Podcasts about ai security

  • 374PODCASTS
  • 775EPISODES
  • 51mAVG DURATION
  • 1DAILY NEW EPISODE
  • Aug 26, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about ai security

Latest podcast episodes about ai security

Security Now (MP3)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (MP3)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

All TWiT.tv Shows (MP3)
Security Now 1093: Tokens in the Stream

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Security Now (Video HD)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (Video HD)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Security Now (Video HI)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (Video HI)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Radio Leo (Audio)
Security Now 1093: Tokens in the Stream

Radio Leo (Audio)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Security Now (Video LO)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (Video LO)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Application Security PodCast
AI Security: OWASP Meets Global Standards

Application Security PodCast

Play Episode Listen Later Aug 26, 2026 47:54


AI security has no shortage of standards—but how do we turn them into practical guidance? Rob van der Veer explains how OWASP, the AI Exchange, and MOSAIC are coordinating global AI security efforts. We also explore responsible AI, agentic red teaming, vulnerability discovery, and how AI could level the playing field between attackers and defenders.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more: Corgea.comAbout CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.Learn more about Corgea → https://bit.ly/4wMCNUfFOLLOW OUR SOCIAL MEDIA:➜ Twitter: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcastFOLLOW OUR SOCIAL MEDIA:➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Cloud Security Podcast
The "Hunt First" AI Security Strategy

Cloud Security Podcast

Play Episode Listen Later Aug 25, 2026 46:29


Did you know that 82% of all intrusions don't involve any sort of malware, and AI-augmented attacks are up 89% year over year? If your security operations team is solely focused on reacting to known-bad SIEM alerts, you may be missing the silent breaches. In this episode, Ashish is joined by Damien Lewke, Founder and CEO of Nebulock, to discuss the critical shift toward a "Hunt First" mindset. Damien explains why moving away from alert fatigue and focusing on raw, normalized telemetry (across endpoint, identity, and cloud) is the only way to proactively surface unknown threats. We also dive into how AI is finally democratizing the elite skill of threat hunting, allowing even single-person security teams to investigate and attribute complex behaviors.From hunting down shadow AI (like unapproved MCPs) to challenging the notion that AI will replace threat hunters, this episode is a masterclass in modern security operations. Guest Socials -⁠⁠ Damien's LinkedinPodcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security PodcastQuestions asked:(00:00) Introduction: The Problem with Reactive Security Alerts(02:00) Damien Lewke's Background (DoD, CrowdStrike, Arctic Wolf, Nebulock)(04:00) Why Breaches Happen in Silence: The Value of Telemetry Over Alerts(05:30) How AI Democratizes Elite Threat Hunting for Small Teams(07:30) Defining the "Hunt First" Mindset and Methodology(11:00) Surfacing Active Intrusions Using Cross-Domain Context(13:30) The Importance of Transparency in AI Decision Making(16:30) When NOT to Use AI for Detections (The Power of Heuristics)(18:30) The Best First AI Security Use Case: Hunting Shadow AI & MCPs(23:00) Detecting Rogue AI Agents via Tempo, Breadth, and Automation Signatures(28:30) The Future of SIEM: Data Gravity vs. Purpose-Built Security Analytics(34:30) Disagreeing with Gartner: Why Threat Hunters Are More Vital Than Ever(40:00) The 89% Rise in AI-Augmented Attacks and Taking Action(41:30) The "You Laugh, You Lose" Cybersecurity Joke Challenge Resources spoken about during the episode:- Hunting MCP Server Exploitations- Using classical machine learning for threat hunting (and saving tokens in the process)- Your newest insider has legitimate access

All INdiana Politics
Sen. Jim Banks demands answers on AI security breach

All INdiana Politics

Play Episode Listen Later Aug 24, 2026 20:49


On this episode of All INdiana Politics, Sen. Jim Banks explains why he wants the federal government to get involved after an AI company accidentally hacked a cybersecurity company while testing a new AI model. He also discusses the latest in the war with Iran. Plus, Indiana's best political team weighs the chances the Chicago Bears move to Hammond after the clearest statement yet from the team.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

LINUX Unplugged
681: Ain't Nothing But a Syncthing

LINUX Unplugged

Play Episode Listen Later Aug 23, 2026 95:19 Transcription Available


Syncthing saves the day in an unexpected way, and we dig into what's new in Linux 7.2.Sponsored By:Jupiter Party Annual Membership: Put your support on automatic with our annual plan, and get one month of membership for free!Managed Nebula: Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.Support LINUX UnpluggedLinks:Web Boost — Send us a boost via sats or USD

Security Now (MP3)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (MP3)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

All TWiT.tv Shows (MP3)
Security Now 1092: Restraint Abliteration

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Security Now (Video HD)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (Video HD)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Security Now (Video HI)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (Video HI)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Radio Leo (Audio)
Security Now 1092: Restraint Abliteration

Radio Leo (Audio)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Security Now (Video LO)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (Video LO)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Hacker Valley Studio
Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Hacker Valley Studio

Play Episode Listen Later Aug 19, 2026 34:52


Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing. Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates. Impactful Moments 00:00 - Introduction 02:05 - The rewind: how SOAR promised to save the SOC in 2015 03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer 05:30 - What cybersecurity looked like before AI at enterprise scale 07:00 - The "humans first" strategy behind Adobe's AI investigator 09:30 - Why careless context management is the biggest pitfall in agent design 14:45 - Solving the speed problem: is it tooling, process, or people? 17:10 - From monolith to microservices: rebuilding the platform for scale 24:05 - What actually makes an AI agent's "persona" work 26:00 - John's prediction for the SOC three years from now 28:50 - The three skills every security practitioner needs for 2026 32:10 - Final verdict: is AI SOC really different, or SOAR with new branding? Links Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/ If you're a researcher ready to make an impact, check out the announcement about Adobe's new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Check out Adobe's Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail Learn more about Adobe: https://www.adobe.com/ –  Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Cloud Security Podcast
Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

