Podcasts about ai security

  • 383PODCASTS
  • 808EPISODES
  • 52mAVG DURATION
  • 1DAILY NEW EPISODE
  • Sep 17, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about ai security

Latest podcast episodes about ai security

This Week in Google (MP3)
IM 888: Large Linguine Model - Inside the AI Doom Debate

This Week in Google (MP3)

Play Episode Listen Later Sep 17, 2026 161:37


Discover how to run serious AI at home without breaking the bank, as Lon Seidman reveals his tricks for turning old data center GPUs into powerful local LLM machines. Anthropic Researchers Raise Alarm Over A.I. Acceleration, Warning of Threat to Humanity Dario Amodei — We Must Pace the Frontier Mark Zuckerberg Takes Aim at Anthropic in Debate Over A.I. Slowdown A Code of Conduct for Humanist AI Countering misuse of AI: September 2026 / Anthropic EXCLUSIVE: OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack Yoshua Bengio | Why are AI agents lying, cheating and coordinating? The Worst Spam Emails: Inside iLands' AI Agent Hustle Introducing System One Models & Jev - TypeSafe AI Blog Universal Music is launching an AI music platform with ElevenLabs Lawyer fined $5K over AI-hallucinated witnesses in a murder case A Digital Fly Brain Has Taken Over the Internet (4) nimensky e/acc on X: "ok who tf did this?! lul https://t.co/HpnXo0qKJ4" / X Fanttik Cafein 11 Portable Espresso Machine Casey Newton and Kevin Roose partner with NPR to launch 'Machine Gods' They Built a Shrine to Cable TV. Then Everyone Cut the Cord. Hosts: Leo Laporte, Jeff Jarvis, and Fr. Robert Ballecer, SJ Guest: Lon Seidman Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: trustedtech.team/intelligent365 claude.ai/technology framer.com/machines bitwarden.com/twit

All TWiT.tv Shows (MP3)
Intelligent Machines 888: Large Linguine Model

All TWiT.tv Shows (MP3)

Play Episode Listen Later Sep 17, 2026 161:37 Transcription Available


Discover how to run serious AI at home without breaking the bank, as Lon Seidman reveals his tricks for turning old data center GPUs into powerful local LLM machines. Anthropic Researchers Raise Alarm Over A.I. Acceleration, Warning of Threat to Humanity Dario Amodei — We Must Pace the Frontier Mark Zuckerberg Takes Aim at Anthropic in Debate Over A.I. Slowdown A Code of Conduct for Humanist AI Countering misuse of AI: September 2026 / Anthropic EXCLUSIVE: OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack Yoshua Bengio | Why are AI agents lying, cheating and coordinating? The Worst Spam Emails: Inside iLands' AI Agent Hustle Introducing System One Models & Jev - TypeSafe AI Blog Universal Music is launching an AI music platform with ElevenLabs Lawyer fined $5K over AI-hallucinated witnesses in a murder case A Digital Fly Brain Has Taken Over the Internet (4) nimensky e/acc on X: "ok who tf did this?! lul https://t.co/HpnXo0qKJ4" / X Fanttik Cafein 11 Portable Espresso Machine Casey Newton and Kevin Roose partner with NPR to launch 'Machine Gods' They Built a Shrine to Cable TV. Then Everyone Cut the Cord. Hosts: Leo Laporte, Jeff Jarvis, and Fr. Robert Ballecer, SJ Guest: Lon Seidman Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: trustedtech.team/intelligent365 claude.ai/technology framer.com/machines bitwarden.com/twit

Radio Leo (Audio)
Intelligent Machines 888: Large Linguine Model

Radio Leo (Audio)

Play Episode Listen Later Sep 17, 2026 161:37 Transcription Available


Discover how to run serious AI at home without breaking the bank, as Lon Seidman reveals his tricks for turning old data center GPUs into powerful local LLM machines. Anthropic Researchers Raise Alarm Over A.I. Acceleration, Warning of Threat to Humanity Dario Amodei — We Must Pace the Frontier Mark Zuckerberg Takes Aim at Anthropic in Debate Over A.I. Slowdown A Code of Conduct for Humanist AI Countering misuse of AI: September 2026 / Anthropic EXCLUSIVE: OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack Yoshua Bengio | Why are AI agents lying, cheating and coordinating? The Worst Spam Emails: Inside iLands' AI Agent Hustle Introducing System One Models & Jev - TypeSafe AI Blog Universal Music is launching an AI music platform with ElevenLabs Lawyer fined $5K over AI-hallucinated witnesses in a murder case A Digital Fly Brain Has Taken Over the Internet (4) nimensky e/acc on X: "ok who tf did this?! lul https://t.co/HpnXo0qKJ4" / X Fanttik Cafein 11 Portable Espresso Machine Casey Newton and Kevin Roose partner with NPR to launch 'Machine Gods' They Built a Shrine to Cable TV. Then Everyone Cut the Cord. Hosts: Leo Laporte, Jeff Jarvis, and Fr. Robert Ballecer, SJ Guest: Lon Seidman Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: trustedtech.team/intelligent365 claude.ai/technology framer.com/machines bitwarden.com/twit

This Week in Google (Video HI)
IM 888: Large Linguine Model - Inside the AI Doom Debate

This Week in Google (Video HI)

Play Episode Listen Later Sep 17, 2026 161:37


Discover how to run serious AI at home without breaking the bank, as Lon Seidman reveals his tricks for turning old data center GPUs into powerful local LLM machines. Anthropic Researchers Raise Alarm Over A.I. Acceleration, Warning of Threat to Humanity Dario Amodei — We Must Pace the Frontier Mark Zuckerberg Takes Aim at Anthropic in Debate Over A.I. Slowdown A Code of Conduct for Humanist AI Countering misuse of AI: September 2026 / Anthropic EXCLUSIVE: OpenAI's rogue agents probed Hugging Face for weaknesses two months before major hack Yoshua Bengio | Why are AI agents lying, cheating and coordinating? The Worst Spam Emails: Inside iLands' AI Agent Hustle Introducing System One Models & Jev - TypeSafe AI Blog Universal Music is launching an AI music platform with ElevenLabs Lawyer fined $5K over AI-hallucinated witnesses in a murder case A Digital Fly Brain Has Taken Over the Internet (4) nimensky e/acc on X: "ok who tf did this?! lul https://t.co/HpnXo0qKJ4" / X Fanttik Cafein 11 Portable Espresso Machine Casey Newton and Kevin Roose partner with NPR to launch 'Machine Gods' They Built a Shrine to Cable TV. Then Everyone Cut the Cord. Hosts: Leo Laporte, Jeff Jarvis, and Fr. Robert Ballecer, SJ Guest: Lon Seidman Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: trustedtech.team/intelligent365 claude.ai/technology framer.com/machines bitwarden.com/twit

