Paul's Security Weekly

Follow Paul's Security Weekly
Share on
Copy link to clipboard

For the latest in computer security news, hacking, and research! We sit around, drink beer, and talk security. Our show will feature technical segments that show you how to use the latest tools and techniques. Special guests appear on the show to enlighten us and change your perspective on inform…

paul@securityweekly.com


    • Sep 2, 2026 LATEST EPISODE
    • weekdays NEW EPISODES
    • 1h 14m AVG DURATION
    • 3,482 EPISODES

    4.4 from 203 ratings Listeners of Paul's Security Weekly that love the show mention: penetration, twitchy, computer security, security professionals, best security, always amusing, tester, technical content, rite, exploits, security podcast, information security, hackers, ooh, linux, cyber, story time, larry, popcorn, hacking.


    Ivy Insights

    The Paul's Security Weekly podcast is a highly entertaining and informative podcast that covers a wide range of topics in the field of information security. The hosts, Paul and Larry, are extremely knowledgeable and have a great rapport that makes listening to their discussions enjoyable. I discovered this podcast about a year ago and quickly became hooked, binge-listening to several episodes in a row. It has now become a weekly ritual for me to listen to the podcast on my way to work.

    One of the best aspects of this podcast is the wealth of information it provides. The hosts and guests delve into various issues such as attack surfaces, malware, web security, privacy concerns, encryption, networking, and more. As someone working in the industry, I have found the knowledge gained from this podcast to be invaluable in my everyday role. Additionally, the guests on the show are often key opinion leaders in the IT security field, providing valuable insights and perspectives.

    While there are many positives about this podcast, one downside is that sometimes the jokes can be cringeworthy or overly explicit. This may not be everyone's cup of tea and could potentially turn off some listeners who prefer a more professional tone. However, for those who don't mind some NSFW humor mixed with their technical discussions, it adds an element of fun to the show.

    In conclusion, The Paul's Security Weekly podcast is an excellent resource for anyone interested in information security. The hosts' expertise combined with their entertaining banter creates an enjoyable listening experience. Whether you're a seasoned professional or just starting out in the field, this podcast provides valuable insights and information that will benefit your career. Cheers to another 10 years!



    Search for episodes from Paul's Security Weekly with a specific topic:

    Latest episodes from Paul's Security Weekly

    Preventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and Kai - Galina Antova, Todd Sorrel, John Hurley - BSW #463

    Play Episode Listen Later Sep 2, 2026 60:19


    Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn't end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how? Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are the only way to defend against these sophisticated wire fraud attacks. Optiv: The One Partner to Advise, Deploy and Operate. That's Cybersecurity Simplified - Black Hat interview with John Hurley, Chief Revenue Officer of Optiv This segment will focus on Optiv's unmatched ability to advise, deploy and operate complete cybersecurity programs. With more than 6,000 clients and 450 technology partners, Optiv is the one clients trust to handle real-world cyber complexity, reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at https://securityweekly.com/optivbh. The Shift to Machine-Led Security: What's Next for Cyber Defense - Black Hat interview with Galina Antova, CEO and Co-Founder of Kai Artificial intelligence is fundamentally changing cybersecurity- not only by making attacks faster and more sophisticated, but also by forcing defenders to rethink how security operations are built. In this conversation, Kai CEO and co-founder Galina Antova discusses why the industry is moving toward machine-led security, what is preventing organizations from trusting autonomous AI, and what recent survey data from hundreds of CISOs reveals about where cybersecurity is headed next. To learn more about Kai, please visit: https://securityweekly.com/kaibh Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-463

    Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612

    Play Episode Listen Later Sep 1, 2026 33:21


    Victorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-612

    Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

    Play Episode Listen Later Sep 1, 2026 68:01


    AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-398

    Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474

    Play Episode Listen Later Aug 31, 2026 96:38


    Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh. Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out! Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS Black Hat Interview 1 - Google Cloud Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense. Segment Resources: https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more! Black Hat Interview 2 - Forcepoint Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety. Segment Resources: https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more! Black Hat Interview 3 - Keyfactor From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments. Segment Resources: https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/ https://www.keyfactor.com/education-center/what-is-trust-infrastructure/ https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1 This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more! Black Hat Interview 4 - Delinea Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session. This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-474

