meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, January 23rd, 2026: Scanning AI Code; FortiGate Update; ISC BIND DoS; Trivial SmaterMail Vulnerability

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 23 January 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Friday, January 23rd, 2026: Scanning AI Code; FortiGate Update; ISC BIND DoS; Trivial SmaterMail Vulnerability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, January 23rd, 2006 edition of the Sands Internet Storm Centers.

0:12.0

Stormcast, my name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:17.9

And this episode is brought you by the sands.edu created certificate program in

0:22.4

industrial control system security. And I mentioned it yesterday, but we are currently looking

0:28.0

for people to fill in our SOC survey. So if you haven't gotten around to it yet, a link to it can

0:34.5

be found on the Internet Storm Center's homepage.

0:44.4

Well, Xavier today looked at a new tool. Bandit. Bandit is a tool that allows you to a static code analysis of Python scripts. Xavier writes a lot of Python and lately also a lot of Python with

0:52.3

AI. And there's, of course, a lot of issues that people run into

0:57.5

when they are using AI for coding. And this particular case, it's a script that Xavi wrote. It's

1:04.1

about a thousand or so lines long. So a pretty good size for a Python script. And he looked at Bandit to give an idea whether or not

1:14.4

the script is reasonably secure. Well, it turned out it was actually reasonably secure. I had some

1:22.0

minor issues, but then of course all depends, as Xavier points out, how the particular script is used, whether or not these issues matter.

1:30.5

A lot of the static code analysis is sometimes a little bit mechanical in that sense.

1:37.0

It comes to using AI tools, like to wipe coding, as it's often referred to.

1:43.5

One of the important things, first of all, is that you design your prompt correctly.

1:48.7

And Xavier gives you some hints there in how to do that and what to look for here.

1:55.0

And in my personal experience, it also helps a lot if you actually know how to code

1:59.7

and use AI sort of more as an assistant

2:02.9

versus having it code all of the code by itself.

2:08.4

That way, sort of do a little bit of review anyway as you're checking what the AI tool

2:14.4

created for you.

2:15.3

And that also usually helps with a lot of logic flow issues and such,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.