Cloud Security Podcast

Play Episode Listen Later Aug 18, 2026 32:27


When Claude Cowork hits a roadblock, it doesn't give up, it writes a custom Python script and downloads an untrusted NPM package just to bypass its restrictions and finish its goal. Are your security tools close enough to stop it? In this episode, Ashish sits down with Michael Leland, VP, Field CTO at Island, to discuss the critical need for an Agentic Control Plane. Michael breaks down why traditional security silos (EDR, DLP, CASB) fail to provide visibility when autonomous AI agents execute tasks outside the network, and why the browser is the ultimate line of defense for monitoring user intent. We explore the massive reality of Shadow AI and the hidden danger of well-intentioned employees accidentally hooking up sensitive data to public LLMs. Finally, Michael shares practical strategies for solving token waste through "model fit steering" and managing the complex "two-hop problem" when an agent calls another agent.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠Michael's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction to the Agentic Control Plane(01:50) Michael Leland's Background (Cabletron, Nitro Security, SentinelOne)(03:20) Why Island Evolved from the Browser to the Desktop for AI(05:50) The Failure of Traditional Siloed Security (EDR, DLP, CASB)(07:20) Goal-Oriented AI: How Claude Cowork Downloads Untrusted NPM Packages(08:30) Model Fit Steering: Routing Users to the Right LLM for the Right Price(10:30) The Threat of Malicious AI Skills and Plugins(11:30) The Well-Intentioned Insider Threat (The Next Cambridge Analytica)(13:00) Uncovering Shadow AI: From 8 Tools to 243(15:10) Token Brokering at the MCP Gateway(16:40) Protecting Non-Human Identities (NHI)(18:20) Solving the "Two-Hop" Problem (Agent-to-Agent Communication)(21:00) Fixing Hallucinations with Corporate RAGs(25:40) Calculating AI ROI Beyond "Token Maxing"(28:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge

LINUX Unplugged
680: Go Hack Yourself

LINUX Unplugged

Play Episode Listen Later Aug 17, 2026 79:44 Transcription Available


We turn HexStrike's red team agents loose on our systems, as OpenSSH warns that AI-assisted bug hunting is already changing the security race.

The Real Estate Agent Playbook
The AI Security Guardrails Every Real Estate Agent Needs

The Real Estate Agent Playbook

Play Episode Listen Later Aug 17, 2026 13:27 Transcription Available


For ambitious real estate agents looking to scale, using AI is mandatory—but using free, public AI tools is a massive legal liability. In this video, I break down the strict new AI data privacy rules mandated across major brokerages and show you how to set up secure guardrails so you can automate your business without risking your license.

ITSPmagazine | Technology. Cybersecurity. Society
Coding Is a Fraction of the Work. Harness Secures Everything After It. | A Brand Briefing at Black Hat USA 2026 with Rahul Sood, General Manager, Application Security at Harness | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 15, 2026 16:02


Rahul Sood has run the application security business at Harness for almost a year. He describes application security as one of the core pillars of the company, part of a vision of building a DevSecOps platform. A year ago Harness publicly announced that security accounted for a quarter of its revenue. Sood says the figure is now considerably higher. The company did not start there. Founder Jyoti Bansal thought about Harness for a decade before founding it, Sood says, after seeing the problem inside one of the largest banks. Harness launched as a DevOps platform, then merged with an API security company Bansal had also funded. The result is a platform that treats security as part of the developer workflow rather than a bolt-on, and covers it from code all the way to runtime. What changes when security lives inside the developer workflow? Developers stop leaving their own tools to chase findings. Harness aggregates results across scanners, deduplicates them, and puts remediation, assignment, and exemption requests in one place. Security teams get the other half of the picture through a policy engine that shows which policies fire on every build, which ones break a build, and where a developer asked for an exception, with a full audit trail behind it. Where is the bottleneck now that AI writes the code? It moved downstream. Sood says nearly every development team is generating more code with AI, while the volume actually reaching users has not risen at the same rate. By his estimate coding is 20 to 30 percent of the software development life cycle, and the remaining 70 to 80 percent happens after the code is written. That includes agents. Harness has extended the platform to support the Agent DLC, with native capabilities for AI evaluation and prompt testing alongside security coverage for agents from code to runtime. Sood points to two differences. The span from code to runtime covers agents while they are built and while they run, and skill scanning and prompt scanning were added to the same scanner already looking for code vulnerabilities rather than shipped as another tool to buy. The operational payoff shows up in release cadence. Sood describes a tier one US bank that maintained 150 separate policies and convened a team to confirm each one had been met before it could launch its banking app. Automating that review removed the meeting, and the bank now runs multiple launches within weeks. With 80 to 90 percent of software now assembled from third-party packages, libraries, and open source components, the same policy engine can block any build that pulls in a package which is end of life or malicious. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Rahul Sood, General Manager, Application Security at Harness On LinkedIn: https://www.linkedin.com/in/rssoods/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Harness: https://www.harness.io/ Harness customer case studies: https://www.harness.io/customers Securing the Agent DLC, by Rahul Sood: https://www.harness.io/blog/securing-the-agent-dlc Harness AI Security: https://www.harness.io/products/ai-security Harness Application Security Testing: https://www.harness.io/products/application-security-testing Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS rahul sood, harness, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, application security, devsecops, agent dlc, ai security, api security, policy engine, software supply chain, open source risk, prompt scanning, skill scanning, code to runtime, developer experience, release velocity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The CyberWire
Apple has a message for you.