    Mythos Writes the Exploit. Atlas Writes the Response. - Harman Kaur - SWN #611

    Play Episode Listen Later Aug 28, 2026 41:03


    Most enterprise AI today is a conversation — it summarizes, suggests, recommends. Harman unpacks what changes when AI actually executes across endpoints, and the governance problem that creates. Where does the human stay in the loop, and where do they get out of the way? This segment is sponsored by Tanium. Visit https://securityweekly.com/tanium to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-611

    Hacking All The Devices, with AI? - Rob Allen - PSW #941

    Play Episode Listen Later Aug 27, 2026 126:01


    Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-941

    Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462

    Play Episode Listen Later Aug 26, 2026 67:29


    The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-462

    Fibonacci, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's, Aaran Leyland - SWN #610

    Play Episode Listen Later Aug 25, 2026 35:44


    Fibonacci and the Unhappy Number, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's battery, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-610

    Applying Zero Trust Principles to Agents - Kieran Human - ASW #397

    Play Episode Listen Later Aug 25, 2026 66:40


    Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface. Resources https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This interview is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-397

    Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473

    Play Episode Listen Later Aug 24, 2026 99:19


    Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. “Easy,” Rob Allen said, “it's already blocked if you're using Threatlocker.” Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting “cyber-enabled crime” mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-473

    Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able and More - SWN #609

    Play Episode Listen Later Aug 21, 2026 41:33


    Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able, Robo-Tips, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-609

    Rejoice In The Nostalgia - PSW #940

    Play Episode Listen Later Aug 20, 2026 128:22


    In the security news this week: Cursor opens your repo, the repo opens you If you want the good model I'm going to need to see your ID Flock's a Flocking mess Defender was supposed to be the chosen one Side stepping Secure boot - twice SonicWall: a LAMP stack in a fancy case Macs don't get viruses, part infinity Flipper One, but why not Nix? NetScaler is back in the room Borrowing phone's good reputation USB and how to make Windows download stuff A KVM with the expensive letters removed Five steps to stop the webcam creeps PlexTrac acquired NIST asks the internet to fix the NVD Poland's health software has a very bad week If Apple pings you about spyware, believe it A macOS stealer that drives your browser for you T-Mobile's incident response tool of choice may suprise you, or not... Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-940

    Preventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461

    Play Episode Listen Later Aug 19, 2026 53:34


    Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in safeguards, organizations can choose to enforce security policies using ThreatLocker. Rob will discuss how ThreatLocker can enforce AI boundaries through Allowlisting, Ringfencing™, Endpoint Firewall, and Web Content Control, with Community Policies that govern what agentic AI tools can run, do, access, and reach. Segment resources: - https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents - https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools - https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, 3 cybersecurity issues that should keep every CEO awake at night, You Don't Find Your Leadership Style. You Mentor Your Way Into It., Cybersecurity Starts With Communication – And We May Be Getting It Wrong, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-461

    Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608

    Play Episode Listen Later Aug 18, 2026 39:25


    The Secret Word is Meow, Red Agent, GitHub, evoooo1bot, Hatman, DecryptAds, Copilot, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-608

    Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396

    Play Episode Listen Later Aug 18, 2026 69:00


    All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to operators. This type of work is especially useful to orgs that deal with petabytes of data and thousands of systems. And, as Kiran notes, it's important to keep that scale from blowing up your budget or turning triage into a procession of false positives. Ideally, this kind of threat intel that's paying attention to attack trends and searching internal systems for evidence of compromise also turns into proactive defenses. We talk about some of the ways to engage developers to improve security visibility into their services and harden their designs against common attacks. After that discussion we're running two sponsored interviews from Black Hat. AI Pentesting and the Future of Cybersecurity: Black Hat interview with Chris Wallis, Founder and CEO of Intruder This segment discusses how AI addresses the long-standing gap between traditional pentesting and automated vulnerability scanning. Intruder CEO and founder Chris Wallis dives into the nuances of AI-enabled security and how these offerings will impact mid-market security teams. Segment Resources: https://www.intruder.io/platform/ai-pentesting https://www.intruder.io/blog/ai-pentesting-the-depth-of-a-pentest-on-demand https://www.intruder.io/blog/ai-web-app-pentesting-test-on-every-major-release Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. For more information about Intruder's products and services, please visit https://securityweekly.com/intruderbh. How Menlo Security Is Securing AI Agents from Prompt Injection: Black Hat Interview with Ramin Farassat, Chief Product Officer of Menlo Enterprises are deploying AI agents like Microsoft Copilot, Google Gemini, and Claude Code faster than they can secure them, and attackers are exploiting that gap through prompt injection. Hidden instructions get buried in web pages, files, and even images that a human would never notice but an AI agent reads and acts on. Menlo Security is building Menlo Agent Runtime Security (MARS) to close that gap, running every agent session in an isolated cloud that sanitizes content before an agent can act on it. Ramin Farassat, Menlo Security's Chief Product Officer, will discuss why the exposure lives in the connectors and integrations around the model rather than the model itself, and how security teams can put controls on the agent attack surface without blocking agentic AI outright. Segment Resources: https://www.menlosecurity.com/product/ai-agent-security MARS is now available today, please visit https://securityweekly.com/menlobh Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-396

    Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

    Play Episode Listen Later Aug 17, 2026 102:03


    Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a “mouthpad”? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-472

    Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More - SWN #607

    Play Episode Listen Later Aug 14, 2026 35:47


    Famous Mathematician feuds, Delta Flight 591, Lazarus, Akira, Computer History, Zoom, Clones, LiteLLM, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-607

    The Breached WiFi AI Ports... What? - PSW #939

    Play Episode Listen Later Aug 13, 2026 124:35


    In the security news this week: North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale Phishing-resistant MFA Goodbye SMS and voice authentication Cornflake RAT and Chaco Shell The NPM worm Hundreds of compromised packages AI lowers the barrier to mass exploitation Rethinking “secure enough” Back to basics: know what's on your network Get off my PCI lawn Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-939

    Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Greg Baker, Ihab Shraim, Lynn Dohm - BSW #460

    Play Episode Listen Later Aug 12, 2026 67:34


    As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company's IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team's research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks. Segment Resources: CSC 2026 Domain Security Report: https://www.cscdbs.com/en/resources/domain-security-report-2026/ CSC 2026 CISO Outlook Report: https://www.cscdbs.com/en/resources/ciso-outlook-2026-report/ How AI Is Reshaping What's Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased. Greg Baker will explore how AI can create a continuously updated understanding of both the enterprise security program and the market around it—giving CISOs the context to model scenarios, prioritize investments, and move from insight to action with greater speed and confidence. For more information about Balance Theory, please visit: https://securityweekly.com/balancetheorybh The Business Case for Cybersecurity Workforce Resilience - Black Hat Interview with Lynn Dohm, Executive Director of WiCyS The joint report from WiCyS and FourOne Insights reveals that mentorship, skills-based promotion, and third-party partnerships don't just improve workforce outcomes — they deliver measurable ROI, including more than $125,000 in savings per employee. As cybersecurity leaders grapple with persistent talent shortages, AI-driven skill shifts, and demographic headwinds, the report positions workforce resilience as a measurable business advantage — not just an HR initiative. Segment Resources: https://www.wicys.org/resources/the-roi-of-resilience/ https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/ This segment is sponsored by Women in CyberSecurity (WiCyS). Visit https://securityweekly.com/wicysbh to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-460

    Squirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606

    Play Episode Listen Later Aug 11, 2026 37:17


    Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-606

    Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

    Play Episode Listen Later Aug 11, 2026 69:11


    Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: https://projectdiscovery.io/research/ai-coding-impact-report https://projectdiscovery.io/blog/oh-my-rogue-agent Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-395

    discovery llm vuln rishi sharma
    Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471

