
← The Elephant in AppSec4 aug · 36 min
The Docker mistakes everyone's still making and how to fix them with Advait Patel
<p>Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.</p><p><br></p><p>In this episode, we get into:</p><ul><li><p>Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matter</p></li><li><p>The AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attacker</p></li><li><p>Why you should treat AI as an assistant on a leash, not an engineer with root access</p></li><li><p>the Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image)</p></li></ul><p>…and much more!</p><p>Get ready, Advait doesn't hold back his opinions. Let's dive right in!</p><p>Connect with Advait: <a href="https://www.linkedin.com/in/advaitpatel93/"><u>https://www.linkedin.com/in/advaitpatel93/</u></a></p><p>Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/</p><p>This podcast is brought to you by</p><p>Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions.</p><p>Mentioned</p><p>DockSec on GitHub (now the OWASP org repo):<a href="https://github.com/OWASP/DockSec"> <u>https://github.com/OWASP/DockSec</u></a></p><p>OWASP project page:<a href="https://owasp.org/www-project-docksec/"> <u>https://owasp.org/www-project-docksec/</u></a><u></u></p><p><u>Open Policy Agent (his "open policy" reference):</u><a href="https://www.openpolicyagent.org/"><u> https://www.openpolicyagent.org/</u></a></p><p><u>OWASP Top 10 for LLM Applications:</u><a href="https://genai.owasp.org/"><u> https://genai.owasp.org/</u></a><br></p>