Podcasts about cloud security

  • 677PODCASTS
  • 3,242EPISODES
  • 40mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 18, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about cloud security

Show all podcasts related to cloud security

Latest podcast episodes about cloud security

Tyler Tech Podcast
Cloud Compliance in Government: FedRAMP vs. GovRAMP

Tyler Tech Podcast

Play Episode Listen Later Aug 18, 2026 30:03


In this episode of the Tyler Tech Podcast, John Smail, U.S. federal security and compliance lead at Amazon Web Services (AWS), and Clay Thomas, vice president of cloud strategy at Tyler Technologies, explore the differences between FedRAMP and GovRAMP and why the distinction matters for government organizations evaluating cloud solutions. Recorded live at Tyler Connect 2026 in Las Vegas, the conversation breaks down the purpose of each framework, who they serve, and how they relate to broader cloud security and compliance efforts. John and Clay discuss common misconceptions surrounding cloud compliance, including why FedRAMP and GovRAMP are often treated as interchangeable despite serving different levels of government and addressing different requirements. They also examine the relationship between compliance and cybersecurity, highlighting why compliance frameworks should be viewed as tools for providing assurance rather than direct measures of security. The episode concludes with practical guidance for government IT, security, and procurement leaders. From evaluating risk and data sensitivity to balancing compliance requirements with cost, innovation, and operational goals, John and Clay emphasize the importance of aligning cloud decisions with an organization's specific needs rather than defaulting to the most stringent compliance standard. This episode also highlights an upcoming webinar on cloud strategy in government, featuring research-backed insights and real-world public sector experiences. Learn more and register now: Why Private Sector Cloud Falls Short: Discover Cloud Purpose-Built for the Mission of Government This episode also highlights emerging strategies for building efficiency in the public sector, with insights into how agencies are using technology and process improvements to do more with existing resources. Download: How Governments Build Efficiency at Scale And learn more about the topics discussed in this episode with these resources: Download: AI for Impact: Proven Results for Government Download: State CIO 2026 Priorities Playbook Download: Industry Insight: AWS GovCloud (US) vs. AWS Standard (US) Download: Modern Governments Live in the Cloud Download: Building a Resilient Government Watch: Peoria County Securely Shares Data Across Agencies Read: Boosting Resilience: Cloud Solutions for Modern Government Read: Modernize in the Cloud for Innovation and Resilience Listen to other episodes of the podcast. Let us know what you think about the Tyler Tech Podcast in this survey!

Gestalt IT Rundown
Fake Airplane Wi-Fi, NVIDIA AI, & Cloud Security | Tech Field Day News Rundown: August 12, 2026

Gestalt IT Rundown

Play Episode Listen Later Aug 12, 2026 30:20


When mid-air Wi-Fi scares meet massive enterprise AI investments, IT teams are forced to rethink both security and cloud strategy. On this episode of the Tech Field Day News Rundown, hosts Tom Hollingsworth and Alastair Cooke break down a fake Wi-Fi network detected on a Delta flight post-DEF CON that temporarily shut down inflight internet. They also explore NetApp acquiring JetStream Software to ease VMware cloud disaster recovery, along with NVIDIA releasing open-source tools like Nemotron 3.5 Lightning and NeMo Switchyard to cut enterprise AI costs. IBM and Together AI are building a $240 million AI cluster on IBM Cloud, Sectigo launched its Orchestration Gateway to automate certificate renewals before TLS lifespans drop to 47 days, Blumira introduced the Hearth AI security command center, and the FBI teamed up with Huntress to patch thousands of compromised Microsoft Exchange servers using an attacker backdoor.This and more on the Tech Field Day News Rundown with Tom Hollingsworth and Alastair Cooke. Tech Field Day is part of The Futurum Group. Time Stamps: 0:00 - Cold Open1:18 - Welcome to the Tech Field Day News Rundown2:17 - NetApp Buys JetStream to Expand VMware Disaster Recovery5:07 - Delta Flight Wi-Fi Targeted by Hackers After DEF CON8:11 - NVIDIA Pushes Open AI With New Models and Routing Tools11:00 - Sectigo Automates Certificate Management as Renewal Windows Shrink14:33 - IBM and Together AI Strike $240M NVIDIA Infrastructure Deal16:55 - Blumira Launches AI Command Center for Cybersecurity19:55 - FBI and Huntress Used Hacker Backdoors to Disrupt Silk Typhoon26:07 - ⁠The Weeks Ahead: Upcoming Tech Field Day Events29:13 - Thanks for Watching the Tech Field Day News RundownThis and more ⁠on the Tech Field Day News Rundown⁠ with ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Tom Hollingsworth⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Alastair Cooke⁠. Follow our hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Tom Hollingsworth⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Alastair Cooke⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Stephen Foskett⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Follow Tech Field Day ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠on LinkedIn⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠X/Twitter⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Bluesky⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, and on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Mastodon⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠.

