The Elephant in AppSec

The Docker mistakes everyone's still making and how to fix them with Advait Patel

August 4, 2026·36 min
Episode Description from the Publisher

Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.In this episode, we get into:Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matterThe AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attackerWhy you should treat AI as an assistant on a leash, not an engineer with root accessthe Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image)…and much more!Get ready, Advait doesn't hold back his opinions. Let's dive right in!Connect with Advait: https://www.linkedin.com/in/advaitpatel93/Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/This podcast is brought to you byEscape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions.MentionedDockSec on GitHub (now the OWASP org repo): https://github.com/OWASP/DockSecOWASP project page: https://owasp.org/www-project-docksec/Open Policy Agent (his "open policy" reference): https://www.openpolicyagent.org/OWASP Top 10 for LLM Applications: https://genai.owasp.org/

Podzilla Summary coming soon

Sign up to get notified when the full AI-powered summary is ready.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.

Listen to This Episode

Get summaries like this every morning.

Free AI-powered recaps of The Elephant in AppSec and your other favorite podcasts, delivered to your inbox.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.