The CyberWire

Play Episode Listen Later Aug 14, 2026 22:59


Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. If you want to learn more on this topic, check out the article here. You can also check out Tom on the AI Security Brief here. Selected Reading If Apple sends you a push notification alerting you to a spyware attack, take it seriously (TechCrunch) Trivy, Not LiteLLM Behind the 2,500 Org Compromise (SecurityWeek) France investigates tax authority breach after hacker claims 600,000 victims (The Record) Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side (Symantec) AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers (Jamf) Ukraine shuts down 94 fraudulent call centers, seize millions in cash (BleepingComputer) This 'adversarial' pattern can prevent surveillance cameras from detecting you (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Swan Signal - A Bitcoin Podcast
The Exponential Debt Society

Swan Signal - A Bitcoin Podcast

Play Episode Listen Later Aug 14, 2026 44:37


Brady breaks down the Bitcoin community's open letter to Anthropic: red team researchers report over a thousand serious vulnerabilities found across Bitcoin's open source ecosystem, and by their account not one was surfaced by an American frontier model Rob Hamilton's line lands hardest: getting locked out of a US cyber program mid-investigation "guts him as a patriotic American," but he uses the models that work, and so do the attackers Isaiah reaches for the crossbow: medieval bans on easy-to-use weapons never held, and hobbling defenders while attackers ignore the rules is the same losing proposition A viral Sam Altman clip about AI watching your screen and hearing your calls prompts the show's sharpest frame: take the Bitcoin ethos to intelligence itself, and control your own model like you control your own money The debt reality check: Trump told Bob Woodward in 2016 the $19 trillion debt could be erased in eight years through trade; a decade later the US approaches $40 trillion and interest payments have passed defense spending Groceries tell the story the CPI smooths over: food prices up roughly a third since 2019 by the AP's chart, quality quietly falling, and full-time employment down millions from its early-2025 peak Japan shrank its debt-to-GDP from 229 to 204 without repaying a dime through financial repression, a roundabout tax nobody voted on, and the gap savers should have earned is exactly what the government kept The catch: Japan owes itself, with the Bank of Japan holding 48% of its own debt, while foreigners hold 31% of America's, so when Washington tried the same trick, foreign holders sold and yields broke five percent Bear market check-in: Brady's third, Isaiah's second, and the shared lesson that conviction is earned in the first winter, while the 200-week moving average and cost-of-production zone mark where Bitcoin sits now The week's rare good news: FinCEN permanently ends beneficial ownership reporting for US companies and deletes the collected data, days after Liechtenstein's equivalent register leaked 31,000 entities ► For high-net-worth individuals and corporations seeking to build generational wealth with Bitcoin, Swan Private is your guide ✔ https://www.swanbitcoin.com/private?utm_campaign=private&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Secure your bright orange future with the Swan IRA today! Real Bitcoin, no taxes ✔ https://www.swanbitcoin.com/ira?utm_campaign=ira&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Secure your Bitcoin with Swan Vault ✔ https://www.swanbitcoin.com/vault?utm_campaign=vault&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Download the all-new Swan Bitcoin App ✔ https://www.swanbitcoin.com/app?utm_campaign=app&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Want to learn more about Bitcoin? Check out Welcome To Bitcoin a FREE Introductory course. Learn about Bitcoin in under 1 hour! ✔ https://www.swanbitcoin.com/welcome?utm_campaign=welcome_to_bitcoin&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Connect with Swan Bitcoin: ✔ Twitter: https://twitter.com/Swan ✔ Instagram: https://instagram.com/SwanBitcoin ✔ LinkedIn: https://linkedin.com/company/swanbitcoin ✔ Threads: https://www.threads.com/@swanbitcoin ✔ Facebook: https://www.facebook.com/SwanBitcoin/ ✔ TikTok: https://www.tiktok.com/@realswanbitcoin

ITSPmagazine | Technology. Cybersecurity. Society
Agents Get Zero Trust, and the Network Becomes the Sensor | A Brand Briefing at Black Hat USA 2026 with David Hughes, SVP and GM of SASE and Security for Networking at HPE | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 15:48


Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security. Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team. What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach. How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal. Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later. Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST David Hughes, SVP and GM of SASE and Security for Networking at HPE On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com/ HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Defense in Depth
What Makes a Good AI Security Deployment?

Defense in Depth

Play Episode Listen Later Aug 13, 2026 31:19


What Makes a Good AI Security Deployment? All links and images can be found on CISO Series Check out this post by Chris Matthews of UpGuard for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Peter Liebert, CISO, Salesloft & Clari. In this episode: Non-determinism changes everything The foundation problem Nobody owns the whole problem The authorization gap A huge thanks to our sponsor, CoreView Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide  

microsoft deployment ciso chris matthews ai security frost bank david spark upguard ciso series
Security Now (MP3)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (MP3)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

All TWiT.tv Shows (MP3)
Security Now 1091: The Post BlackHat State of AI

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video HD)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video HD)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video HI)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video HI)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Radio Leo (Audio)
Security Now 1091: The Post BlackHat State of AI

Radio Leo (Audio)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video LO)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video LO)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

All TWiT.tv Shows (Video LO)
Security Now 1091: The Post BlackHat State of AI

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Aug 12, 2026 171:12 Transcription Available


