The Most Exciting Time in InfoSec
AI-driven vulnerability management is entering its most consequential decade. Wade Woolwine, Senior Director of Product Security and Distinguished Engineer at Rapid7, sat down with Alan Shimel to unpack the shift. In addition, they explore how AI is rewriting every playbook defenders rely on.
Wade Woolwine of Rapid7 with Alan Shimel on Techstrong TV.About Wade Woolwine
Wade has spent more than two decades in the industry. As a result, he has watched security transform from the dial-up era through today’s LLM-driven world. Meanwhile, Rapid7 has grown from a scanner vendor into a full detection, response and attack-surface management platform.
Why AI-driven vulnerability management matters now
On this episode of Techstrong TV, the two hosts trace how the category has evolved. Together, they cover the shift from standalone scanners into integrated platforms. In addition, they explain why the space is finally converging around business risk instead of raw findings.
Wade also makes a bold claim. According to him, this is the most exciting moment his career has ever seen. Furthermore, AI is expanding the surface of discoverable flaws. At the same time, defenders now have new tools. These tools prioritize by business impact instead of raw CVSS scores.
A practical challenge for every engineer
The conversation gets practical, too. As a result, Wade challenges every security engineer to pick up Claude Code, Codex and similar tools. However, he clarifies the goal is not developer bragging rights. Instead, engineers should use these tools to automate scripts, glue APIs together and 10x their own workflows. For more on this shift, browse other interviews in this series.
Finally, the closing moments turn philosophical. AI-authored code, he argues, forces a fundamental rethink of what “quality” really means. In short, AI-driven vulnerability management is only one piece of a much bigger transformation now underway in security. Learn more about Rapid7’s approach at rapid7.com, or explore additional security coverage on Techstrong TV.
Transcript
Hey, everyone. Welcome back here to Techstrong TV. My next guest is Wade Wohlwine.
Wade is the senior director of product security and distinguished engineer at Rapid7. Well, Wade, that's a heavy title to bring on in here. Welcome to Techstrong TV.
It's great to have you on. Thank you very much for having me. I appreciate it.
So I've had the pleasure of meeting a lot of folks who have distinguished engineer, distinguished fellow in their name, and it's always a great story hearing their stories. Let's hear your story. Sure.
So over my 27-year career, I have touched just about every aspect of information security that you can possibly imagine. Though I have primarily specialized in the detection and response and exposure space. My employers include wonderful names such as Mandiant and now Rapid7, where I lead our product security function.
I love it. So I've been in cyber myself, right around 27 years, too. '98, '99, helped a dot-com company, and we were in ASP, if you remember that back then, application service provider.
But part of it was we were also managing the firewall. This is before. There's no cloud, virtualization was in its infancy.
So we had checkpoint firewalls wrapped around machines running Lotus Notes, Domino server, PeopleSoft, Oracle, stuff like this, and we would do managed firewall. And from there, I spent a long time in security. As a matter of fact, I remember when Rapid7 launched, Alan Matthews and Rapid7, the first interface was one of the most ugliest interfaces I ever saw in my life.
At the time, companies like EI, Foundstone, I'm sure you're familiar with all those names, EI, Foundstone, Qualys was there already, Tenable was there. So it was an interesting time in the vulnerability management assessment space. But we've come a long way.
Would you say Rapid7 is still a vulnerability assessment of management, or has it mission grown? The mission has definitely grown. So while Rapid7 was really born out of the vulnerability management space, about 12 years ago, the company decided to branch into the detection and response space, and as a matter of fact, that's when I joined the company.
So my initial work at Rapid7 was building out the MDR service, helping evolve the product that they had launched at the time was called User Insight, is now called InsightIDR. And ever since, we've been on a mission to really be the security data platform that not only brings in the data from our tooling and VM and detection and response in attack surface management, but then also being able to bring in third-party data feeds so that our customers can get a full picture of everything that is going on in their ecosystem and take action when the red lights go blinky blink. When the red lights go blinky blink, yes.
The dreaded red light blinky blink. Look, for me, a turning point in the Rapid7 evolution was when they acquired Metasploit and really moved from sort of that traditional vulnerability scan to pen testing and all that, which I think the next logical step was the threat detection and the stuff you're involved in. I think it's all part of that succession, but it's all part of what you need to be a security company today, right?
