Episode
Ship It Conversations: Kat Traxler of Vectra AI on AI Security, the Zero-Day Clock, IAM, and Cloud Risk
- Published
- Jun 28, 2026
- Duration seconds
- 2553
- Processing state
not_requested- Canonical source
- https://rss.com/podcasts/ship-it-weekly/2944542
Actions
POST https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/ship-it-conversations-kat-traxler-of-vectra-ai-on-ai-security-the-zero-day-clock-iam-and-cloud-risk/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/ship-it-conversations-kat-traxler-of-vectra-ai-on-ai-security-the-zero-day-clock-iam-and-cloud-risk.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
This is a guest conversation episode of Ship It Weekly , separate from the weekly news recaps. In this Ship It: Conversations episode, I talk with Kat Traxler of Vectra AI about AI security, the zero-day clock, IAM, cloud risk, AI-assisted bug hunting, and why the scariest future security problems may still start with the boring fundamentals teams already struggle with today. Kat is a Principal Security Researcher at Vectra AI focused on abuse techniques and vulnerabilities in the public cloud, especially around the intersection of cloud security, AppSec, IAM, managed identities, and insecure-by-design flaws. We talk about the current AI security mood, from the excitement around faster research and bug hunting to the fear that AI could shrink the window between vulnerability disclosure and exploitation. Kat explains the “San Francisco Consensus,” why the zero-day clock is getting so much attention, and why she thinks the facts may be real while some of the conclusions are overextended. The bigger theme here is that AI is absolutely changing security work, but it does not erase the fundamentals. Attackers still take the lowest-friction path that works. For most teams, that still means credentials, IAM, misconfigurations, known vulnerabilities, and systems that were never threat-modeled as deeply as people assume. Highlights • Why AI security feels exciting and unsettling at the same time • What the “San Francisco Consensus” means and why people are talking about the zero-day clock • How AI may shrink the time between vulnerability disclosure and exploitation • Why Kat is skeptical of the full “zero-day apocalypse” narrative • Why credentials, IAM, misconfigurations, and known vulnerabilities still matter most for many teams • How AI helps narrow the search space in bug…