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Radio Leo (Video HD)
Security Now 1091: The Post BlackHat State of AI

Radio Leo (Video HD)

Play Episode Listen Later Aug 12, 2026 171:12 Transcription Available


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

The CEO Sessions
The AI Security Threat Leaders Aren't Ready For | Dennis Kozak, CEO of Ivanti

The CEO Sessions

Play Episode Listen Later Aug 11, 2026 39:42 Transcription Available


AI isn't just transforming business—it's transforming cyberattacks.In this episode of Lead the Team, Ben Fanning sits down with Dennis Kozak, CEO of Ivanti, to discuss why artificial intelligence is changing cybersecurity faster than most organizations can adapt. After leading companies through cloud computing, mobile, remote work, cybersecurity, and now AI, Dennis explains the leadership principles that remain constant even as technology rapidly evolves.He shares the story of a company that unknowingly allowed attackers to remain inside its systems for more than a year—even though the security patch already existed. The lesson isn't just about technology. It's about leadership, prioritization, and preparing organizations for a future where AI accelerates both innovation and risk.You'll also learn:• Why AI is changing cybersecurity forever• How executives should think about AI adoption and risk• The leadership mistake that leaves organizations vulnerable• Why companies fail to deploy critical security patches• How to balance long-term strategy with constant operational fires• What separates future executives from everyone else• Why curiosity and adaptability matter more than expertise in the AI eraIf you're a CEO, executive, technology leader, or anyone responsible for navigating AI transformation, this conversation offers practical leadership lessons for one of the fastest-changing business environments in history.-----Connect with the Host, #1 bestselling author Ben FanningSpeaking and Training inquiresSubscribe to my Youtube channelLinkedInInstagramTwitter

Security Now (MP3)
SN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

Security Now (MP3)

Play Episode Listen Later Aug 6, 2026 125:11


At Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge and genuine progress? • Black Hat and DEF CON: Hacking Stories and Conference Culture • Zoox Ride-Hailing Hack and Over-the-Air Vulnerabilities • Autonomous Vehicles, AI, and the Security Implications • Hosts Share Personal Adoption and Use of AI Tools • AI-Powered Coding: From Hobbyists to Advanced Agency Chains • Local Models vs. Cloud AI: Privacy, Cost, and Control • App Development Democratized: Listeners Build Custom Solutions With AI • Code Generation, Testing, and Managing AI-Driven Project Cycles • AI's Role in Security: Vulnerability Discovery, Exploitation, and Patch Challenges • Technical Debt and the Race to Patch Decades-Old Bugs • The Dual-Use Dilemma: AI Tools for Both Attack and Defense • Guardrails, Model Partitioning, and the Fight Over Forbidden Knowledge • Open vs. Restricted AI: Global Models, Distillation, and Free Speech • LLM Security Weaknesses: Prompt Injection and Role Confusion Exposed • The Reliability Problem: Probabilistic AI and Non-Deterministic Software • AI Progress: Public Perception, Skepticism, and "Hogwash" Rebuttals • Reflections on AI's Fast Evolution and the Sci-Fi Reality Gap • Closing Thoughts: Tech Community, Listener Feedback, and the Future of Security Now Hosts: Steve Gibson, Leo Laporte, Richard Campbell, and Paul Thurrott Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security bitwarden.com/twit XBOW.com hoxhunt.com/securitynow threatlocker.com/twit

Security Now (Video HD)
SN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

Security Now (Video HD)

Play Episode Listen Later Aug 6, 2026 125:11 Transcription Available


At Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge and genuine progress? • Black Hat and DEF CON: Hacking Stories and Conference Culture • Zoox Ride-Hailing Hack and Over-the-Air Vulnerabilities • Autonomous Vehicles, AI, and the Security Implications • Hosts Share Personal Adoption and Use of AI Tools • AI-Powered Coding: From Hobbyists to Advanced Agency Chains • Local Models vs. Cloud AI: Privacy, Cost, and Control • App Development Democratized: Listeners Build Custom Solutions With AI • Code Generation, Testing, and Managing AI-Driven Project Cycles • AI's Role in Security: Vulnerability Discovery, Exploitation, and Patch Challenges • Technical Debt and the Race to Patch Decades-Old Bugs • The Dual-Use Dilemma: AI Tools for Both Attack and Defense • Guardrails, Model Partitioning, and the Fight Over Forbidden Knowledge • Open vs. Restricted AI: Global Models, Distillation, and Free Speech • LLM Security Weaknesses: Prompt Injection and Role Confusion Exposed • The Reliability Problem: Probabilistic AI and Non-Deterministic Software • AI Progress: Public Perception, Skepticism, and "Hogwash" Rebuttals • Reflections on AI's Fast Evolution and the Sci-Fi Reality Gap • Closing Thoughts: Tech Community, Listener Feedback, and the Future of Security Now Hosts: Steve Gibson, Leo Laporte, Richard Campbell, and Paul Thurrott Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security bitwarden.com/twit XBOW.com hoxhunt.com/securitynow threatlocker.com/twit

Security Now (Video HI)
SN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

Security Now (Video HI)