    Play Episode Listen Later Aug 10, 2026 97:23


    Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why? We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape. Interview 2 with Kyle Sandy from Logically Operational Clarity as the New Customer Experience Kyle Sandy joins Adrian to discuss how prioritizing resilience affects how organizations should plan for incident response. In the past, security teams were focused on prevention and limiting breach damage. Today, boards want to know how long it will take to recover operations. The interview wraps up with a discussion of the right and wrong way to handle a breach and the three most important things every company must get right in order to handle an incident well. Interview 3 with Todd Thiemann from Omdia AI Agents and Identity Security: How Enterprises Are Rewriting the Rules Todd joins ESW with some eye-opening survey insights on the topic of IAM for AI agents. While cybersecurity conversations about internal AI use often revolve around the SOC and security operations, Omdia surveyed identity professionals for a more holistic enterprise perspective. Unsurprisingly, AI agent use is as diverse as enterprise business units. The surprises are around where the budget comes from for these AI projects, and how authentication is handled. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-471

    Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605

    Play Episode Listen Later Aug 7, 2026 38:20


    Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-605

    When AI Commits Felonies - PSW #938

    Play Episode Listen Later Aug 6, 2026 118:59


    This week: When you are not at summer camp you can't read about it The Fettle continues Using the CFAA against AI Social contracts are not security models VSCode extentions, again Bugtraq is back! NVIDA, LVFS, and unraveling AI infrastructure More routers that come with backdoors Do we care about LPE? Even more AI that finds vulnerabilities When AI breaks its own guardtails Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-938

    Say Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459

    Play Episode Listen Later Aug 5, 2026 50:19


    This week, we air our thirteenth pre-recorded segment called “Say Easy, Do Hard”. Inspired by my co-host, Jason Albuquerque, we discuss “Performance Through People”. Greg Hoffman joined us a few weeks back to discuss his new book. This week, we dig into his five disciplines of Performance Through People and do the hard part. Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-459

    Randomness, Grey, Deepseek, Sonicwall, Spice, CaptiveCrunch, eBay, and Aaran Leyland - SWN #604

    Play Episode Listen Later Aug 4, 2026 36:37


    Randomness, 50 Shades of Grey, Deepseek, Sonicwall, Spice Weasels, CaptiveCrunch, eBay, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-604

    Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394

    Play Episode Listen Later Aug 4, 2026 63:35


    There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research into the success, quality, and failures of LLM-generated security patches. Notably, they saw scenarios across a spectrum from robust, effective patches to patches that changed the software's behavior to patches that introduced new vulns to patches that didn't even fix the original vuln while also introducing a new vuln. The research considers factors like quality and correctness of prompts, complexity of the target software, programming language, and expertise required to understand what a robust patch should look like. If you're going to spend tokens on fixing security flaws, you want a feedback loop that fixes them correctly -- not an infinite loop of new flaws creeping in with every LLM iteration. Watch for this research, its toolset, and data to be released on Thursday August 6th during Black Hat. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-394

    AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

    Play Episode Listen Later Aug 3, 2026 97:00


    Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

    Rogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603

    Play Episode Listen Later Jul 31, 2026 33:02


    Rogue AI, the Bar, Breaches, BMC, More Hugging Face, Helmuth von Multke, Ike, Shieldfont, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-603

    Sandwich Hats - PSW #937

    Play Episode Listen Later Jul 30, 2026 125:15


    In the security news: 2.2 million cars, one shared Bluetooth key JFrog tries to spin an AI 0-day into a win Sextortion scammers recycling ShinyHunters' leaks The first hack ever, from 1966 Prompt injection as a service, $150 a month Cisco's mystery "static credential" BMCs still on the internet, still handing out hashes Scattered Spider duo sentenced over the TfL hack Air-gapped data sneaking out over the video cable A ghost in the network DNS poisoning checks into hotel WiFi Microsoft's cut-rate cybersecurity AI Learning to trust USB drives again Agentic pentesting shows up just in time for Black Hat Microsoft rethinks security for the AI age, again Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-937

    Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458

    Play Episode Listen Later Jul 29, 2026 41:10


    Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type. Segment 1 Resources: https://www.PredictableProfits.com Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-458

    Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet and More - SWN #602

    Play Episode Listen Later Jul 28, 2026 35:19


    Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-602

    Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393

    Play Episode Listen Later Jul 28, 2026 69:55


    Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known security threats. Mert Saltimaz talks about the background of the project, how orgs can use it as they bring more LLMs into their environment, and how the project intends to grow. Importantly, we also talk about the security controls and designs that orgs can build around the systems and data that models interact with in addition to evaluating the security of the agents and agent harnesses themselves. Segment Resources: https://github.com/OWASP/Agent-Security-Regression-Harness https://youtu.be/6DWs5EwbFQ0?si=r0IJ_F0SZnkPzzYg -- "What Trading Systems Taught Me About Breaking (And Defending) Infrastructure" Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-393

    Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469

    Play Episode Listen Later Jul 27, 2026 110:45


    Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a “dumb phone”? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-469

    Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland - SWN #601

    Play Episode Listen Later Jul 24, 2026 34:12


    Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-601

    Fixing Vulns Is Harder Than Finding Them - PSW #936

    Play Episode Listen Later Jul 23, 2026 122:34


    In the news this week: InfraTrust and knowing what to patch Adversary in the middle triggered command injection Exploitarium again FreeRDP comes with free vulnerabilities AI breaking out of sandboxes on its own Wordpress RCE DMA dangers Nightmware eclypse is at it again Fortisandbox Turning AI to the dark side more prompt injection Secure boot is broken, still and again... Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-936

    AI's Disruption as Cybersecurity's Economics Are Broken, Compounding Security Debt - Ben Gilliland - BSW #457

    Play Episode Listen Later Jul 22, 2026 58:42


    America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American history? Ben Gilliland, author of the upcoming book Breaking the Compact, joins Business Security Weekly to discuss why business leaders need to be prepared for the upcoming AI disruption. The impact of AI, which has not fully materialized, goes far beyond security and job displacement. It will impact our economy, our privacy, and our way of life. The closest recent warning is the "China shock," the period of rapidly increasing import competition that followed China's integration into the global trading system. AI will dwarf that. Ben will discuss the human advantage and how we can prepare now. In the leadership and communications segment, Cybersecurity's Economics Are Broken. Automation Alone Won't Fix It, The business case for burning down security debt: A practical approach for CISOs, The last human relationship in cybersecurity, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-457

    LegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - Kieran Human - SWN #600

    Play Episode Listen Later Jul 21, 2026 36:47


    Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More. Segment Resources: Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/ This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-600

    MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

    Play Episode Listen Later Jul 21, 2026 72:06


    Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system. Resources: https://objective-see.org/blog/blog_0x86.html https://objective-see.org/products/lulu.html https://objectivebythesea.org/v9/index.html Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-392

    AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

    Play Episode Listen Later Jul 20, 2026 102:29


    Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions. In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution. Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting. Segment Resources: https://arcova.com/sectors/ https://arcova.com/category/blog/ For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova Topic: CMMC Pause creating chaos among federal contractors This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself. I think Howard Holton nails it here when he says: "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November." PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons. What this means: Phase II is paused Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work) NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required 60-day review aims to reform CMMC DoW opened an RFI for industry perspectives on what they should do CMMC characterized as a "compliance burden" and "red tape" False Claims Act and DOJ's cyber-fraud enforcement are still on the table More resources: CIO Davies' post on Twitter Administrator of the Small Business Administration, Kelly Loeffler's post A useful LinkedIn post that breaks down a lot of what this really means (and doesn't) Weekly Enterprise News Finally, in the enterprise security news, will AI eliminate more cybersecurity jobs than it creates? Linus's law, amended the biggest patch Tuesday ever AI context bombs AI workflows are a security disaster people using AI in areas they don't understand ransomware crews are hitting legal firms hard lessons learned from CISA's recent github leak demystify your USB cables! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-468

    M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More - SWN #599

    Play Episode Listen Later Jul 17, 2026 34:16


    M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-599

    1999 Called and It Wants It's Exploits Back - PSW #935

    Play Episode Listen Later Jul 16, 2026 131:49


    This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously discussed! Then in the security news: The GodDamn Ransomware CMMC suspended Holy Microsoft Tuesday! Lessons learned Without the Internet, do we still get water? The forgotten shims More than two BIOS passwords Cracking firmware encryption with Claude 1999 called, and it wants its "Exploits" back Prompt injection for defenders Grok has your repo You're not going to outpatch AI Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-935

    Take Back Control as Enterprises Struggle to Incorporate Risks They Don't Understand - Ben Lipczynski - BSW #456