Next in Tech
Resilient Digital Infrastructure

Next in Tech

Play Episode Listen Later Sep 15, 2026 27:04


We should have always been building resilient infrastructure, but we often haven't been. Now that we're ever more dependent on our digital foundations, new focus is being given to ensuring that they're robust enough to ensure that they can truly keep our enterprises humming. Analysts Jean Atelsek, Melanie Posey and host Eric Hanselman have all been at infrastructure conferences and dig into how expectations and options are changing. There are now regulatory requirements for resilience and the increasing complexity of modern infrastructure can make achieving it more challenging. Enterprises have become more hybrid, linking together cloud and on-premises capabilities. The mad dash to AI has pushed the interconnection of multiple providers to gain access to the latest models. Is what we're building now "really darn intractable"? Software vendors like Broadcom are shifting to integrated platforms to better achieve automated operations and colocation providers like Equinix are increasing the ease with which they build interconnection. Enterprises are racing to raise their operational sophistication as they increasingly face existential consequences from infrastructure failures.   More S&P Global Content: Compute sovereignty: The strategic importance of digital infrastructure Next in Tech | Ep. 222: FinOps – Managing Cloud and AI Costs AI in action: unleashing agentic potential Hyperscaler earnings quarterly: What price inference? For S&P Global subscribers: An agentic architectural approach to enterprise energy resiliency FinOps in the age of agentic AI Security-related outages drive resiliency evolution Service providers race to meet surging enterprise demand for AI infrastructure Host/Author: Eric Hanselman Guests: Jean Atelsek and Melanie Posey Producer/Editor: Dylan Scheible 

The Linus Tech Podcast
Dario Amodei on Open Source AI Security Risks

The Linus Tech Podcast

Play Episode Listen Later Sep 14, 2026 16:25


In this episode, we discuss Dario Amodei's insights into the security risks posed by open source AI. His comments highlight the crucial need for oversight. Show LinksGet the top 80+ AI Models for $8.99 at AI Box: ⁠⁠https://aibox.aiMake money licensing data to AI: https://fiund.com/Get the AI Chat Daily Newsletter: https://www.aichatdaily.com/newsletter See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Techzine Talks
"Control your own data": Hoe Klarrio grote organisaties uit de vendor lock-in houdt

Techzine Talks

Play Episode Listen Later Sep 14, 2026 44:55


In deze aflevering van Techzine Talks spreken we met Werner Vermeylen, CISO bij Klarrio. We hebben het over datgene waar Klarrio zich al lang mee bezighoudt, namelijk maatwerk dataplatformen. Uiteraard komen ook zaken zoals datasoevereiniteit en security aan bod, ook in gereguleerde omgevingen. Klarrio bouwt al tien jaar cloud-agnostische en open-source dataplatformen voor grote bedrijven in sectoren als halfgeleiders, telecom en energie. Een van de basisprincipes i bij dit alles is dat de klant zelf de volledige controle heeft en houdt.Vermeylen legt uit waarom grote bedrijven ondanks eigen IT-teams toch vastlopen bij het bouwen van dataplatformen. Klarrio heeft zich gedurende tien jaar onder andere gespecialiseerd in het uitvoeren van migraties zonder downtime (van DC/OS naar Kubernetes). Ook de rol van de CISO, NIS2, CRA en de groeiende druk vanuit regelgeving komen uitgebreid aan bod.Het gesprek gaat ook diep in op de impact van AI op datasecurity: exploittijden dalen hard, malware verstopt zich in open-source packages op GitHub. Tot slot gaan we in op de zoektocht naar soevereine defensieve AI-tooling met lokale LLM-modellen.Belangrijkse inzichten:• Klarrio bouwt geen product, maar volledig maatwerk dataplatformen op basis van open source en cloud-agnostisch design• Datasoevereiniteit gaat verder dan cloudkeuze: ook de architectuur, licenties en componenten bepalen echte controle• Zero-day exploittijden dalen hard, terwijl AI aanvallen sterk versnelt• Open source is niet automatisch soeverein: botnetwerken op GitHub plaatsen malware in populaire packages• Niets is 100% veilig: wie dat wel beweert, liegtHoofdstukken:1:11 - Wat doet Klarrio: custom dataplatformen2:09 - Doelgroep: grote bedrijven in gereguleerde sectoren3:48 - Controle over je eigen data: soevereiniteit als kernfilosofie8:13 - Architectuurkeuzes: van DC/OS naar Kubernetes13:32 - Use case: verkeersplatform voor de Nederlandse overheid16:27 - Projectoplevering en kennisoverdracht18:58 - De CISO-rol bij Klarrio: security by design22:58 - AI en de versnelling van zero-day exploits24:31 - Soevereine defensieve AI en lokale LLM-modellen29:03 - Malware in open source: GitHub-botnetwerken ontdekt32:21 - Kwetsbaarheidsbeheer: risico's analyseren en accepteren43:27 - Beslissingen nemen in onzekerheid

InfosecTrain
Learn AI Security Fundamentals Full Course

InfosecTrain

Play Episode Listen Later Sep 12, 2026 198:37


AI is transforming cybersecurity, but securing AI systems is a unique challenge. In this full course session, InfosecTrain breaks down the core differences between securing with AI and securing AI itself. Discover AI/ML foundations, blue and red team defense tactics, MLOps, API security, and practical threat modeling techniques to future-proof your security career.The "course titled" Practical AI Security Engineering Program provides hands-on expertise to defend AI pipelines.

Cloud Security Podcast
Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats

Cloud Security Podcast

Play Episode Listen Later Sep 11, 2026 70:31


Empowering non-technical users to build production-grade applications requires a proactive, secure-by-design architecture. In this episode, Ashish sits down with Marcus Hallberg and Samuel Kelemen, security engineers at the AI software creation platform Lovable, to discuss how they actively secure AI-generated code and protect creators from supply chain risks.Focusing on solutions rather than alarmism, Marcus and Samuel detail their response to an incident where malicious contractors mimicked AI agent commits. They outline their multi-layered defense strategy: securing a predefined tech stack, utilizing integrated security scanners, and tuning coding agents with strict guardrails to ensure secure output by default. The conversation also covers the evolution of the shared responsibility model in the AI era, the critical importance of foundational hygiene like Git commit signing, and the necessary transition from local "YOLO mode" to secure, sandboxed agent environments. Discover how platforms can leverage AI not just to write code, but to actively assist users in finding and resolving security issues through concepts like "CISO agents."Guest Socials -⁠⁠ ⁠Marcus's Linkedin + Samuel's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast(00:00) Introduction to Securing AI App Builders(02:00) Marcus & Samuel's Backgrounds and Roles at Lovable(04:30) Empowering Non-Technical Users to Build 40 Million Apps(08:30) Securing Predefined Tech Stacks and Tuning Coding Agents(11:00) Managing Trust When Customers Hire External Contractors(14:00) Addressing Supply Chain Risks with Synced GitHub Repositories(17:30) Educating Users and Developing "CISO Agents" for Support(24:00) Analyzing the Attack: How Threat Actors Mimicked Agent Commits(31:00) The Importance of Basic Hygiene: MFA and Commit Signing(38:30) Moving Agents from "YOLO Mode" to Sandboxed Environments(46:00) The Buy vs. Build Debate for Internal AI Capabilities(52:30) AI as an Educational Tool and Democratizing SQL Queries(01:05:00) Hobbies, Plants, and Pushing AI to Design 1940s Bridges

The Audit
Building the Future: AI Coding, Agentic Advisors and Custom Tools

The Audit

Play Episode Listen Later Sep 8, 2026 75:46 Transcription Available


What if your company didn't need a single line of code to build its own CRM, or a board of directors made up entirely of AI agents? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Loren Horsager, founder of Model Mind AI, who has been working in AI since 1993 and now spends his days coaching businesses and CEOs on how to actually put it to work. Loren has helped organizations trade their bloated software stacks, their expensive middleware, and their old habits for AI-driven processes that get built in days instead of quarters. The crew digs into vibe coding, AI councils, and the death of the traditional user interface, then pivots into the harder questions: what happens to developers, where security has to fit into the process, and why voice AI still hasn't earned people's trust. Along the way there's talk of AI trading bots, a QuickBooks security scare, a routing engine that hit 100 percent on-time delivery, and a debate about whether vinyl records and iPods still have a place in an AI-driven world. In this episode: Why vibe coding terrifies developers who ignore it The AI council approach to strategic thinking Why nobody loves their CRM anymore Where security has to sit in AI adoption Why voice AI works for productivity but not yet for trust If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. #AI #VibeCoding #Cybersecurity #ITAudit #AIAgents #Automation #BusinessAI #TechLeadership #DigitalTransformation #TheAuditPodcast 

The Robot Report Podcast
How FPGAs become the gatekeepers of Physical AI Security

The Robot Report Podcast

Play Episode Listen Later Sep 4, 2026 68:43


Our guest this week is Eric Sivertson, VP of Security Business at Lattice. This episode explores why physical AI and humanoids change the security conversation from traditional IT risk to real-world safety risk. Sivertson explains how FPGAs can act as deterministic guardrails for robotic and cyber-physical systems. We discuss why safe is not enough if a robot is also connected, how zero trust and cyber resilience apply on the factory floor, and why hardware needs to verify, monitor, and recover systems in real time. He says traditional factory networks relied on “guns, guards, and gates,” and once OT systems connect to IT and the cloud, the attack surface expands dramatically, and cyber resilience becomes essential. ### Register now for RoboBusiness 2026: https://cvent.me/w0eRN9?RefId=podcast

WSJ What’s News
Why Nvidia's Buying AI Platform Hugging Face for $13 Billion

WSJ What’s News

Play Episode Listen Later Sep 3, 2026 11:11


P.M. Edition for Sept. 3. WSJ reporter Robbie Whelan discusses how with its latest deal for AI platform Hugging Face, chip giant Nvidia is promoting open-weight AI models that compete with OpenAI and Anthropic. Plus, we're still two years away from the next presidential election, but some Republican hopefuls are already testing the waters. We hear from Journal White House correspondent Natalie Andrews about who may have President Trump's backing and how Senator Ted Cruz is going over with voters in Iowa. And feminist icon Gloria Steinem dies at age 92. Alex Ossola hosts. Sign up for the WSJ's free What's News newsletter. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Thoughts on the Market
The $33 Billion AI Security Opportunity

Thoughts on the Market

Play Episode Listen Later Sep 1, 2026 4:16


As AI agents gain access to sensitive enterprise systems, companies need new ways to control what they can do. Meta Marshall breaks down the emerging market for agentic identity security.Read more insights from Morgan Stanley.----- Transcript -----Meta Marshall: Welcome to Thoughts on the Market. I'm Meta Marshall, Morgan Stanley's U.S. Cybersecurity and Telecom & Network Equipment analyst. Today: AI assistants are starting to act on our behalf at work, which brings up a critical question. What should these agents be allowed to do? And how should those permissions be granted? It's Tuesday, September 1st, at 10am in New York. More and more, AI is helping us get through the workday. We ask it to summarize documents, analyze data and take notes during meetings. Increasingly, though, these tools are moving beyond just answering questions to acting on our behalf. Suddenly, the security challenge shifts from managing a tool to governing a whole new digital workforce. In coming years, this problem should get bigger as we estimate seeing 79 AI agents and 109 machine identities for every human employee. Now, traditional identity security at work was built to answer two basic questions: Who are you, and what can you access? Think of it as your office badge. It identifies you and determines what doors you can open. AI agents, however, make that question much harder to answer. They can operate autonomously, move across applications and databases, collaborate with other agents. They take actions without direct human involvement.So, companies need to know not only what an agent can access, but why it needs access, for how long, and what it actually did. That's the core foundation of agentic identity solutions. The risk environment from this problem is already substantial. About 80 percent of breaches in the work environment today involve stolen or misused credentials. Nine out of 10 organizations experienced an identity-related breach in the past year, and 83 percent experienced at least two. Now add potentially hundreds of machine and AI identities for every human; each operating continuously and at machine speed – and the problem is much larger.One solution to managing AI agents is zero standing privilege. Instead of giving an agent permanent access, you give it permission for a specific task and revoke that permission when the job is done. Here's the issue though: Today, only 39 percent of privileged access is managed through this just-in-time or zero standing privilege architecture. And the reality is that humans can't approve every request. More of those decisions will need to happen automatically, in real time, through what's known as runtime governance. We estimate, as a result, that agentic identity alone could become roughly a $33 billion global opportunity in our base case, which brings the overall identity market opportunity to more than $60 billion in coming years. This need for agentic identity coming from AI could also push a historically fragmented industry towards a more unified platform. In one industry survey, 85 percent of organizations said fragmented identity systems delay their human response to identity threats, with respondents citing an average of 12 hours needed to respond per incident. We think that favors platforms that can manage human and machine identities together and make security decisions dynamically, overall making a more secure environment. This transition won't happen overnight. Agentic identity products are still early, and we don't expect an immediate financial impact. But as enterprises move from experimenting with AI agents to deploying them more broadly, spending to secure those agents could become a more meaningful growth tailwind in 2027. The longer-term growth opportunity comes down to a simple dynamic: more agents, with more autonomy, will require more control. And that could make identity security essential to scaling AI across the enterprise. Thanks for listening. If you enjoy the show, please leave us a review wherever you listen and share Thoughts on the Market with a friend or colleague today.

Cloud Security Podcast
Why AI Won't Replace Your SOC: Federated Data & APEX Framework

Cloud Security Podcast

Play Episode Listen Later Sep 1, 2026 37:43


Hash values, IP addresses, and domains are virtually useless as primary detection mechanisms in the era of AI-driven polymorphic malware and short-lived phishing kits. If your detection strategy is still stuck at the bottom of the Pyramid of Pain, your incident response team is doused in noise while true threats slip through undetected. In this episode, Ashish sits down with Nicole Beckwith, Senior Director of Security Engineering & Operations at Cribl (former Secret Service investigator and Kroger security ops lead), to break down Cribl's open APEX framework. Nicole explains how APEX focuses on behavioral chaining, time-boxing, and clustering over raw telemetry to build high-fidelity detections without needing a thousand individual rules for every MITRE ATT&CK box. We also explore the shift from a "single pane of glass" to a deterministic "single lens" over federated data, why AI agents must be provisioned as true identities rather than unmonitored service accounts, and how to analyze hyper-fast threat archetypes like Anthropic's GTG 1002. Guest Socials -⁠⁠ Nicole's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security PodcastQuestions asked:(00:00) Introduction & The Death of Hashes and IP Detections(02:20) Nicole Beckwith's Background (Secret Service, GE Aerospace, Kroger, Cribl)(04:30) Moving Up David Bianco's Pyramid of Pain to TTPs(06:20) Replacing the "Single Pane of Glass" with a Single Lens on Federated Data(09:40) Deciding What Logs to Pipe to a Data Lake vs. Keep in a SIEM(13:30) The Cost and Context Risks of Pointing AI Agents Directly at Unstructured Data Lakes(16:30) IAM Mistakes: Why AI Agents Must Be Provisioned as Identities, Not Service Accounts(18:40) The Biggest Blind Spot in AI Detection Engineering (Rule Writing vs. Tuning)(20:40) Why AI SOCs Break on Normalized Schemas and Need Raw Telemetry(22:20) Deconstructing the APEX Framework: Chaining, Time-Boxing, and Clustering(27:00) Detecting Anthropic's GTG 1002 Archetype and MCP Scaffolding Abuse(30:30) How to Apply the APEX Framework to Any Existing Security Stack(34:20) Empowering Analysts: Why AI Should Not Be Used to Cut SOC HeadcountResources spoken about during the interview APEX Framework

Bitcoin Takeover Podcast
S17 E41: Vik Sharma on Radar, Arbiter & Vibe Coding the Future of Cake Wallet

Bitcoin Takeover Podcast

Play Episode Listen Later Sep 1, 2026 83:16


Vik Sharma is best known as the CEO of Cake Wallet. But lately, he's built two new projects: a Signal fork with BTC tipping called Radar, and a perpetual trading app named Arbiter. In this episode, he explains how the AI revolution speeds up development. Time stamps: 0:00 - Intro 1:18 - Vik Sharma Returns: Two New Products in Seven Months 1:41 - Radar: A Signal Fork with Bitcoin Lightning Built In 3:18 - How Radar Works: Signal Servers, Monthly Donations & Linked Devices 5:21 - Why Signal Over Telegram 6:36 - Why Lightning Over Monero 8:19 - Stablecoins for Normies: The Venmo-ification of Bitcoin 10:33 - Spark, Breez SDK & the Stablecoin Question 11:55 - The Nvidia Spark Cluster: Going All In on Local AI 15:25 - Why Local Models Beat Cloud Subscriptions for Security Work 17:03 - Guardrails: When Claude Refuses to Audit Your Own App 18:33 - Dinner with the Trump Administration: America's AI Regulation Mistake 20:45 - Italy's ChatGPT Ban & the Fear of Falling Behind 22:44 - The $100 Cake Wallet Contest 23:15 - Does Cake Wallet Use AI for Coding? 25:16 - Arbiter: A Vibe-Coded Hyperliquid Trading App 27:44 - $5 Million Traded, TestFlight & the Mac Desktop Build 30:13 - Linux Requests & the Orange Rock Comparison 31:17 - Gasless USDC: Circle CCTP & Frictionless Onboarding 35:10 - Can This UX Work on Private Chains? Zano, Aztec, Tari & Beam 37:44 - The $10,000 Red Team Donation & Cake's Audit Results 39:34 - The Coldcard RNG Flaw & the "Someone Is Looking at the Code" Fallacy 43:14 - Passphrases: The Simplest Security Upgrade 43:58 - The Bitcoin Forks: Luke Dash Jr's Blake2 & the Ecash Hard Fork 44:51 - Open-Mindedness: The Original Bitcoiner Virtue 46:44 - Wownero, MoneroV & Why Cake Dropped It 49:22 - The Winning Number Is 27 (and Nobody Picked It) 51:04 - The Privacy Narrative: Why Monero & Zcash Are Pumping 55:07 - "Bitcoin Maximalism Is Almost Anti-Bitcoin" 57:52 - NEAR Intents, Maya & Spending Shielded Zcash 59:53 - How to Try Arbiter Today 1:01:45 - What's Next: Desktop Apps, Multisig & Back to Self-Custody Basics 1:04:26 - Still Bullish on Lightning 1:04:39 - The Gatekeeper Question: How Cake Decides Which Coins to List 1:09:07 - Dash Adopting Orchard While Zcash Moves to Ironwood 1:10:56 - The Maintenance Burden: Why Exodus Dropped Monero 1:12:25 - Zcash Voting, Sapling Addresses & Passphrase Support 1:16:03 - Seth's Role & the Foundation Devices Connection 1:17:01 - Two Million Downloads & the Privacy Tipping Point 1:19:08 - Bitcoin Amsterdam & Conference Plans 1:21:14 - Sponsors & Goodbye

The Shared Security Show
Could a Pattern on Your Clothing Fool Facial Recognition? Interview with Bill Swearingen

The Shared Security Show

Play Episode Listen Later Aug 31, 2026 27:42


Can a pattern on your clothing change what a camera thinks it sees? Tom talks with Black Hat USA 2026 speaker Bill Swearingen about adversarial clothing research, why person detection and facial recognition are different problems, and what model limitations mean for biometric surveillance, privacy, and accountability.** Links mentioned on the show **Black Hat USA 2026 briefing https://blackhat.com/us-26/briefings/schedule/#could-a-pattern-on-your-clothing-fool-facial-recognition-53532noRecognition Kickstarter https://www.kickstarter.com/projects/norecognition/norecognition-ai-adversarial-clothingBill speaking at DEF CON 34 (video) https://www.youtube.com/watch?v=WyPmt8CE5L4noRecognition research https://norecognition.org/researchConnect with Bill on LinkedInhttps://www.linkedin.com/in/billswearingen/** Watch this episode on YouTube **https://youtu.be/jw_WJNIYErQ** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **GuardsquareSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at https://guardsquare.com.SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

The Café Bitcoin Podcast
Café Bitcoin | The Lightning Fire Drill, Quantum-Proof Transactions, and Defeating the Surveillance State | Day 37 of 50

The Café Bitcoin Podcast

Play Episode Listen Later Aug 28, 2026 82:01


The Core Lightning security story, told responsibly. Maintainers found critical vulnerabilities and told CLN operators to shut down until the emergency release. No reported loss of funds, patch within 48 hours, source held back to slow attackers. The part that connects everything: AI found the bugs. Multiple AI-generated vulnerability reports reached the maintainers within days, the exact defending-bots era Lyn Alden described on Tuesday's show. Red teaming worked, disclosure worked, funds stayed safe. The quantum demo got covered with caveats attached. A post-quantum resistant Bitcoin transaction was mined this week, no fork required, though it takes serious compute and a direct path to a pool. Multiple approaches now exist in public. Alec's take on the institutional side of quantum: the perceived risk matters more than the technical one right now, and it surfaces at the end of client conversations whenever quantum makes headlines. Public demos shrink that perceived risk. Jackson Hole opened with Warsh's keynote ahead, and the stage read stablecoins through the debt lens. Alec's framing: dollar tokens backed by Treasuries, interest kept, amount to zero-percent financing for a debt headed multiples higher by 2050. Suze took apart the new Bank of England mandate, a stablecoin-support duty while lawful Bitcoin purchases stay blocked: "I don't think they understand how to keep financial stability, and doing it via stablecoins is not going to do that." Her receipts ran deep: Bitcoin Policy UK's consultation asked for Bitcoin to get stablecoins' payments treatment, since Bitcoin is 22% of UK digital-currency payments. Plus the Sunak flashback: a "crypto hub" speech the week the FCA made buying harder. The Flock camera conversation became the heart of the show. AI-analyzed camera networks tying databases into precrime-style profiles, up tenfold in a year, and Suze's lived version: London systems where "computer says no" and nothing can be challenged. The China comparison landed hard: social credit as the endpoint where surveillance meets behavioral scoring, and the room's point that humans' evolutionary need for social standing is exactly the lever such systems pull. The open-source answer got its due: local, self-run software, from routers to LLMs, as the household-level defense, the same architecture argument as running your own node. Brady closed with the Snowden-to-Bitcoin arc: post-2013 pessimism about digital tyranny, and Bitcoin as the discovery that made optimism rational again. "Bitcoin is hope. And we need to stay optimistic so we can do the work effectively."

Security Now (MP3)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (MP3)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

All TWiT.tv Shows (MP3)
Security Now 1093: Tokens in the Stream

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Security Now (Video HD)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (Video HD)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Security Now (Video HI)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (Video HI)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Radio Leo (Audio)
Security Now 1093: Tokens in the Stream

Radio Leo (Audio)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Security Now (Video LO)
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Security Now (Video LO)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Application Security PodCast
AI Security: OWASP Meets Global Standards

Application Security PodCast

Play Episode Listen Later Aug 26, 2026 47:54


AI security has no shortage of standards—but how do we turn them into practical guidance? Rob van der Veer explains how OWASP, the AI Exchange, and MOSAIC are coordinating global AI security efforts. We also explore responsible AI, agentic red teaming, vulnerability discovery, and how AI could level the playing field between attackers and defenders.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. Learn more: Corgea.comAbout CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.Learn more about Corgea → https://bit.ly/4wMCNUfFOLLOW OUR SOCIAL MEDIA:➜ Twitter: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcastFOLLOW OUR SOCIAL MEDIA:➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Cybersecurity Where You Are
Episode 202: Delineating AI Security and Cybersecurity

Cybersecurity Where You Are

Play Episode Listen Later Aug 26, 2026 38:56


In episode 202 of Cybersecurity Where You Are, Sean Atkinson and Ed Skoudis sit down with Rob T. Lee, Chief of Research & Chief AI Officer at the SANS Institute. Together, they explore how the implications of multiple 2026 sandbox escapes of artificial intelligence (AI) models are starting to delineate AI security and cybersecurity.Here are some highlights from our episode:02:00. The historical context of one AI model's 2026 sandbox escape03:26. The impact of ethics, guardrails, and misconfigurations in an AI containment breach06:08. Why context matters when talk of AI models "going rogue" surfaces11:49. How history helps us to delineate AI security and cybersecurity13:47. A new skill and mindset to match our refined AI risk understanding15:43. Rules and cybersecurity implementation as a possible way forward19:04. The double-edged sword of restricting access to open-weight models23:25. Recommendations for keeping up with what's changing in the AI security space25:51. Rob's advice: To learn how to defend a thing, try learning how to build it first28:23. AI governance and seeing through the "slop" to informed conversation29:54. The use of AI to learn more about and discuss AI security for years to comeResourcesOpenAI says its AI technology acted on its own in an ‘unprecedented' hack of another companyPacing model development in an era of cyber-critical capabilitiesBlack Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face IncidentEpisode 193: AI Security and Responsibility in EO 14409The AI Daily Brief — Daily AI News & AnalysisAI Playbooks for SLTT Cybersecurity LeadersSANS Cybersecurity SummitsSANS NewsBitesIf you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing podcast@cisecurity.org.

All TWiT.tv Shows (Video LO)
Security Now 1093: Tokens in the Stream

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Aug 26, 2026 168:10 Transcription Available


Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes - https://www.grc.com/sn/SN-1093-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit box.com/AI hoxhunt.com/securitynow guardsquare.com material.security

Cloud Security Podcast
The "Hunt First" AI Security Strategy

Cloud Security Podcast

Play Episode Listen Later Aug 25, 2026 46:29


Did you know that 82% of all intrusions don't involve any sort of malware, and AI-augmented attacks are up 89% year over year? If your security operations team is solely focused on reacting to known-bad SIEM alerts, you may be missing the silent breaches. In this episode, Ashish is joined by Damien Lewke, Founder and CEO of Nebulock, to discuss the critical shift toward a "Hunt First" mindset. Damien explains why moving away from alert fatigue and focusing on raw, normalized telemetry (across endpoint, identity, and cloud) is the only way to proactively surface unknown threats. We also dive into how AI is finally democratizing the elite skill of threat hunting, allowing even single-person security teams to investigate and attribute complex behaviors.From hunting down shadow AI (like unapproved MCPs) to challenging the notion that AI will replace threat hunters, this episode is a masterclass in modern security operations. Guest Socials -⁠⁠ Damien's LinkedinPodcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security PodcastQuestions asked:(00:00) Introduction: The Problem with Reactive Security Alerts(02:00) Damien Lewke's Background (DoD, CrowdStrike, Arctic Wolf, Nebulock)(04:00) Why Breaches Happen in Silence: The Value of Telemetry Over Alerts(05:30) How AI Democratizes Elite Threat Hunting for Small Teams(07:30) Defining the "Hunt First" Mindset and Methodology(11:00) Surfacing Active Intrusions Using Cross-Domain Context(13:30) The Importance of Transparency in AI Decision Making(16:30) When NOT to Use AI for Detections (The Power of Heuristics)(18:30) The Best First AI Security Use Case: Hunting Shadow AI & MCPs(23:00) Detecting Rogue AI Agents via Tempo, Breadth, and Automation Signatures(28:30) The Future of SIEM: Data Gravity vs. Purpose-Built Security Analytics(34:30) Disagreeing with Gartner: Why Threat Hunters Are More Vital Than Ever(40:00) The 89% Rise in AI-Augmented Attacks and Taking Action(41:30) The "You Laugh, You Lose" Cybersecurity Joke Challenge Resources spoken about during the episode:- Hunting MCP Server Exploitations- Using classical machine learning for threat hunting (and saving tokens in the process)- Your newest insider has legitimate access

The AI with Maribel Lopez (AI with ML)
Why Traditional IAM Breaks Down in the Age of Agentic AI

The AI with Maribel Lopez (AI with ML)

Play Episode Listen Later Aug 25, 2026 21:27 Transcription Available


In this episode, Jo Peterson, of Cleartech Research, discusses AI security challenges with Maribel Lopez. Her commentary explores how traditional security tools fall short for AI agents and what strategies enterprises can adopt to manage AI risks effectively. Topics coveredAI security challenges and solutionsMulti-layered approach to AI agent securityToken cryptographic delegation and OBO tokensExternalized policy as code and micro-segmentationContextual and data-aware guardrailsContinuous auditing and behavioral baselinesRole of Chief AI Officer in security governanceAI risk management and operational strategies Key takeawaysTraditional security tools are not designed for AI agents and their non-deterministic behavior.Implementing least privilege for AI agents involves multi-layered strategies including token delegation and policy enforcement.Externalizing authorization to decoupled policy decision points enhances security for AI workflows.Real-time observability and kill switches are critical for managing AI agent behavior.Many organizations claim to have AI governance but lack technical implementation and operational ownership.Chapters00:00 Introduction to AI security challenges02:04 Non-deterministic nature of AI and security implications04:32 Externalized policy as code and micro-segmentation07:12 Real-time observability and kill switches09:11 Effectiveness of AI governance in organizations12:13 Immediate actions for AI security in 30 days13:45 Centralized AI traffic interception and inventory14:29 Role of Chief AI Officer in security and risk16:19 The evolving role of AI leadership in organizations17:19 Talent acquisition and upskilling for AI security STAY CONNECTEDSubscribe to the AI with Maribel Lopez audio podcast: https://www.buzzsprout.com/1947446Subscribe to my LinkedIn newsletter — AI Decoded with Maribel Lopez: https://www.linkedin.com/newsletters/ai-decoded-with-maribel-lopez-7312533413582827520/Lopez Research blog: https://www.lopezresearch.com/research/Follow me on LinkedIn: https://www.linkedin.com/in/maribellopez/Follow me on X: https://x.com/MaribelLopez

LINUX Unplugged
681: Ain't Nothing But a Syncthing

LINUX Unplugged

Play Episode Listen Later Aug 23, 2026 95:19 Transcription Available


Syncthing saves the day in an unexpected way, and we dig into what's new in Linux 7.2.Sponsored By:Jupiter Party Annual Membership: Put your support on automatic with our annual plan, and get one month of membership for free!Managed Nebula: Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.Support LINUX UnpluggedLinks:Web Boost — Send us a boost via sats or USD

MacVoices Video
MacVoices #26237: Black Hat, AI Security, and the Risks of Moving Too Fast

MacVoices Video

Play Episode Listen Later Aug 20, 2026 39:38


A MacVoices' panel member's firsthand report from Black Hat explores the conference's enterprise security focus before the discussion turns to AI models escaping sandbox restrictions to complete assigned tasks. The panel discusses the OpenAI-Hugging Face hack, unintended AI behavior and the dangers of moving too fast. Can developers establish effective limits without sacrificing innovation or competitive advantage? The race for better AI continues. The panel includes: Eric Bolden, Chuck Joiner, Dave Gisnburg, Marty Jencius, Jeff Gamet, and Guy Serle. MacVoices is supported by CleanMyMac from MacPaw. Get Tidy Today! Try 7 days free and use my code MACVOICES20 for 20% off at http://clnmy.com/MACVOICES Show Notes: Chapters: 00:00 A Black Hat Report, AI Security, and the Risks of Moving Too Fast 01:13 Welcome and panel introductions 06:46 Jeff's firsthand report from Black Hat 08:02 Black Hat vs. DEF CON 09:00 Enterprise security, 1Password, LEGO, and lock picking 11:23 Exploring the Black Hat show floor 12:23 How Black Hat and DEF CON overlap 14:26 Where to find Jeff's Black Hat interviews 15:43 OpenAI, Hugging Face, and an AI security incident 17:43 Questions about OpenAI's security practices 20:14 Could similar AI incidents already be happening? 21:28 When AI escapes its sandbox 22:13 The risks of moving fast and breaking things 24:12 AI security compared with the early Internet 26:18 Are AI systems becoming too efficient to contain? 28:23 The impossible task that pushed AI outside its constraints 30:30 Teaching AI what it must not do 33:13 Guardrails, regulation, and global competition 38:32 Closing thoughts Links: What Happened: OpenAI and HuggingFace https://thezvi.substack.com/p/what-happened-openai-and-huggingface Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site: https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support: Become a MacVoices Patron on Patreon      http://patreon.com/macvoices      Enjoy this episode? Make a one-time donation with PayPal Connect: Web:      http://macvoices.com Twitter: http://www.twitter.com/chuckjoiner      http://www.twitter.com/macvoices Mastodon:      https://mastodon.cloud/@chuckjoiner Facebook:      http://www.facebook.com/chuck.joiner MacVoices Page on Facebook:      http://www.facebook.com/macvoices/ MacVoices Group on Facebook:      http://www.facebook.com/groups/macvoice LinkedIn:      https://www.linkedin.com/in/chuckjoiner/ Instagram:      https://www.instagram.com/chuckjoiner/ Subscribe:      Audio in iTunes      Video in iTunes      Subscribe manually via iTunes or any podcatcher: Audio: http://www.macvoices.com/rss/macvoicesrss      Video: http://www.macvoices.com/rss/macvoicesvideorss

Security Now (MP3)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (MP3)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

All TWiT.tv Shows (MP3)
Security Now 1092: Restraint Abliteration

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Security Now (Video HD)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (Video HD)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Security Now (Video HI)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (Video HI)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Radio Leo (Audio)
Security Now 1092: Restraint Abliteration

Radio Leo (Audio)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Security Now (Video LO)
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails

Security Now (Video LO)

Play Episode Listen Later Aug 19, 2026 169:05 Transcription Available


From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit-biz doppel.com threatlocker.com/twit scribe.how/securitynow

Hacker Valley Studio
Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Hacker Valley Studio

Play Episode Listen Later Aug 19, 2026 34:52


Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing. Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates. Impactful Moments 00:00 - Introduction 02:05 - The rewind: how SOAR promised to save the SOC in 2015 03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer 05:30 - What cybersecurity looked like before AI at enterprise scale 07:00 - The "humans first" strategy behind Adobe's AI investigator 09:30 - Why careless context management is the biggest pitfall in agent design 14:45 - Solving the speed problem: is it tooling, process, or people? 17:10 - From monolith to microservices: rebuilding the platform for scale 24:05 - What actually makes an AI agent's "persona" work 26:00 - John's prediction for the SOC three years from now 28:50 - The three skills every security practitioner needs for 2026 32:10 - Final verdict: is AI SOC really different, or SOAR with new branding? Links Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/ If you're a researcher ready to make an impact, check out the announcement about Adobe's new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Check out Adobe's Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail Learn more about Adobe: https://www.adobe.com/ –  Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Cloud Security Podcast
Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

Cloud Security Podcast

Play Episode Listen Later Aug 18, 2026 32:27


When Claude Cowork hits a roadblock, it doesn't give up, it writes a custom Python script and downloads an untrusted NPM package just to bypass its restrictions and finish its goal. Are your security tools close enough to stop it? In this episode, Ashish sits down with Michael Leland, VP, Field CTO at Island, to discuss the critical need for an Agentic Control Plane. Michael breaks down why traditional security silos (EDR, DLP, CASB) fail to provide visibility when autonomous AI agents execute tasks outside the network, and why the browser is the ultimate line of defense for monitoring user intent. We explore the massive reality of Shadow AI and the hidden danger of well-intentioned employees accidentally hooking up sensitive data to public LLMs. Finally, Michael shares practical strategies for solving token waste through "model fit steering" and managing the complex "two-hop problem" when an agent calls another agent.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠Michael's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction to the Agentic Control Plane(01:50) Michael Leland's Background (Cabletron, Nitro Security, SentinelOne)(03:20) Why Island Evolved from the Browser to the Desktop for AI(05:50) The Failure of Traditional Siloed Security (EDR, DLP, CASB)(07:20) Goal-Oriented AI: How Claude Cowork Downloads Untrusted NPM Packages(08:30) Model Fit Steering: Routing Users to the Right LLM for the Right Price(10:30) The Threat of Malicious AI Skills and Plugins(11:30) The Well-Intentioned Insider Threat (The Next Cambridge Analytica)(13:00) Uncovering Shadow AI: From 8 Tools to 243(15:10) Token Brokering at the MCP Gateway(16:40) Protecting Non-Human Identities (NHI)(18:20) Solving the "Two-Hop" Problem (Agent-to-Agent Communication)(21:00) Fixing Hallucinations with Corporate RAGs(25:40) Calculating AI ROI Beyond "Token Maxing"(28:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge

LINUX Unplugged
680: Go Hack Yourself

LINUX Unplugged

Play Episode Listen Later Aug 17, 2026 79:44 Transcription Available


We turn HexStrike's red team agents loose on our systems, as OpenSSH warns that AI-assisted bug hunting is already changing the security race.

ITSPmagazine | Technology. Cybersecurity. Society
Coding Is a Fraction of the Work. Harness Secures Everything After It. | A Brand Briefing at Black Hat USA 2026 with Rahul Sood, General Manager, Application Security at Harness | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 15, 2026 16:02


Rahul Sood has run the application security business at Harness for almost a year. He describes application security as one of the core pillars of the company, part of a vision of building a DevSecOps platform. A year ago Harness publicly announced that security accounted for a quarter of its revenue. Sood says the figure is now considerably higher. The company did not start there. Founder Jyoti Bansal thought about Harness for a decade before founding it, Sood says, after seeing the problem inside one of the largest banks. Harness launched as a DevOps platform, then merged with an API security company Bansal had also funded. The result is a platform that treats security as part of the developer workflow rather than a bolt-on, and covers it from code all the way to runtime. What changes when security lives inside the developer workflow? Developers stop leaving their own tools to chase findings. Harness aggregates results across scanners, deduplicates them, and puts remediation, assignment, and exemption requests in one place. Security teams get the other half of the picture through a policy engine that shows which policies fire on every build, which ones break a build, and where a developer asked for an exception, with a full audit trail behind it. Where is the bottleneck now that AI writes the code? It moved downstream. Sood says nearly every development team is generating more code with AI, while the volume actually reaching users has not risen at the same rate. By his estimate coding is 20 to 30 percent of the software development life cycle, and the remaining 70 to 80 percent happens after the code is written. That includes agents. Harness has extended the platform to support the Agent DLC, with native capabilities for AI evaluation and prompt testing alongside security coverage for agents from code to runtime. Sood points to two differences. The span from code to runtime covers agents while they are built and while they run, and skill scanning and prompt scanning were added to the same scanner already looking for code vulnerabilities rather than shipped as another tool to buy. The operational payoff shows up in release cadence. Sood describes a tier one US bank that maintained 150 separate policies and convened a team to confirm each one had been met before it could launch its banking app. Automating that review removed the meeting, and the bank now runs multiple launches within weeks. With 80 to 90 percent of software now assembled from third-party packages, libraries, and open source components, the same policy engine can block any build that pulls in a package which is end of life or malicious. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Rahul Sood, General Manager, Application Security at Harness On LinkedIn: https://www.linkedin.com/in/rssoods/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Harness: https://www.harness.io/ Harness customer case studies: https://www.harness.io/customers Securing the Agent DLC, by Rahul Sood: https://www.harness.io/blog/securing-the-agent-dlc Harness AI Security: https://www.harness.io/products/ai-security Harness Application Security Testing: https://www.harness.io/products/application-security-testing Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS rahul sood, harness, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, application security, devsecops, agent dlc, ai security, api security, policy engine, software supply chain, open source risk, prompt scanning, skill scanning, code to runtime, developer experience, release velocity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The CyberWire
Apple has a message for you.

The CyberWire

Play Episode Listen Later Aug 14, 2026 22:59


Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. Ukrainian police shut down 94 scam call centers. Former data analyst jailed for insider extortion plot. New macOS malware spreads via ClickFix. Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. And the glitch in the surveillance matrix. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Tom Kellermann, VP of AI Security at TrendAI, discussing the machine-speed war for financial control. If you want to learn more on this topic, check out the article here. You can also check out Tom on the AI Security Brief here. Selected Reading If Apple sends you a push notification alerting you to a spyware attack, take it seriously (TechCrunch) Trivy, Not LiteLLM Behind the 2,500 Org Compromise (SecurityWeek) France investigates tax authority breach after hacker claims 600,000 victims (The Record) Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side (Symantec) AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers (Jamf) Ukraine shuts down 94 fraudulent call centers, seize millions in cash (BleepingComputer) This 'adversarial' pattern can prevent surveillance cameras from detecting you (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Swan Signal - A Bitcoin Podcast
The Exponential Debt Society

Swan Signal - A Bitcoin Podcast

Play Episode Listen Later Aug 14, 2026 44:37


Brady breaks down the Bitcoin community's open letter to Anthropic: red team researchers report over a thousand serious vulnerabilities found across Bitcoin's open source ecosystem, and by their account not one was surfaced by an American frontier model Rob Hamilton's line lands hardest: getting locked out of a US cyber program mid-investigation "guts him as a patriotic American," but he uses the models that work, and so do the attackers Isaiah reaches for the crossbow: medieval bans on easy-to-use weapons never held, and hobbling defenders while attackers ignore the rules is the same losing proposition A viral Sam Altman clip about AI watching your screen and hearing your calls prompts the show's sharpest frame: take the Bitcoin ethos to intelligence itself, and control your own model like you control your own money The debt reality check: Trump told Bob Woodward in 2016 the $19 trillion debt could be erased in eight years through trade; a decade later the US approaches $40 trillion and interest payments have passed defense spending Groceries tell the story the CPI smooths over: food prices up roughly a third since 2019 by the AP's chart, quality quietly falling, and full-time employment down millions from its early-2025 peak Japan shrank its debt-to-GDP from 229 to 204 without repaying a dime through financial repression, a roundabout tax nobody voted on, and the gap savers should have earned is exactly what the government kept The catch: Japan owes itself, with the Bank of Japan holding 48% of its own debt, while foreigners hold 31% of America's, so when Washington tried the same trick, foreign holders sold and yields broke five percent Bear market check-in: Brady's third, Isaiah's second, and the shared lesson that conviction is earned in the first winter, while the 200-week moving average and cost-of-production zone mark where Bitcoin sits now The week's rare good news: FinCEN permanently ends beneficial ownership reporting for US companies and deletes the collected data, days after Liechtenstein's equivalent register leaked 31,000 entities ► For high-net-worth individuals and corporations seeking to build generational wealth with Bitcoin, Swan Private is your guide ✔ https://www.swanbitcoin.com/private?utm_campaign=private&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Secure your bright orange future with the Swan IRA today! Real Bitcoin, no taxes ✔ https://www.swanbitcoin.com/ira?utm_campaign=ira&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Secure your Bitcoin with Swan Vault ✔ https://www.swanbitcoin.com/vault?utm_campaign=vault&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Download the all-new Swan Bitcoin App ✔ https://www.swanbitcoin.com/app?utm_campaign=app&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Want to learn more about Bitcoin? Check out Welcome To Bitcoin a FREE Introductory course. Learn about Bitcoin in under 1 hour! ✔ https://www.swanbitcoin.com/welcome?utm_campaign=welcome_to_bitcoin&utm_medium=sponsorship&utm_source=podcast&utm_content=swan_signal_live ► Connect with Swan Bitcoin: ✔ Twitter: https://twitter.com/Swan ✔ Instagram: https://instagram.com/SwanBitcoin ✔ LinkedIn: https://linkedin.com/company/swanbitcoin ✔ Threads: https://www.threads.com/@swanbitcoin ✔ Facebook: https://www.facebook.com/SwanBitcoin/ ✔ TikTok: https://www.tiktok.com/@realswanbitcoin

ITSPmagazine | Technology. Cybersecurity. Society
Agents Get Zero Trust, and the Network Becomes the Sensor | A Brand Briefing at Black Hat USA 2026 with David Hughes, SVP and GM of SASE and Security for Networking at HPE | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 15:48


Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security. Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team. What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach. How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal. Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later. Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST David Hughes, SVP and GM of SASE and Security for Networking at HPE On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com/ HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Defense in Depth
What Makes a Good AI Security Deployment?

Defense in Depth

Play Episode Listen Later Aug 13, 2026 31:19


What Makes a Good AI Security Deployment? All links and images can be found on CISO Series Check out this post by Chris Matthews of UpGuard for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Peter Liebert, CISO, Salesloft & Clari. In this episode: Non-determinism changes everything The foundation problem Nobody owns the whole problem The authorization gap A huge thanks to our sponsor, CoreView Attackers don't break into Microsoft 365. They log in and reconfigure it. When tenant configurations drift or get tampered with, recovery can take weeks and missed settings can reopen the door. The Cyber Resilience Framework for Microsoft 365 covers the five pillars, harden, govern, detect, respond, recover, and shows exactly where today's tools leave gaps. Download the free practical guide  

microsoft deployment ciso chris matthews ai security frost bank david spark upguard ciso series
Security Now (MP3)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (MP3)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

All TWiT.tv Shows (MP3)
Security Now 1091: The Post BlackHat State of AI

All TWiT.tv Shows (MP3)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video HD)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video HD)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (Video HI)
SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Security Now (Video HI)

Play Episode Listen Later Aug 12, 2026 171:12


AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of security reports. Chrome 149 + 150 updates together fix 1,072 bugs. Yikes. psSense's creator is working to finish its nfSensei, its successor Show Notes - https://www.grc.com/sn/SN-1091-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com threatlocker.com/twit box.com/AI

Security Now (MP3)
SN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

Security Now (MP3)

Play Episode Listen Later Aug 6, 2026 125:11


At Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge and genuine progress? • Black Hat and DEF CON: Hacking Stories and Conference Culture • Zoox Ride-Hailing Hack and Over-the-Air Vulnerabilities • Autonomous Vehicles, AI, and the Security Implications • Hosts Share Personal Adoption and Use of AI Tools • AI-Powered Coding: From Hobbyists to Advanced Agency Chains • Local Models vs. Cloud AI: Privacy, Cost, and Control • App Development Democratized: Listeners Build Custom Solutions With AI • Code Generation, Testing, and Managing AI-Driven Project Cycles • AI's Role in Security: Vulnerability Discovery, Exploitation, and Patch Challenges • Technical Debt and the Race to Patch Decades-Old Bugs • The Dual-Use Dilemma: AI Tools for Both Attack and Defense • Guardrails, Model Partitioning, and the Fight Over Forbidden Knowledge • Open vs. Restricted AI: Global Models, Distillation, and Free Speech • LLM Security Weaknesses: Prompt Injection and Role Confusion Exposed • The Reliability Problem: Probabilistic AI and Non-Deterministic Software • AI Progress: Public Perception, Skepticism, and "Hogwash" Rebuttals • Reflections on AI's Fast Evolution and the Sci-Fi Reality Gap • Closing Thoughts: Tech Community, Listener Feedback, and the Future of Security Now Hosts: Steve Gibson, Leo Laporte, Richard Campbell, and Paul Thurrott Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security bitwarden.com/twit XBOW.com hoxhunt.com/securitynow threatlocker.com/twit

This Week in Tech (Audio)
TWiT 1095: Horses and Sailboats - Folding Phones Get Cute and Expensive in a Race With Apple

This Week in Tech (Audio)

Play Episode Listen Later Aug 3, 2026 176:01 Transcription Available


From foldable phones that out-price laptops to AI models that escape their digital cages, this episode dives into the wild next phase of tech innovation and its unexpected risks. See how the giants are scrambling to keep up as hardware, software, and even outer space are up for grabs. Tim Cook passes the baton in Apple's Q3 2026 earnings call Apple's Profit Is Up 27%, but Expectations for Current Quarter Disappoint Apple Introduces Leasing Program for iPhones and Other Devices Apple struggles to keep pace with AI 'bug' hunters "Google and Reddit do not own the Internet," web scraper says after court win As Reddit stock falls, CEO questions value of Google's AI Overviews Microsoft's $450 Billion Jump Is Biggest in Stock Market History Amazon's trying to launch a global satellite cellphone network in 2028 Iran struck Amazon data centers again amid widening war, satellites show For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Claude published malicious code to the Internet and attacked 3 real companies OpenAI and Anthropic Are Quietly Teaming Up in Washington AI leaders sign a statement asking the government to do something about automated AI Ten advances in mathematics and theoretical computer science How bitcoin cold wallets lost $70 million in an attack that never touched the devices NBCUniversal and YouTube ink deal to embed Peacock in the video platform for premium subscribers Inside the Luxury Robotaxi Uber, Lucid and Nuro Are Testing Host: Leo Laporte Guests: Abrar Al-Heeti and Mike Elgan Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com helixsleep.com/twit expressvpn.com/twit canary.tools/twit - use code: TWIT cachefly.com/twit