Play Episode Listen Later Aug 6, 2026 125:11 Transcription Available


At Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge and genuine progress? • Black Hat and DEF CON: Hacking Stories and Conference Culture • Zoox Ride-Hailing Hack and Over-the-Air Vulnerabilities • Autonomous Vehicles, AI, and the Security Implications • Hosts Share Personal Adoption and Use of AI Tools • AI-Powered Coding: From Hobbyists to Advanced Agency Chains • Local Models vs. Cloud AI: Privacy, Cost, and Control • App Development Democratized: Listeners Build Custom Solutions With AI • Code Generation, Testing, and Managing AI-Driven Project Cycles • AI's Role in Security: Vulnerability Discovery, Exploitation, and Patch Challenges • Technical Debt and the Race to Patch Decades-Old Bugs • The Dual-Use Dilemma: AI Tools for Both Attack and Defense • Guardrails, Model Partitioning, and the Fight Over Forbidden Knowledge • Open vs. Restricted AI: Global Models, Distillation, and Free Speech • LLM Security Weaknesses: Prompt Injection and Role Confusion Exposed • The Reliability Problem: Probabilistic AI and Non-Deterministic Software • AI Progress: Public Perception, Skepticism, and "Hogwash" Rebuttals • Reflections on AI's Fast Evolution and the Sci-Fi Reality Gap • Closing Thoughts: Tech Community, Listener Feedback, and the Future of Security Now Hosts: Steve Gibson, Leo Laporte, Richard Campbell, and Paul Thurrott Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security bitwarden.com/twit XBOW.com hoxhunt.com/securitynow threatlocker.com/twit

Security Now (Video LO)
SN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

Security Now (Video LO)

Play Episode Listen Later Aug 6, 2026 125:11 Transcription Available


At Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge and genuine progress? • Black Hat and DEF CON: Hacking Stories and Conference Culture • Zoox Ride-Hailing Hack and Over-the-Air Vulnerabilities • Autonomous Vehicles, AI, and the Security Implications • Hosts Share Personal Adoption and Use of AI Tools • AI-Powered Coding: From Hobbyists to Advanced Agency Chains • Local Models vs. Cloud AI: Privacy, Cost, and Control • App Development Democratized: Listeners Build Custom Solutions With AI • Code Generation, Testing, and Managing AI-Driven Project Cycles • AI's Role in Security: Vulnerability Discovery, Exploitation, and Patch Challenges • Technical Debt and the Race to Patch Decades-Old Bugs • The Dual-Use Dilemma: AI Tools for Both Attack and Defense • Guardrails, Model Partitioning, and the Fight Over Forbidden Knowledge • Open vs. Restricted AI: Global Models, Distillation, and Free Speech • LLM Security Weaknesses: Prompt Injection and Role Confusion Exposed • The Reliability Problem: Probabilistic AI and Non-Deterministic Software • AI Progress: Public Perception, Skepticism, and "Hogwash" Rebuttals • Reflections on AI's Fast Evolution and the Sci-Fi Reality Gap • Closing Thoughts: Tech Community, Listener Feedback, and the Future of Security Now Hosts: Steve Gibson, Leo Laporte, Richard Campbell, and Paul Thurrott Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security bitwarden.com/twit XBOW.com hoxhunt.com/securitynow threatlocker.com/twit

HPE Tech Talk
Can AI find every vulnerability? The new cybersecurity arms race | Jon Green

HPE Tech Talk

Play Episode Listen Later Aug 6, 2026 21:19


What do you do when you create an AI that can find security vulnerabilities in almost everything? As AI exposes vulnerabilities hidden deep within critical systems, organisations face a new challenge: staying ahead of threats that can now be discovered at machine speed.This week, Technology Now explores the changing cyber security landscape as AI transforms how vulnerabilities are found, fixed, and exploited, forcing organisations to rethink how they manage risk. Jon Green, CTO HPE Networking, joins us to help explain:  How AI can be used to pen test new software before releaseHow AI could fundamentally change the way organisations patch and upgrade technology Why critical infrastructure is particularly vulnerable to these types of attacksWhether we could be heading towards a future where software is completely vulnerability free

Cloud Security Podcast
How Adobe Uses AI Agents for building a WAF Pipeline?

Cloud Security Podcast

Play Episode Listen Later Aug 4, 2026 47:06


When vulnerability disclosures shrink the wild exploit window down to less than 24 hours (or even minutes), traditional manual patching and WAF rule creation simply cannot keep up.In this episode, Ashish sits down with Ammar Alim (Product Security Engineering Lead at Adobe) to break down how to build an automated, agentic WAF pipeline. Ammar shares how his team manages the scale and complexity of seven commercial and open-source WAFs (including AWS WAF, Cloudflare, Akamai, Azure WAF, Wallarm, and ModSecurity) by leveraging AI agents.Discover how to construct an agentic harness, orchestrate deep research agents to gather exploit POCs, and utilize multi-model architectures (e.g., Anthropic for rule generation and OpenAI as an LLM judge) to eliminate false positives and safely deploy virtual patchesGuest Socials -⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠Ammar's LinkedinPodcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction & The Currency of Speed in Security(02:00) Ammar Alim's Background: From Data Centers to Product Security at Adobe(05:00) The Multi-Vendor WAF Nightmare: Managing Scale Across 7 Products(08:30) Understanding False Positives vs. False Negatives in WAF Management(12:30) Why

This Week in Tech (Audio)
TWiT 1095: Horses and Sailboats - Folding Phones Get Cute and Expensive in a Race With Apple

This Week in Tech (Audio)

