Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394

Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394

Author: Security Weekly Productions August 4, 2026 Duration: 1:03:35

There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research into the success, quality, and failures of LLM-generated security patches. Notably, they saw scenarios across a spectrum from robust, effective patches to patches that changed the software's behavior to patches that introduced new vulns to patches that didn't even fix the original vuln while also introducing a new vuln.

The research considers factors like quality and correctness of prompts, complexity of the target software, programming language, and expertise required to understand what a robust patch should look like. If you're going to spend tokens on fixing security flaws, you want a feedback loop that fixes them correctly -- not an infinite loop of new flaws creeping in with every LLM iteration.

Watch for this research, its toolset, and data to be released on Thursday August 6th during Black Hat.

Show Notes: https://securityweekly.com/asw-394


Dive into the ever-evolving world of digital defense with the Security Weekly Podcast Network (Video). Produced by Security Weekly Productions, this network isn't a single perspective but a comprehensive hub where different facets of cybersecurity come into focus through distinct, dedicated shows. You'll find episodes from series like Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News, all curated in one feed. This structure means that whether you're analyzing code, shaping corporate policy, or managing infrastructure, there's relevant content for you. The discussions move beyond headlines, offering practical analysis and expert insights that help make sense of complex threats and solutions. By blending technology deep dives with timely news commentary, this video podcast provides a multi-dimensional view of the field, suitable for professionals who need to stay informed and enthusiasts curious about how security shapes our digital lives. It’s a consistent resource for anyone looking to understand not just what is happening in cybersecurity, but why it matters and how to respond.
Author: Language: English Episodes: 50

Security Weekly Podcast Network (Video)
Podcast Episodes
Fixing Vulns Is Harder Than Finding Them - PSW #936 [not-audio_url] [/not-audio_url]

Duration: 2:02:34
In the news this week: InfraTrust and knowing what to patch Adversary in the middle triggered command injection Exploitarium again FreeRDP comes with free vulnerabilities AI breaking out of sandboxes on its own Wordpress…
1999 Called and It Wants It's Exploits Back - PSW #935 [not-audio_url] [/not-audio_url]

Duration: 2:11:49
This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python imple…