How Adobe Uses AI Agents for building a WAF Pipeline?

How Adobe Uses AI Agents for building a WAF Pipeline?

Source: YouTube · Cloud Security Podcast · published Aug 4, 2026 · 47:09

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

In security, speed is the biggest currency—AI now enables attackers to stitch multiple vulnerabilities together for root access 0:00-0:20, while the window between vulnerability disclosure and exploitation has shrunk to under 24 hours 0:21-0:27.

Key Takeaways:
• Managing multiple WAFs (Adobe uses seven) doesn't scale with human administrators due to sheer complexity, making AI-driven automation essential 5:07-5:15
• AI excels at reducing false positives by reading source code, architecture diagrams, and threat models to craft custom WAF rules 10:06-10:55
• The agentic pipeline: ingest CVEs via GitHub API → scan environment → deep research agent gathers POCs → AI generates rules → test locally → staging deployment → shadow mode → blocking mode 18:42-21:28
• A "harness" is the agent's operating environment—including APIs, shell commands, memory, and instructions—that enables it to execute tasks autonomously 29:45-30:37
• Use multiple models (generator + judge) for different perspectives, and generate rules even for non-relevant CVEs to train the system through repetition 32:25-34:55

This framework extends beyond WAFs to SOC analysis, detection engineering, and incident response—start small by automating tedious daily tasks 42:59-45:30.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Insecurity, the biggest currency is speed. If you can't secure quick, might as well you just don't secure. He [music] told his AI system, find a way to give me root access to this device, shell access. And the AI was able to stitch multiple vulnerabilities together and have root access in the Wi-Fi system. >> Vulnerability being announced in publicly and explored found in the wild, the window was less than 24 hours. >> Urgent health issue, don't do that. Game is not the answer. The answer is calling 911. I didn't go to school for it or anything. Um >> No academic, none of that stuff, right? >> I didn't build a model um or >> Any given day, this kind of vulnerability is coming every day. >> Things will be discovered very fast and taken advantage of very fast. I'm talking about we going from…