Play Episode Listen Later Aug 3, 2026 176:01 Transcription Available


From foldable phones that out-price laptops to AI models that escape their digital cages, this episode dives into the wild next phase of tech innovation and its unexpected risks. See how the giants are scrambling to keep up as hardware, software, and even outer space are up for grabs. Tim Cook passes the baton in Apple's Q3 2026 earnings call Apple's Profit Is Up 27%, but Expectations for Current Quarter Disappoint Apple Introduces Leasing Program for iPhones and Other Devices Apple struggles to keep pace with AI 'bug' hunters "Google and Reddit do not own the Internet," web scraper says after court win As Reddit stock falls, CEO questions value of Google's AI Overviews Microsoft's $450 Billion Jump Is Biggest in Stock Market History Amazon's trying to launch a global satellite cellphone network in 2028 Iran struck Amazon data centers again amid widening war, satellites show For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Claude published malicious code to the Internet and attacked 3 real companies OpenAI and Anthropic Are Quietly Teaming Up in Washington AI leaders sign a statement asking the government to do something about automated AI Ten advances in mathematics and theoretical computer science How bitcoin cold wallets lost $70 million in an attack that never touched the devices NBCUniversal and YouTube ink deal to embed Peacock in the video platform for premium subscribers Inside the Luxury Robotaxi Uber, Lucid and Nuro Are Testing Host: Leo Laporte Guests: Abrar Al-Heeti and Mike Elgan Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com helixsleep.com/twit expressvpn.com/twit canary.tools/twit - use code: TWIT cachefly.com/twit

This Week in Tech (Video HI)
TWiT 1095: Horses and Sailboats - Folding Phones Get Cute and Expensive in a Race With Apple

This Week in Tech (Video HI)

Play Episode Listen Later Aug 3, 2026 178:43


From foldable phones that out-price laptops to AI models that escape their digital cages, this episode dives into the wild next phase of tech innovation and its unexpected risks. See how the giants are scrambling to keep up as hardware, software, and even outer space are up for grabs. Tim Cook passes the baton in Apple's Q3 2026 earnings call Apple's Profit Is Up 27%, but Expectations for Current Quarter Disappoint Apple Introduces Leasing Program for iPhones and Other Devices Apple struggles to keep pace with AI 'bug' hunters "Google and Reddit do not own the Internet," web scraper says after court win As Reddit stock falls, CEO questions value of Google's AI Overviews Microsoft's $450 Billion Jump Is Biggest in Stock Market History Amazon's trying to launch a global satellite cellphone network in 2028 Iran struck Amazon data centers again amid widening war, satellites show For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Claude published malicious code to the Internet and attacked 3 real companies OpenAI and Anthropic Are Quietly Teaming Up in Washington AI leaders sign a statement asking the government to do something about automated AI Ten advances in mathematics and theoretical computer science How bitcoin cold wallets lost $70 million in an attack that never touched the devices NBCUniversal and YouTube ink deal to embed Peacock in the video platform for premium subscribers Inside the Luxury Robotaxi Uber, Lucid and Nuro Are Testing Host: Leo Laporte Guests: Abrar Al-Heeti and Mike Elgan Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com helixsleep.com/twit expressvpn.com/twit canary.tools/twit - use code: TWIT cachefly.com/twit

All TWiT.tv Shows (MP3)
This Week in Tech 1095: Horses and Sailboats

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 3, 2026 176:01 Transcription Available


From foldable phones that out-price laptops to AI models that escape their digital cages, this episode dives into the wild next phase of tech innovation and its unexpected risks. See how the giants are scrambling to keep up as hardware, software, and even outer space are up for grabs. Tim Cook passes the baton in Apple's Q3 2026 earnings call Apple's Profit Is Up 27%, but Expectations for Current Quarter Disappoint Apple Introduces Leasing Program for iPhones and Other Devices Apple struggles to keep pace with AI 'bug' hunters "Google and Reddit do not own the Internet," web scraper says after court win As Reddit stock falls, CEO questions value of Google's AI Overviews Microsoft's $450 Billion Jump Is Biggest in Stock Market History Amazon's trying to launch a global satellite cellphone network in 2028 Iran struck Amazon data centers again amid widening war, satellites show For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Claude published malicious code to the Internet and attacked 3 real companies OpenAI and Anthropic Are Quietly Teaming Up in Washington AI leaders sign a statement asking the government to do something about automated AI Ten advances in mathematics and theoretical computer science How bitcoin cold wallets lost $70 million in an attack that never touched the devices NBCUniversal and YouTube ink deal to embed Peacock in the video platform for premium subscribers Inside the Luxury Robotaxi Uber, Lucid and Nuro Are Testing Host: Leo Laporte Guests: Abrar Al-Heeti and Mike Elgan Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com helixsleep.com/twit expressvpn.com/twit canary.tools/twit - use code: TWIT cachefly.com/twit

All TWiT.tv Shows (MP3)
This Week in Tech 1095: Horses and Sailboats

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 3, 2026 178:43 Transcription Available


From foldable phones that out-price laptops to AI models that escape their digital cages, this episode dives into the wild next phase of tech innovation and its unexpected risks. See how the giants are scrambling to keep up as hardware, software, and even outer space are up for grabs. Tim Cook passes the baton in Apple's Q3 2026 earnings call Apple's Profit Is Up 27%, but Expectations for Current Quarter Disappoint Apple Introduces Leasing Program for iPhones and Other Devices Apple struggles to keep pace with AI 'bug' hunters "Google and Reddit do not own the Internet," web scraper says after court win As Reddit stock falls, CEO questions value of Google's AI Overviews Microsoft's $450 Billion Jump Is Biggest in Stock Market History Amazon's trying to launch a global satellite cellphone network in 2028 Iran struck Amazon data centers again amid widening war, satellites show For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Claude published malicious code to the Internet and attacked 3 real companies OpenAI and Anthropic Are Quietly Teaming Up in Washington AI leaders sign a statement asking the government to do something about automated AI Ten advances in mathematics and theoretical computer science How bitcoin cold wallets lost $70 million in an attack that never touched the devices NBCUniversal and YouTube ink deal to embed Peacock in the video platform for premium subscribers Inside the Luxury Robotaxi Uber, Lucid and Nuro Are Testing Host: Leo Laporte Guests: Abrar Al-Heeti and Mike Elgan Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com helixsleep.com/twit expressvpn.com/twit canary.tools/twit - use code: TWIT cachefly.com/twit

