Absolute AppSec
Absolute AppSec
Absolute AppSec·Aug 25, 2026

Episode 331 - Being "Mythos" Ready, CRLF-Powered De-sync Attacks

Show notes

Sponsored by Guardsquare (guardsquare.com), Episode 331 focuses heavily on the growing role of AI agents in application security and how organizations should build and defend against agentic systems. Ken and Seth argue that effective AI security systems should combine deterministic tooling with the probabilistic reasoning of LLMs rather than handing an entire security workflow to a model. Deterministic steps can map repositories, identify dependencies, reconstruct code relationships, and narrow the areas requiring investigation, while LLMs provide reasoning and creativity where those capabilities add value. Preparing for AI-assisted attackers, emphasizing secure development practices, guardrails, sandboxing, pre-production testing, and faster detection and response. The episode also examines HTTP request smuggling and CRLF-based attacks, including how differences in request parsing between proxies and backend services can create authorization bypasses and other exploit chains. Seth and Ken emphasize identifying the critical vulnerability within an exploit chain and discuss how service-oriented architectures can increase risk when components interpret the same request differently. Finally, they question whether bug bounty programs adequately reward researchers for discovering complex, high-impact vulnerabilities, especially as AI agents increasingly automate vulnerability discovery.