
← Cloud Security Podcast4 aug · 47 min
How Adobe Uses AI Agents for building a WAF Pipeline?
<p>When vulnerability disclosures shrink the wild exploit window down to less than 24 hours (or even minutes), traditional manual patching and WAF rule creation simply cannot keep up.</p><p>In this episode, Ashish sits down with <a href="https://www.linkedin.com/in/ammar-alim-6630a977/" target="_blank" rel="noopener noreferer">Ammar Alim</a> (Product Security Engineering Lead at <a href="https://www.adobe.com/" target="_blank" rel="noopener noreferer">Adobe</a>) to break down how to build an automated, agentic WAF pipeline. Ammar shares how his team manages the scale and complexity of seven commercial and open-source WAFs (including AWS WAF, Cloudflare, Akamai, Azure WAF, Wallarm, and ModSecurity) by leveraging AI agents.</p><p>Discover how to construct an agentic harness, orchestrate deep research agents to gather exploit POCs, and utilize multi-model architectures (e.g., Anthropic for rule generation and OpenAI as an LLM judge) to eliminate false positives and safely deploy virtual patches</p><p><br></p><p>Guest Socials - <a href="https://www.linkedin.com/in/ammar-alim-6630a977/" target="_blank" rel="noopener noreferer">Ammar's Linkedin</a></p><p>Podcast Twitter - <a href="https://twitter.com/cloudsecpod">@CloudSecPod</a> <a href="https://twitter.com/CloudSecureNews"></a></p><p>If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:</p><p>-<a href="https://www.youtube.com/c/CloudSecurityPodcast?sub_confirmation=1">Cloud Security Podcast- Youtube</a></p><p>- <a href="https://www.cloudsecuritynewsletter.com/">Cloud Security Newsletter </a></p><p>If you are interested in AI Security, you can check out our sister podcast -<a href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII"> AI Security Podcast</a></p><p><br></p><p>Questions asked:</p><p>(00:00) Introduction & The Currency of Speed in Security(02:00) Ammar Alim’s Background: From Data Centers to Product Security at Adobe(05:00) The Multi-Vendor WAF Nightmare: Managing Scale Across 7 Products(08:30) Understanding False Positives vs. False Negatives in WAF Management(12:30) Why <24-Hour Exploit Windows Demand Virtual Patching(15:30) Pitching Product Leadership: Protecting Release Cycles with WAF Rules(18:30) High-Level Architecture: How the Agentic CVE Pipeline Listens for Disclosures(21:00) Testing Rules in ModSecurity, GitHub Actions, and Shadow Production(26:00) Defining an Agentic Harness: Memory, Constraints, and Context Engineering(32:00) Multi-Model Scoring: Using Anthropic and OpenAI as LLM Judges(34:30) Reinforcement Memory: Training Agents with OWASP and CVE Repetition(37:00) Do You Need to Be an ML Academic to Build Agentic Pipelines?(43:00) Applying Agentic Automation to Other Tedious Security Tasks </p><p><br></p><p>Resources spoken about during the episode:</p><p><a href="https://www.youtube.com/watch?v=k8bqDHfkvEw" target="_blank" rel="noopener noreferer">The