The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Resilient Cyber
Resilient Cyber artwork

You Don't Need A Frontier Model to Find Zero Days

Resilient Cyber · 2026-06-18 · 41 min

0:00--:--

Episode notes

Niels Provos on why you don't need a frontier model to find zero days, why the Vulnpocalypse is overstated, and how security invariants change the game. Description Niels Provos has spent twenty-five years in security, from writing bcrypt to running security at Google and Stripe, and he came on to push back on the panic around AI and vulnerabilities. He explains why finding zero days is an orchestration problem rather than a frontier-model problem, using his Iron Curtain runtime and an open-weight model to surface net-new bugs for the cost of a cheap scan. We get into security invariants and egress control, why remediation is the real bottleneck, why AI coding tools ignore the security abstractions you build, and why someone this technical keeps coming back to incentives over technology. Key takeaways You don't need a frontier model to find zero days. Niels used his Iron Curtain runtime and an open-weight model to surface net-new vulnerabilities, which is why he calls this an orchestration problem rather than a frontier-model problem. The Vulnpocalypse framing is overstated.

More from Resilient Cyber

All episodes →
  • Rain Versus Flood, Making Sense of the 2026 CVE Surge76 / 100
  • AI Industrialized the Vuln Lifecycle and Broke the System of Record
  • AI Is Winning the Cyber Arms Race
  • Securing the Agentic SDLC
  • The Agentic GRC Revolution
Explore the best B2B AI & Data podcasts →
All Resilient Cyber episodes →