Radio Leo (Audio)
This Week in Tech 1095: Horses and Sailboats

Radio Leo (Audio)

Play Episode Listen Later Aug 3, 2026 176:01 Transcription Available


From foldable phones that out-price laptops to AI models that escape their digital cages, this episode dives into the wild next phase of tech innovation and its unexpected risks. See how the giants are scrambling to keep up as hardware, software, and even outer space are up for grabs. Tim Cook passes the baton in Apple's Q3 2026 earnings call Apple's Profit Is Up 27%, but Expectations for Current Quarter Disappoint Apple Introduces Leasing Program for iPhones and Other Devices Apple struggles to keep pace with AI 'bug' hunters "Google and Reddit do not own the Internet," web scraper says after court win As Reddit stock falls, CEO questions value of Google's AI Overviews Microsoft's $450 Billion Jump Is Biggest in Stock Market History Amazon's trying to launch a global satellite cellphone network in 2028 Iran struck Amazon data centers again amid widening war, satellites show For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Claude published malicious code to the Internet and attacked 3 real companies OpenAI and Anthropic Are Quietly Teaming Up in Washington AI leaders sign a statement asking the government to do something about automated AI Ten advances in mathematics and theoretical computer science How bitcoin cold wallets lost $70 million in an attack that never touched the devices NBCUniversal and YouTube ink deal to embed Peacock in the video platform for premium subscribers Inside the Luxury Robotaxi Uber, Lucid and Nuro Are Testing Host: Leo Laporte Guests: Abrar Al-Heeti and Mike Elgan Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com helixsleep.com/twit expressvpn.com/twit canary.tools/twit - use code: TWIT cachefly.com/twit

Radio Leo (Audio)
This Week in Tech 1095: Horses and Sailboats

Radio Leo (Audio)

Play Episode Listen Later Aug 3, 2026 178:43 Transcription Available


From foldable phones that out-price laptops to AI models that escape their digital cages, this episode dives into the wild next phase of tech innovation and its unexpected risks. See how the giants are scrambling to keep up as hardware, software, and even outer space are up for grabs. Tim Cook passes the baton in Apple's Q3 2026 earnings call Apple's Profit Is Up 27%, but Expectations for Current Quarter Disappoint Apple Introduces Leasing Program for iPhones and Other Devices Apple struggles to keep pace with AI 'bug' hunters "Google and Reddit do not own the Internet," web scraper says after court win As Reddit stock falls, CEO questions value of Google's AI Overviews Microsoft's $450 Billion Jump Is Biggest in Stock Market History Amazon's trying to launch a global satellite cellphone network in 2028 Iran struck Amazon data centers again amid widening war, satellites show For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Claude published malicious code to the Internet and attacked 3 real companies OpenAI and Anthropic Are Quietly Teaming Up in Washington AI leaders sign a statement asking the government to do something about automated AI Ten advances in mathematics and theoretical computer science How bitcoin cold wallets lost $70 million in an attack that never touched the devices NBCUniversal and YouTube ink deal to embed Peacock in the video platform for premium subscribers Inside the Luxury Robotaxi Uber, Lucid and Nuro Are Testing Host: Leo Laporte Guests: Abrar Al-Heeti and Mike Elgan Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com helixsleep.com/twit expressvpn.com/twit canary.tools/twit - use code: TWIT cachefly.com/twit

ITSPmagazine | Technology. Cybersecurity. Society
Agentic Security Changes Everything | An On Location Conversation at Infosecurity Europe 2026 with John Sotiropoulos and Rock Lambros

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 31, 2026 6:54


Sean Martin catches John Sotiropoulos and Rock Lambros at the end of the OWASP GenAI Security Summit, held alongside Infosecurity Europe 2026 at ExCeL London. Both are deep in the standards work: John Sotiropoulos co-leads the OWASP Agentic Security Initiative and sits on the board of the OWASP GenAI Security Project, and Rock Lambros serves as Director of AI Standards and Governance at Zenity and co-leads the OWASP Top 10 for LLM 2026 update. The headline from the day is the launch of the Agentic Security Council, bringing Oxford University, Queen's University Belfast, CSIT, and other research institutions into the same room as practitioners and industry. John Sotiropoulos frames the reasoning bluntly: content on its own does not create change. Papers and Top 10 lists matter, but they only matter if the people building and defending systems can act on them. The number that reframes everything is twenty-two seconds. That is the average time from an initial access event to the next attacker action, down from eight hours. John Sotiropoulos puts the question directly to anyone still running a human-speed playbook: how do you respond to that? A panel on incident response with participants from AWS and Microsoft, a keynote from Microsoft's National Security Officer, and a walkthrough of the State of Agentic Security and Governance report all point at the same shift toward runtime security. Rock Lambros brings a different kind of grounding. For the first time in the four-year history of the OWASP Top 10 for LLM, the update draws on a corpus of reported incidents rather than opinion and community vote alone. It is one data point among several, but it is data, and that changes what the list can claim. A panel with the heads of AI security at Deloitte supplies the operational counterweight. As one of them puts it, security has to stop being the Ministry of No, because people will route around it and ship anyway. The report's adoption tiers and maturity levels exist for exactly that reason: security that lives only inside a PDF is not security. The invitation from both John Sotiropoulos and Rock Lambros is the same. Join the work. Research, red teamers, defenders, builders, and SecOps all looking at one view of what is actually happening is the only version of this that scales to machine speed. ⬥HOST⬥ Sean Martin, CISSP | Co-Founder, ITSPmagazine & Studio C60 | Host, Redefining CyberSecurity Podcast & Music Evolves Podcast | https://www.seanmartin.com/ ⬥GUESTS⬥ John Sotiropoulos, Deep Cyber | Co-Lead, OWASP Agentic Security Initiative; Board Director, OWASP GenAI Security Project | On LinkedIn: https://www.linkedin.com/in/jsotiropoulos/ Rock Lambros, Director of AI Standards and Governance, Zenity; Founder, RockCyber | Co-Lead, OWASP Top 10 for LLM 2026 | On LinkedIn: https://www.linkedin.com/in/rocklambros/ ⬥RESOURCES⬥ Infosecurity Europe 2026 is taking place June 2-4, 2026 | ExCeL London. Follow our coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage OWASP GenAI Security Project | https://genai.owasp.org Contribute to the OWASP GenAI Security Project | https://genai.owasp.org/contribute The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/ Redefining CyberSecurity Podcast | https://www.seanmartin.com/redefining-cybersecurity-podcast On Location | https://www.itspmagazine.com/on-location