    Play Episode Listen Later Jul 15, 2026 55:20


    More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited. However, you're expected to mitigate all vulnerabilities, or at least critical and high. But what if there is no patch to fix the vulnerability or the software is unsupported? Ben Lipcynski, Director Security and Regulatory Services at Optima, joins Business Security Weekly to discuss how organizations can take back control of your enterprise software. OPTAS — Origina Proactive Threat Assurance Service — predicts, validates, prioritizes, and mitigates threats specific to your environment. Unlike AI vulnerability tools that flag everything without context or mitigation guidance, OPTAS cuts through the noise. OPTAS helps security teams focus on the risks that matter instead of chasing the 99% that do not. Segment Resources: - https://www.origina.com/optas#optas-overview This segment is sponsored by Origina. Visit https://securityweekly.com/origina to request a consultation. In the leadership and communications segment, US enterprises incorporate cyber risk into larger strategic focus, 75% of CISOs Fear Executives Don't Understand Cybersecurity Risks, AI agents are not your “coworkers”, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-456

    Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598

    Play Episode Listen Later Jul 14, 2026 31:19


    Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-598

    Discovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391

    Play Episode Listen Later Jul 14, 2026 67:29


    While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface. A lot of orgs don't have to deal with model-specific threats or building their own GPU architecture, but every org adopting LLMs and agents should be aware of how those agents are being invoked and the output those agents are producing. That awareness of input and output helps in identifying and mitigating prompt injection attacks, ensuring agents are working within their expected boundaries, and taming token budgets. Resources: https://genai.owasp.org/llm-top-10/ https://github.com/rtk-ai/rtk https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-caching.html https://www.firetail.ai/blog/beyond-the-spectacle-rsac-2026-and-the-5-layers-of-ai-security Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-391

    Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467

    Play Episode Listen Later Jul 13, 2026 98:59


    Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-467

    Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet,.. - SWN #597

    Play Episode Listen Later Jul 10, 2026 33:23


    Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Locutus, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-597

    AI Is Annoying & IoT Devices Still Get Hacked - PSW #934

    Play Episode Listen Later Jul 9, 2026 125:41


    In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV's Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabilities Citrix just keeps bleeding Old hardware is new again A sneak peak into next week's tech segment Tenda hidden backdoors We're still talking about Mirai Today was not a good day for Roundcube Canada is hacking criminals AI safeguards are still annnoying All cars will spy on you The FatFs unpatched vulnerability in millions of embedded devices Windows OS market share drops below 60% (Paul uses Arch) ‘We Cannot Choose to Become Idiots' - or can we? Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-934

    Why AI Just Broke Traditional IT Security as Leaders Clash Over AI's Value and Hiring - Matt Quinn - BSW #455

    Play Episode Listen Later Jul 8, 2026 50:10


    The latest generation of AI models has collapsed the time from vulnerability discovery to weaponized exploit from weeks to minutes, and reactive, module-based tools built around static dashboards simply can't keep up. In this episode, Tanium COO Matt Quinn joins Business Security Weekly to discuss Tanium Atlas, the new autonomous operating system for IT and security. Matt explains why "good enough" operations are now a liability, how Atlas turns a single operator into the equivalent of an entire team, giving organizations the speed, scale, and efficiency to match the pace of today's threat environment. He also breaks down why nearly two decades of real-time endpoint telemetry across more than 36 million endpoints is the foundation no AI model can replicate on its own. This segment is sponsored by Tanium. Visit https://securityweekly.com/tanium to learn more about them! In the leadership and communications segment, CEOs, CIOs clash over AI's value, Aspiring Leaders, Don't Just Network Up, Your Talent Strategy Has to Keep Up with Your AI Transformation, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-455

    Dune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland & More - SWN #596

    Play Episode Listen Later Jul 7, 2026 33:16


    Dune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-596

    Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390

    Play Episode Listen Later Jul 7, 2026 47:53


    Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and why they are important to mobile applications. Securing workflows goes beyond input validation and pattern matching suspicious payloads; it requires detailed attention to state machines, edge cases, and collecting signals to evaluate trust. Segment Resources: https://hubs.la/Q04jLKj70 https://mas.owasp.org/MASTG/0x04c-Tampering-and-Reverse-Engineering/ https://owasp.org/API-Security/editions/2023/en/0x00-header/ This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-390

    Claim Paul's Security Weekly

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel