
The episode discusses Docker security vulnerabilities and how AI can enhance container scanning through the open-source tool DockSec.
Containers run much of the software we depend on, and many are shipped with security problems that no one noticed. Traditional container scanning tools can miss important vulnerabilities, insecure configurations, embedded secrets, and risky Dockerfile patterns before they reach production. In this episode, ISACA’s Adedayo Ojo, Principal, Emerging Technologies and Professional Practices, Research Development, speaks with Advait Patel, Senior Site Reliability Engineer at Broadcom, Docker Captain, and Google Developer Expert in Google Cloud, about why traditional container scanning misses so much and what it takes to identify the issues that matter most. Advait shares lessons from running containers at scale on a large cloud platform and explains how he built DockSec, an open-source tool that uses AI to identify insecure Dockerfile patterns, embedded secrets, and misconfigurations that signature-based scanners tend to overlook. The conversation offers practical guidance that developers and security teams can apply immediately, along with an honest look at where AI can strengthen container security—and where it cannot. Related Resources & Stay Connected Explore DockSec on GitHub…
Host: Adedayo Ojo
Guest: Advait Patel
Organizations: Broadcom, Google, OWASP
Products: DockSec
Explore listener stats, chart rankings, contacts and more on the ISACA Podcast podcast page.