolution
  4. 5:24 Secure by design principles
  5. 5:46 Mitigating common bugs
  6. 6:39 AI vulnerability benchmarks
  7. 11:20 Autonomous agent security
  8. 12:36 Corridor security solutions
  9. 13:43 Policy and export controls
  10. 14:51 Recommendations for Congress

Open at this second