惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
SecWiki News
SecWiki News
博客园_首页
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
P
Palo Alto Networks Blog
V
Vulnerabilities – Threatpost
Project Zero
Project Zero
WordPress大学
WordPress大学
NISL@THU
NISL@THU
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Privacy & Cybersecurity Law Blog
Jina AI
Jina AI
AWS News Blog
AWS News Blog
Scott Helme
Scott Helme
Martin Fowler
Martin Fowler
C
Cybersecurity and Infrastructure Security Agency CISA
Forbes - Security
Forbes - Security
H
Heimdal Security Blog
小众软件
小众软件
I
Intezer
A
Arctic Wolf
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
O
OpenAI News
S
Security Affairs
阮一峰的网络日志
阮一峰的网络日志
Latest news
Latest news
G
GRAHAM CLULEY
Blog — PlanetScale
Blog — PlanetScale
J
Java Code Geeks
N
News and Events Feed by Topic
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
V2EX - 技术
V2EX - 技术
Stack Overflow Blog
Stack Overflow Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
L
LINUX DO - 最新话题
博客园 - Franky
P
Proofpoint News Feed
aimingoo的专栏
aimingoo的专栏
博客园 - 司徒正美
P
Proofpoint News Feed
S
Secure Thoughts
Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
T
The Exploit Database - CXSecurity.com
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
C
CXSECURITY Database RSS Feed - CXSecurity.com
F
Full Disclosure
Security Latest
Security Latest

Risky Business Media

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers Srsly Risky Biz: Knives are out for open-weight AI models Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach Risky Business #845 -- OpenAI's Skynet moment Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraine Risky Bulletin: Hacker wipes Romania's entire land registry database Sponsored: Thinkst on building companies that don’t suck Srsly Risky Biz: Ransomware uses AI to amp up negotiations Fortibleed: The bleeding edge of AI cybercrime Between Two Nerds: Exploits are not cyber power What to do 'til the bugpocalypse gets here Risky Bulletin: NSA Tailored Access Operations is back Sponsored: Why Sublime doesn’t toss AI at every email Srsly Risky Biz: US Supreme Court undermines Section 702 intel Risky Bulletin: DHS IG investigates forced CISA reassignments Soap Box: Using threat hunting to drive detection Between Two Nerds: Why AI has not meant more hacks. Yet. Risky Bulletin: EU official’s phone infected with Pegasus Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices Srsly Risky Biz: America won't beat the distillation ecosystem Risky Bulletin: Researcher drops giant cache of zero-days Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban Between Two Nerds: Set cyberspace ablaze Risky Bulletin: White House asks OpenAI to restrict GPT 5.6 Sponsored: Corelight’s blueprint for AI-era defence Risky Bulletin: Operation Endgame dismantles Amadey and StealerC Srsly Risky Biz: Open weight models make the Mythos debate moot Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffing Risky Business #843 -- Fortibleed is kinda awesome, actually Pitching security startups to VCs in the AI era Sponsored: Trail of Bits and OpenAI patch the planet Between Two Nerds: The PRC vs AI Risky Bulletin: Klue breach impacts security firms How using open weight models can blow up in your face Risky Bulletin: Creds for 74,000 Fortinet devices leaked Srsly Risky Biz: Anthropic has artificial, but not emotional, intelligence Risky Bulletin: China arrests Silver Fox cybercrime group suspects Risky Business #842 -- Anthropic needs an adult in the C suite The state of the art in AI model jailbreaks Between Two Nerds: Why NATO and cyber don't mix Risky Bulletin: Arch Linux supply chain attack hits 1,900 packages Sponsored: Ent on using AI to track human behavior on the endpoint Why NPM v12 won’t stop supply chain attacks Risky Bulletin: CISA tightens patching rules amid bug deluge Sponsored: Understanding CI/CD attack paths Srsly Risky Biz: Europe wants to wean itself off US tech Risky Bulletin: Nightmare Eclipse drops fresh 0day Risky Business #841 -- Microsoft gets owned and 0day'd Between Two Nerds: Nerds at NATO Risky Bulletin: RubyGems adds dependency cooldowns to counter supply chain attacks Everything is getting much worse, much faster Soap Box: Detection and response in the AI age Risky Bulletin: EU unveils digital sovereignty plan Srsly Risky Biz: NATO's cyber approach needs to change Risky Bulletin: FSB calls out Western spyware operation Risky Business #840 -- Microsoft walks back researcher threats Solo podcast: A deep dive on TeamPCP Between Two Nerds: The intelligence cult Risky Bulletin: Recently patched PAN 0day exploited in the wild Sponsored: Inside CISA's disastrous secrets leak Risky Bulletin: Dutch police take down 17m device botnet Risky Bulletin: Iran to reconnect to the Internet Risky Business #839 -- TeamPCP stole GitHub's internal repos How to survive supply chain attacks Risky Bulletin: Mythos has found thousands of critical bugs Sponsored: Teaching AI agents the rules of the road Risky Bulletin: Microsoft ends SMS MFA for personal accounts How the CopyFail disclosure went sideways Risky Business #838 -- GitHub investigates possible breach
Mythos on your desk? Using local LLMs for code reviews
James Wilson · 2026-06-30 · via Risky Business Media

Risky Business Features Podcast

June 30, 2026

Presented by

James Wilson

James Wilson

Technology Editor

In this podcast episode James Wilson chats with Karsten Nohl about his research into using local LLMs to replace cloud AI in security code reviews.

In essence, Karsten created a hybrid code reviewing system where both cloud and local models are used to orchestrate, triage outputs, and write reports. In this system, only the local LLMs have source code access, with the cloud models used to manage the local models.

In this “source-local” review technique, the source code never leaves the local endpoint, which is a requirement for some reviews. But funnily enough, Karsten was able to use this system to generate findings that were as impressive as when using frontier models directly.

In a nutshell, Karsten proved it’s possible to use locally-hosted, open-weight models running on commodity hardware to produce findings comparable to those discovered by frontier cloud models.

This episode is also available on YouTube.

Your browser does not support the audio element.

Mythos on your desk? Using local LLMs for code reviews

0:00 / 71:29

Logo