
Hosted by Kyle McNulty
Kyle McNulty interviews cutting-edge founders in the cyber security space to understand their plights, glories, and revolutionary products. New episodes are published every other Tuesday. If you are interested in sharing your story, please contact me at kyle@secureventures.io Following the podcast really helps!
139 episodes · publishes fortnightly · latest 2026-06-02 · ~43 min/episode
Rank
#657
Substance
75.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#657 of 6183
Substance
Top 11%
outscores 89% of the index
Secure Ventures with Kyle McNulty ranks #657 on The B2B Podcast Index with a substance score of 75.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and specificity & evidence. Rishi is a genuine practitioner: started bug bounties at 15, built Nuclei into a major open-source security standard used across the industry, and co-founded a real product company with VC backing. He speaks from firsthand operational experience rather than abstraction, which gives his claims credibility even when the delivery is unpolished.
Averaged across 1 recently scored episode, with cited evidence.
The episode contains genuine practitioner insights buried in significant verbal filler and repetitive phrasing - the points on CVE exploitation going 'negative' (pre-announcement exploitation), LLMs being structurally poor at business logic vulnerabilities, and AI auto-remediation potentially breaking features are substantive. However, a significant portion of the runtime is autobiography and vague macro statements about the industry.
“attackers are even reverse engineering all the releases of popular repositories to figure out whether they are about to uh, talk about a CVE or advisory of CVE in a week or two. And they are in, I would say in the negative, not even in the, in the hours or days period.”
“LLMs are very good at findings that are non business logic ones...But the moment you take uh account into authorization privilege escalations or like business logical ones, uh they still do a very poor job.”
A few genuinely counterintuitive angles emerge - particularly the pre-announcement CVE exploitation thesis and the AI auto-remediation feature-breaking problem - but the macro framing around expanding attack surfaces, AI noise in bug bounties, and the harness-vs-model debate are well-circulated takes in security circles.
“attackers are even reverse engineering all the releases of popular repositories to figure out whether they are about to uh, talk about a CVE or advisory of CVE in a week or two”
“I don't think I am not saying that teams have figured out how to act on the remediation cycles and like shorten that out. And that's my hope that we uh, like from cybersecurity we all figure that out in the next six to eight months. If you don't then it is going to be a bit wild”
Rishi is a genuine practitioner: started bug bounties at 15, built Nuclei into a major open-source security standard used across the industry, and co-founded a real product company with VC backing. He speaks from firsthand operational experience rather than abstraction, which gives his claims credibility even when the delivery is unpolished.
“when we started in 2021 with nuclear and other projects, we were seeing weeks to months uh, from a given CVE to exploitation period. Now in some cases attackers are even reverse engineering all the releases”
“we have around more than 10,000 detection templates but 80% of them are written by community”
The episode has a useful mix of concrete data points - bounty dollar figures, GitHub star counts, template percentages, token context windows, per-report instance discovery rates - but slides frequently into generality ('a bit of a bottleneck,' 'much more complicated') and several key claims lack supporting evidence or named references.
“we have around more than 10,000 detection templates but 80% of them are written by community”
“for each report they used to find eight or ten net new instances vulnerable from the same vulnerability”
The host occasionally reframes or sharpens the guest's point (e.g., clarifying 'all time high' as 'all time low in time-to-exploit') and asks a few structurally sound follow-ups about bottlenecks and model vs. harness tradeoffs, but never meaningfully challenges a claim, lets vague macro assertions pass unchallenged, and spends notable time on tangential biography.
“when you say all time highs, just to be clear, right, you're talking about record speed. So in some ways it's actually kind of like an all time low in terms of the amount of time to develop uh, some of these exploits”
“What do you think the bottleneck is for doing remediation with these models? Right. Because if I think about the different types of vulnerabilities that need to be um, actually remediated.”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/secure-ventures-with-kyle-mcnulty" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/secure-ventures-with-kyle-mcnulty/badge.svg" alt="Ranked #102 on The B2B Podcast Index" width="360" height="136" />
</a>Track Secure Ventures with Kyle McNulty's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.