Tech News Weekly (MP3)
TNW 448: The Math Behind Apple Upgrade - Understanding Apple Upgrade

Tech News Weekly (MP3)

Play Episode Listen Later Jul 30, 2026 57:43


Jacob Ward from The Rip Current joins the show this week! Looking into the fallout from an OpenAI model breaching Hugging Face. Winamp returns with a Deezer-powered streaming relaunch. Breaking down the math behind Apple's new leasing program. And shared Claude chats are turning up in Google search results. Last week, an OpenAI Model autonomously hacked into Hugging Face while performing a cybersecurity task. Jacob breaks down the fallout from the incident and how it is fueling questions about whether AI labs have crossed into "critical risk" territory. Winamp is getting a new lease on life through a partnership with Deezer, bringing a Winamp-branded music subscription alongside local files, internet radio, and podcasts, set to launch in the first half of 2027. D. Griffin Jones joins to explain how Apple Upgrade replaces the iPhone Upgrade Program and expands leasing, via Klarna, across iPhone, Apple Watch, iPad, and Mac. And a report from 404 Media's Joseph Cox looks into publicly published Claude conversations and artifacts being indexed by Google, exposing sensitive material like crypto wallet keys and personal data, and why understanding what "public" really means before sharing matters. Hosts: Mikah Sargent and Jacob Ward Guest: D. Griffin Jones Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: cirasync.com/TNW rippling.ai/tnw

Tech News Weekly (Video HI)
TNW 448: The Math Behind Apple Upgrade - Understanding Apple Upgrade

Tech News Weekly (Video HI)

Play Episode Listen Later Jul 30, 2026 57:43


Jacob Ward from The Rip Current joins the show this week! Looking into the fallout from an OpenAI model breaching Hugging Face. Winamp returns with a Deezer-powered streaming relaunch. Breaking down the math behind Apple's new leasing program. And shared Claude chats are turning up in Google search results. Last week, an OpenAI Model autonomously hacked into Hugging Face while performing a cybersecurity task. Jacob breaks down the fallout from the incident and how it is fueling questions about whether AI labs have crossed into "critical risk" territory. Winamp is getting a new lease on life through a partnership with Deezer, bringing a Winamp-branded music subscription alongside local files, internet radio, and podcasts, set to launch in the first half of 2027. D. Griffin Jones joins to explain how Apple Upgrade replaces the iPhone Upgrade Program and expands leasing, via Klarna, across iPhone, Apple Watch, iPad, and Mac. And a report from 404 Media's Joseph Cox looks into publicly published Claude conversations and artifacts being indexed by Google, exposing sensitive material like crypto wallet keys and personal data, and why understanding what "public" really means before sharing matters. Hosts: Mikah Sargent and Jacob Ward Guest: D. Griffin Jones Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: cirasync.com/TNW rippling.ai/tnw

All TWiT.tv Shows (MP3)
Tech News Weekly 448: The Math Behind Apple Upgrade

All TWiT.tv Shows (MP3)

Play Episode Listen Later Jul 30, 2026 57:43 Transcription Available


Jacob Ward from The Rip Current joins the show this week! Looking into the fallout from an OpenAI model breaching Hugging Face. Winamp returns with a Deezer-powered streaming relaunch. Breaking down the math behind Apple's new leasing program. And shared Claude chats are turning up in Google search results. Last week, an OpenAI Model autonomously hacked into Hugging Face while performing a cybersecurity task. Jacob breaks down the fallout from the incident and how it is fueling questions about whether AI labs have crossed into "critical risk" territory. Winamp is getting a new lease on life through a partnership with Deezer, bringing a Winamp-branded music subscription alongside local files, internet radio, and podcasts, set to launch in the first half of 2027. D. Griffin Jones joins to explain how Apple Upgrade replaces the iPhone Upgrade Program and expands leasing, via Klarna, across iPhone, Apple Watch, iPad, and Mac. And a report from 404 Media's Joseph Cox looks into publicly published Claude conversations and artifacts being indexed by Google, exposing sensitive material like crypto wallet keys and personal data, and why understanding what "public" really means before sharing matters. Hosts: Mikah Sargent and Jacob Ward Guest: D. Griffin Jones Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: cirasync.com/TNW rippling.ai/tnw