To be a cyber company. Yes, absolutely. The world's changing.
The world has absolutely changed, and you can even see it in the cybersecurity market. A lot of the big vendors are starting to bring a lot of capabilities under a single umbrella because at the end of the day, when you're running a security program, all of the components are dependent on each other. Your vulnerability management program informs your DNR program, informs your attack surface management program, and if all of that information is in different places, different silos, different tools, it becomes very difficult to really have a complete view of where your attack surface is, where the attackers are targeting, and of course, where to be able to remediate.
Agreed. We haven't mentioned the AI word yet, have we? We have not mentioned the AI word, but it has been- Let me just take note of the time.
It's about seven minutes in. That's a record. I think that might be a record, yes.
Yeah. It's the world we live in, man. Absolutely.
But seriously, AI's changing the game, and maybe... Well, it's changed the game in coding like crazy. But with the advent of Mythos and all of the other ones, it's not just Mythos anymore.
Five six was, I think, allowed out today. ChatGPT was-- Five six was released today. The Chinese, I forget which one, ZAI, I forgot what, GA 52, whatever it's called.
That supposedly has similar capabilities. GLM 52 has those capabilities. It's turned vulnerability on its head.
The bottleneck used to be how many vulnerabilities could we find? We were never able to fix the ones we found. That was always the problem.
We never caught up. We never remediated fast enough to keep up with the vulnerabilities we were finding. Now we're finding, you want to say 2X, 10X, 100X more vulnerabilities.
What are we supposed to do? Sure. Well, I think that we've really been in this space, call it for the last six to eight months, where the disclosure of new vulnerabilities has really accelerated.
And of course, this isn't just the traditional vulnerabilities in our operating systems or in our servers. This is also vulnerabilities in open source packages that every single piece of software that we use incorporate. And so organizations have really had to start evolving their practices into, quite frankly, what they should've been doing in the first place, which is really prioritizing the vulnerabilities, not just based on CVSS scores or Kev or any of the other kind of public ratings, but the importance of the system or the software within their own infrastructure.
So doing business impact analysis, doing disaster recovery exercises to identify which assets within your environment are the most critical, and prioritizing patching those over everything else. Wade, I don't disagree with you. I agree wholeheartedly.
I wrote an article about this. You know the old story that surgery was a success, but the patient died, right? The problem we have getting from here to there is we got to get there, we got to live through that, and it's hard.
I'm glad I sit on this side of the camera. I just get to ask you guys questions and talk about it rather than actually having to do it, because I don't know how we do it. Because what you're asking for is, we talk about technical debt.
We've known this, those of us in security like you and I, 25-plus years. We've known this for 25-plus years, and we've been preaching, and security people are paranoid, and the sky's falling, and the bride wolf, and how many times have we all heard that story? But now what's the saying?
Whatever's come home to roost or whatever. It's come home. It has indeed come home, and we look slightly less crazy for all of the things that we've been saying for the last 25 years about defense- Yep ...
in depth, and there is no silver bullet. Resilience. Yeah.
Right. Exactly. You pick the saying.
But honestly, to your comment about being on that side of the camera, frankly, there has been no more exciting time in my career- Oh, yeah ... in InfoSec than today. Not just because of the evolution of the threat actor, the presence of AI, and so on and so forth.
It's that the interest and the attention in security- In the spotlight ... has gotten to the board level. There you go.
Exactly. When the Rapid7 board convenes, our chief information security officer speaks to the board, speaks to the audit committee, gives them information about the risks and the remediations. And so we're no longer having to beg to get things done.
Security is a business imperative if you want to make it, especially in the cybersecurity product space. Absolutely. Wade, I want to give the folks at home something they could take with them, though.
So we're living in this era. There's no going back. How are our security friends out here, fellow security workers, aspiring security people, even not our platform engineers, our DevOps engineers, our developers who watch this, what can we give them?
What can we advise them on how they can... Because you could use AI for good to help you with this and apply it to real-world situations. Yeah, absolutely.
And the first thing that I would say to any individual security engineer out there is pick up Cloud Code, pick up Codex, because those tools are not just for developers. And even if you consider them to just be developer tools, how many times have you written a script to solve a security problem? These tools are not only accelerating development, they are accelerating security work.
And as you become more curious with those tools, you start asking them to do different things. You start asking them to connect to the APIs of your security tools across three or four different security tools, and they're able to rationalize and reconcile different components of data to help answer the questions that you have as a security analyst. So taking my world, for example, in product security, the reverse of coding is product security.
And so we use these tools in order to go through our source code, identify potential vulnerabilities, propose fixes to the developers. And now, because we are using a common platform across both security and engineering, we can provide artifacts and files that the Cloud Code instance that my developers are using understand. And so it's become much easier to communicate the issues that we've identified.
It becomes much easier for the developers to validate those findings, to determine whether within the context of the other controls that are in place, whether those vulnerabilities are still true or if they're not exploitable. So AI, for me, when I started picking up Cloud Code, oh gosh, I think it was Cloud Code beta, honestly, that ages me in the AI space. I just started asking it questions that I didn't think it could provide the answers to, or I started asking it to do things that I didn't think it could do, and I was really surprised to find out that it was able to.
When the agent has access to the command line, when the agent understands how to communicate with APIs, when the agent understands how to write its own code to solve its problems, its capabilities are just about limitless. Yeah. The scary thing is it's getting better every- It is ...
release. I mentioned earlier- It is ... 6 came out today, I think it was allowed out.
0 Claude release. 5 came out today? It's supposed to be on par, Mythos maybe level even, is what Elon says, anyway, if you believe him.
We're in this Cold War kind of thing, and Cold War maybe is a good word for it because we mentioned the Chinese models. They're not far behind, not far behind at all anymore. And so you can't stop the merry-go-round and get off.
We're stuck in this, you want to call it a hamster wheel? I don't know. But we're stuck in this cycle.
You see, as we both, I think, talked about before, maybe at some point it all winds up being for the good. Right? We build better code as a result.
That is to be determined. We can wish, can't we? Indeed.
I have lots of debates with developers about this because the complaint is that LLMs and, in general, AI models don't code as well as humans. And my argument to that is, well, the AI agent is coding for what it thinks is best, which is not necessarily what humans think are best. Right?
When we look at software development practices where you want to make sure that you reuse your code, you don't write multiple functions for the same thing, the AI doesn't have that same problem. Right? If it needs to go make a fix to one of the three or three of the three functions it wrote to do the same thing, it can do that, no sweat.
So, I think there's a reckoning that needs to happen around, yes, we are trusting this AI to write its software, but we can't necessarily be critical of what it is doing, because ultimately it is operating as designed. If you want human-written code, nice, clean, all of those things, then by all means, let a human write it. But AI writes some sloppy code, I will certainly admit.
But in general, it works. And if you really know how to harness these coding models, you start to understand the areas where the AI is writing slop or developing functions that aren't necessarily right, or introducing security vulnerabilities, and you can tune your development harness to make sure that it takes care of those things. It's just like any new tool.
It takes a lot of time and practice to really refine your craft in using this new tool. Absolutely. Hey, Wade, we're over time.
I enjoy talking. I can talk about this all day, to tell you the truth. But for people out here who maybe want to find out more, stay in the conversation, maybe want to find out more about Rapid7, what's your best advice?
Absolutely. Check out the Rapid7 blog. All of the experts in the company produce content on a regular basis.
Check out the Rapid7 page on LinkedIn, because again, lots of good content there. And last but not least, feel free to find me on LinkedIn. I publish under Rapid7 brand, also my own.
So, happy to have a conversation offline. Love it. Wade Woolwine, thank you for coming here on Techstrong TV today.
Appreciate it. Are you going to be in Vegas for Black Hat, DEF CON, any of the fun stuff? After 27 years in the industry, I do not attend those crazy events anymore, but- I don't blame you ...
some of the smaller ones, the BSides, the OWASP conferences- Got it ... those, I generally attend. So, I actually was at the very first Security BSides Vegas, which was the first BSides.
And there was a period I stopped when I was still in the industry. I wasn't on this side of the camera. Now that I'm on this side of the camera, I go because it's recovery.
But you're not missing anything in 115-degree heat, that's for sure. Agreed. Yeah.
Well, thank you very much. It was a pleasure being on the show. Thank you.
All right. Wade Woolwine, Senior Director of Product Security and Distinguished Engineer at Rapid7, here on Techstrong TV. We're going to take a break.
We'll be back with more, lots more. Stay tuned.