Ich glaube, es hackt!
KI, Cloud und andere Dinge, die plötzlich Milliarden kosten

Ich glaube, es hackt!

Play Episode Listen Later Aug 11, 2026 57:31 Transcription Available


In dieser Folge von „Ich glaube, es hackt!“ geht es einmal quer durch die digitale Welt: - Zwangstrennung bei Mobilfunk: Warum 23 Stunden Telefonieren doch kein notwendiger Test waren. - Abkürzungs-Quiz: Radar, SCUBA, LASER und CAPTCHA – und die überraschenden Bedeutungen dahinter. - KI erkennt ein Kühlakku als Handy: Wenn automatische Verkehrsüberwachung kreativ danebenliegt. - Cloud-Kosten außer Kontrolle: Was passiert, wenn aus 43 Cent plötzlich Milliarden werden – und warum Plausibilitätschecks bei Cloud-Rechnungen dringend nötig sind. - Ausgebrochene KI-Agenten: Was passiert, wenn eine KI aus ihrer Sandbox entkommt und plötzlich mit anderen KI-Agenten kommuniziert? - KI-Crawler und robots.txt: Wem gehört eigentlich der Content im Internet – und darf KI ihn einfach fürs Training verwenden? - Cloudflare und AI-Crawler: Warum sich die Spielregeln für Webseitenbetreiber verändern könnten. - Pay-per-Crawl: Bezahlen KI-Anbieter künftig für das Crawlen von Webseiten? - Lokale KI-Modelle: Warum Regierungen möglicherweise darüber diskutieren, wer welche Modelle herunterladen darf. - Das große Codezeilen-Quiz: Ford F-150 gegen Boeing 787 gegen Facebook. Spoiler: Das Auto gewinnt deutlich. - KI im Bewerbungsgespräch: Bewerber lassen sich live coachen – und Unternehmen setzen ihrerseits KI im Recruiting ein. - Bakteriophagen und KI: Wenn künstliche Intelligenz nicht nur Software, sondern biologische Systeme mitgestaltet. - Grok(k)epedia: Warum die KI-Wikipedia von Elon Musk offenbar nicht mehr weiter aktualisiert wird. - Doom in Microsoft Paint: Weil „läuft Doom darauf?“ offenbar immer noch eine gültige technische Messgröße ist. - PlayStation-2-Tricks: Warum manche Spiele-Discs absichtlich mit Datenmüll gefüllt wurden. - Blitzer.de für den ÖPNV: Eine App warnt vor Fahrkartenkontrollen. - Werbung im Auto: Spider-Man im BMW – harmlose Spielerei oder der nächste Schritt zur Werbeplattform auf vier Rädern? - Software-Features zum Mieten: Warum Rüdiger und Tobi so gar keine Fans von nachträglich freischaltbaren Funktionen sind. - Tonies und veränderliche Inhalte: Was passiert, wenn das Produkt, das man gekauft hat, seine Inhalte nachträglich ändern kann? - Kreuzfahrt-Security: Ein beobachteter Zugangscode reicht offenbar, um eine vermeintliche Kapitänsdurchsage zu faken. - Und zum Schluss: Golf. Natürlich. Nach fast 24 Stunden Telefonat darf auch das noch sein. -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast

DailyCyber The Truth About Cyber Security with Brandon Krieger
Agentic AI Closing Cloud Security's 15-Minute Exploit Window | DailyCyber 297 with Shimon Tolts

DailyCyber The Truth About Cyber Security with Brandon Krieger

Play Episode Listen Later Aug 9, 2026 62:54


Attackers are moving from a 14-day exploit window to a 15-minute one. On this episode, Shimon Tolts, CEO & Co-Founder of Copperhelm, joins Brandon Krieger to explain how his team built the industry's first agentic cloud security platform to meet that speed — and why security has lagged behind every other engineering discipline in adopting AI. Topics include: What makes a security platform genuinely "agentic" How Context Lake structures cloud data so AI can act with confidence Earning security leaders' trust in autonomous agents on live infrastructure Building at scale: lessons from Unity and ironSource What CISOs should prioritize to prepare for the agentic era Guest: Shimon Tolts, CEO & Co-Founder, Copperhelmhttps://copperhelm.com/ Host: Brandon Krieger, CEO & vCISO Advisor Listen: https://www.DailyCyber.ca Watch Full Episode: YouTube.com/BrandonKrieger Listen: DailyCyber.ca

Federal Drive with Tom Temin
VA's cloud security memo more mythbuster than new policy

Federal Drive with Tom Temin

Play Episode Listen Later Aug 5, 2026 9:07


The Department of Veterans Affairs recent memo on cloud security isn't breaking new ground. It's not even changing policy. The best comparison for the memo that is reminding VA contracting officers and program managers that vendors do not have to have their FedRAMP certification before responding to or submitting proposals for solicitations or requests for information is mythbusting.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

The ISO Show
#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

The ISO Show

Play Episode Listen Later Aug 5, 2026 45:06


There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation of 20,000 jobs during its construction, and a further 8,000 jobs once it's operational. It's undoubtedly brought a lot of eyes towards the smallest county in the UK, and with it a lot of opportunity for local businesses to get involved with not only the main theme park itself, but the surrounding projects that aim to make Bedford and beyond a thriving tourist destination. For those wondering how to get involved, there is a dedicated group looking to share knowledge and tools to get you tender ready. In this episode, we are joined by Lorna Leonard, Managing Director of LBS, and Kirsty Maynard, Commercial Director of THSP, who are instrumental in running BedX, a group dedicated to sharing knowledge and tools to help businesses get tender ready for Universal and beyond. Listen to our roundtable discussion as we dive into why BedX was created, its main drivers, how it can support local businesses and how you can get involved. You'll learn ·      Who are Kirsty and Lorna? ·      What is BedX? ·      What were the main drivers behind the creation of BedX? ·      What are the group's main aims? ·      What are Kirsty and Lorna's roles within the group? ·      How can businesses get involved with and benefit from BedX? ·      What can businesses be doing now to get tender ready for Universal?     Resources ·      Bedfordshire Chamber of Commerce - BedX ·      BedX Webinars ·      Tender Diagnostic ·      Kirsty Maynard LinkedIn ·      Lorna Leonard LinkedIn   In this episode, we talk about: [02:25] Episode Summary – Stephanie Churchman and Carly Mowbray are joined by Lorna Leonard (LBSv) and Kirsty Maynard (THSP) to discuss the creation of BedX, and how it aims to support businesses with tender preparation ahead of the Universal and related projects currently underway in Bedfordshire.   [01:25] Who are Kirsty and Lorna?: Kirsty is the commercial director at THSP. THSP work with businesses across health and safety, HR and compliance, helping organizations make sure they've got the right systems, processes and people in place to operate safely, professionally and compliantly. THSP have been in operation since 1992 and support any type of organisation, from construction to food brands, global luxury retailers, major transport organizations, and complex international businesses operating in highly controlled environments. Lorna is the managing director of LBS. LBS is a business solutions company supporting sophisticated start-ups and growing corporations with outsourced finance department services, direction and solutions. She set-up the business 14 years ago, and has worked with organisations of all sizes, from blue chip companies to micro businesses of only 1 or 2 people. Regular listeners may recall Lorna from a previous episode, she also shares many insightful posts on LinkedIn and is certainly worth a follow! [07:05] What is BedX? It's A business-led working group powered by the Bedfordshire Chamber of Commerce. It was created to help Bedfordshire businesses understand, prepare for and win work from the major investments coming into the region, in particular, the universal destinations and experiences, the Luton Airport expansion and other on-going linked projects. BedX's role is to connect, inform and prepare, but they don't lobby, they don't represent the developers and they don't do politics. They are simply there to help local businesses get ready. [07:45] What were the main drivers behind the creation of BedX? The Universal park is certainly the banner piece for the group. It's what all the big numbers are attached to, including 5 billion pounds worth of inward economic investment, 20,000 jobs created and the five years' worth of construction. However, that is just one part of the upcoming development going on in Bedfordshire. The big project is seeing more funding going into the area to support transport networks and other venues as investors seek to make Bedfordshire a place worth staying for more than just the Universal Park. Other projects include the expansion of the Wixams Train Station, construction at the Luton Hoo, the new Luton Town Football Club and a new Data Centre at Quest Pit. BedX was created in response to all of these projects, not just Universal. It's to help local businesses navigate these opportunities, as this small county has rarely seen such a seismic shift in the amount of investment going into the area. Even though the deadline for Universal Park is 5 years away, supply chains are looking for support now, which is why it's better to start preparing sooner rather than later. [10:20] Making Bedfordshire a play to stay: It's also not just about the venues, to prepare for the influx of tourists there will be more investment in housing and transport and related routes such as the work currently going on at the Black Cat roundabout. Kirsty states that the Bedford County Council have a scrutiny committee, which is currently labelled as the Universal Scrutiny Committee, and are in discussion about a viable tourist strategy for Bedfordshire. So, there is no doubt that there will be many more small projects going ahead within a very short timeframe to get the area ready. [12:00] How LBS's expertise is instrumental within BedX: Businesses that want to get involved may not know how to get working capital or access potential available funding, which is where Lorna's and LBS's expertise comes in to support BedX's aims. With tenders as highly valued as this, it can throw businesses through a loop if they're not prepared. Lorna shares a story where she explains that she used to work for a company that made point of purchase display equipment, this company had a US subsidiary called Anshauser-Busch, who own Budweiser. That subsidiary put through an order directly through to their factory, requesting a huge order be manufactured and delivered within 180 days. The cost of which was upwards of $2.7 million, which was due to suppliers 150 days prior to Lorna's company at the time being paid. It was their first time working with that subsidiary, so there was no guarantee on payment. The lessons they learned ended up shaping how the company operated going forward. All this to say, if you're bidding for high value contracts, you need to think about the opportunity from every perspective. [14:40] Be realistic about what you bid for: Kirsty states she is really passionate about ensuring businesses are trying to grow responsibly, so that they understand those terms in the bid and that they're realistic about the size of contract that they should be bidding for. If you're looking for more guidance in this area, Katie from Bids and Tender Support provided a webinar on this topic for BedX. It's available to view on-demand on BedX's website. [16:25] Lorna's role within BedX: Lorna reminds us that a lot of the Tier 1 contractors started out as 1 or 2 person businesses. She states that, honestly, 90% of the companies that BedX help will not be in direct contact with one of those Tier 1 contractors. However, supply chains are just that, a chain, there are many opportunities to get involved further down the line. Lorna feels as if that's a large part of her role, keeping businesses focused on the opportunities they can access within that supply chain. She is also keen to help all the local businesses understand how this is going to affect them, because whether they get involved in the various projects being built or not, the whole area is going to be affected regardless. She points out an example where they needed to source a large number of electricians, and it turns out that Bedfordshire simply doesn't have enough! So BedX is helping to make the wider community aware of training opportunities like this that can open doors for local businesses. [18:45] Other considerations for businesses operating in Bedfordshire: Lorna points out a few other concerns that people had about the on-going development in the area, including the possibility of local contractors putting prices up due to all the other projects. Timeframes may also be affected by both on-going work and the fact that more businesses will be getting involved in the area's development. [19:15] What are the group's main aims?: BedX's main aim is to be an opportunity exchange, they sit in the middle as a conduit between the opportunities and the Bedfordshire businesses and help to inform, educate and prepare to be a part of it. They are there to support preparation local businesses are able to access emerging supply chains as that waterfall flows down into tier 2 and 3 and even into 4 and 5 over the course of the project. If you're not sure which of those tiers you'd likely sit in, BedX have a helpful household checklist to find out. [20:20] Getting ISO Ready for Universal: Kirsty mentions that she's seen a lot of recent Pre-Qualification Questionnaires (PQQ's) request that bidding companies are certified to ISO 27001 Information Security. Many will be familiar with the requests for ISO 9001 (Quality Management), ISO 14001 (Environmental Management) and ISO 45001 (Occupational Health & Safety), but ISO 27001 seems to be a more recent pre-requisite. This is particularly the case for any Government contracts, with them stating either Cyber Essentials or ISO 27001 must be in place for any bidding businesses. Carly points out that ISO 27001 in many cases is just the first step, as you can strengthen this with supporting Standards such as ISO 27701 (Privacy Information Management) and ISO 27017 & ISO 27018 (Cloud Security), which can give you an advantage over your competitors. If you've not got any Standards in place, or are just starting out on your implementation journey, you can get in contact with Blackmores as we'd be happy to guide you towards successful certification. [25:00] Kirsty's role within BedX: Kirsty's role is focused on coordination, though all BedX organisers are volunteers, they still want to ensure that actions are followed up and completed. Kirsty has a project planning background and brings those skills to the group. She also plays a key part in tender and procurement readiness, as she has years of experience with PQQ's from her work within the construction industry. She knows what good looks like when bidding for work, and ensures that knowledge is being passed on to those looking to bid for Universal and other Bedfordshire development projects. A trait that many of the BedX team hold, Kirsty and Lorna especially, is the motivation to help people, and this group allows them to do so at scale. [27:45] How can businesses get involved with BedX?: You don't need to be a member of the Bedfordshire Chamber of Commerce to get involved. Currently BedX's main focus is on knowledge sharing, so their main output in webinars. They also have a tender diagnostic tool available, this is an online tool which takes just a few minutes to complete and will give you an idea of where you're already compliant and where there's work to be done. They have also had 1 in-person event, that being their official launch in April of 2026, which was attended by members from the Bedfordshire business community and representatives from Universal, Sizewell C and Luton Rising. They expect to run more in-person events in future, so keep an eye on their LinkedIn for news on these! Lorna hints at an upcoming event planned for September 2026

Cloud Security Podcast
Why Runtime Agents Are Replacing Static Posture Checks

Cloud Security Podcast

Play Episode Listen Later Jul 28, 2026 44:31


The attack window from the discovery of a vulnerability to its exploitation has shrunk to less than 24 hours and sometimes down to just 25 minutes. Is your security team prepared for the speed of AI-driven attacks?In this episode, Ashish sits down with Sarit Tager, who leads Cortex Cloud product management at Palo Alto Networks, to discuss why the post-Mythos era is forcing Cloud Security and AppSec out of their traditional silos. Sarit explains how AI coding agents prioritize generating code over securing it, which can sometimes result in flaws like accidentally deleting production databases within two weeks.We also explore how English has become the new primary programming language, effectively making everyone a potential developer. Sarit breaks down why relying solely on cloud posture management is no longer enough and why deploying active runtime agents is now mandatory to block real-time exploits.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠⁠⁠Sarit's Linkedin ⁠⁠Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠(00:00) Introduction: The Convergence of Cloud and AppSec(01:50) Sarit Tager's Background: From VP of Engineering to Palo Alto Networks(03:00) Why English is the New Programming Language(06:00) The Problem with LLMs Suggesting AppSec Fixes That Break Functionality(09:30) How AI Agents Can Accidentally Delete Production Databases(11:40) The Attack Window Shrinking to 25-30 Minutes(14:00) The Post-Mythos Fear and the Token Cost Challenge(16:30) Why You Must Deploy a Runtime Agent (Posture is Not Enough)(18:30) Why AI Coding Agents Put Security Second(24:00) Breaking the Silos: The Rise of Holistic Product Security(36:00) How AI Empowers Non-Experts to Investigate Across Security Domains(40:30) Fun Questions: 50 Countries, No Social Media, and Japanese FoodThank you to Palo Alto Networks for sponsoring this episode:Learn more about Palo Alto Networks Cortex Cloud.

LowOpsCast
#53 O caminho até se tornar Kubestronaut e especialista em Cloud Security com Igor Eulalio

LowOpsCast

Play Episode Listen Later Jul 28, 2026 60:54


O próximo papo é com Igor Eulalio Morgado Lopes (https://www.linkedin.com/in/igoreulalio/), Senior Solutions Engineer na Orca Security, ex-AWS e Sysdig, engenheiro de software, palestrante e uma das referências brasileiras quando o assunto é Cloud Native, Kubernetes e segurança.A história do Igor mostra que uma carreira sólida não é construída apenas com certificações ou boas oportunidades. Ela é resultado de curiosidade, estudo constante e da disposição para assumir desafios cada vez maiores.Ao longo da conversa, falamos sobre a transição da engenharia de software para plataformas cloud, a experiência trabalhando em empresas globais, a evolução da carreira até chegar à área de segurança e os aprendizados adquiridos ao longo dessa jornada.Também conversamos sobre:* A evolução da carreira em Cloud e Platform Engineering* A experiência na AWS, Sysdig e Orca Security* Segurança em ambientes Kubernetes e Cloud Native* O papel da IA na engenharia e na segurança* Certificações, comunidade e aprendiza

Relating to DevSecOps
Episode #084: No Humans Required: Agentic Attackers vs. Automated Defenders

Relating to DevSecOps

Play Episode Listen Later Jul 24, 2026 46:40


Send us Fan MailAI is changing the economics of cyberattacks by making them faster, cheaper, and easier to scale. In this episode of Relating to DevSecOps, Ken is joined by Conor Sherman, Chief Security Officer at Sysdig and host of the Zero Signal podcast, to explore what the rise of agentic threat actors means for defenders.Using the Jade Puffer ransomware attack as a real-world example, they discuss how autonomous attackers can discover vulnerabilities, compromise environments, move laterally, adapt their code, identify valuable data, and deploy ransomware with little human involvement.The conversation also looks at how defenders can respond through stronger security architecture, automated patching, real-time detection, automatic response, and AI-assisted modernization. Rather than replacing security fundamentals, AI can help teams apply them faster, handle difficult edge cases, and build more resilient systems.For security teams wondering where to begin, the message is simple: start small, automate one meaningful workflow, and build from there.

InfosecTrain
AI-Powered Cloud Security for Engineers

InfosecTrain

Play Episode Listen Later Jul 21, 2026 70:23


AI is changing cloud infrastructure, but how do you secure AI-assisted workflows? In this episode of InfosecTrain TechTalks: Real World Decoded, host Payal Pawar sits down with Cloud Architect Chitra Nair to discuss AI-powered cloud security.The "course titled" AWS Certified Solutions Architect Associate Training helps engineers master secure cloud design.

Cloud Do You Do?
A day at the breach: How to fix data sprawl and shadow sharing

Cloud Do You Do?

Play Episode Listen Later Jul 17, 2026 27:26


Who still has access to your company files? What happens to the sensitive files your team shares once a project is over? In this episode of the Cloud Do You Do podcast, Revolgy's Ashley talks with Matt Dubreuil from our partner, DoControl, about the hidden risks of data sprawl and shadow sharing in Google Workspace. Google Workspace makes file sharing incredibly easy. People just create a link and drop it in a chat to get work done. The problem is that access stays open long after a vendor contract ends or an employee leaves, leaving private company data sitting in personal emails and forgotten folders. Matt explains why built-in security tools make it hard to clean up this historical mess, and why putting strict blocks on file sharing doesn't actually solve the problem. In this episode: Shadow sharing: How everyday file sharing creates massive compliance and security blind spots over time. The limits of native tools: Why standard Google Workspace settings make it difficult to see what is currently exposed and fix it in bulk. A smarter way to fix it: Why sending a quick Slack message to ask a user about a risky file share works much better than just blocking them. Free data risk assessment: Find out exactly how many open links and former employees still have access to your workspace with a fast, non-disruptive scan that makes audits easier. Reach out directly to Ashley at ash@revolgy.com to get your free scan set up. Links & Resources Listen to DoControl's podcast, The Breach Seat Matt's podcast recommendation: How I Built This (specifically the episode with Jensen Huang of NVIDIA) Check out DoControl.io We are Revolgy - a global cloud partner. Our cloud engineers and architects provide professional and managed services for your projects on GCP and AWS. In a nutshell, we help to make life digital-native companies, SMBs and corporates in the cloud easier. Check our website revolgy.com for more information.Make sure to follow Revolgy on Spotify, Linkedin, and X.Thanks a lot for listening, and see you next time!

Command Control Power: Apple Tech Support & Business Talk
677: Beyond the Surface: Network Tools and Cloud Security

Command Control Power: Apple Tech Support & Business Talk

Play Episode Listen Later Jul 14, 2026 50:23


The hosts discuss several network and security topics, starting with UniFi's new "Device Supervisor" feature under Power and Resiliency to monitor device heartbeat and automatically recover silent devices, plus UniFi's move from UniFi Server to UniFi OS Server that may require a migration and re-adoption, pushing remaining sites off a Mac mini to cloud management. They revisit ethernet surge protection and grounding for outdoor cameras and consider alternatives like rack grounding, DIN rails, grounding rods, or using a sacrificial outdoor switch with fiber uplink. They mention Speedify for bonding multiple cellular/Wi‑Fi connections. The conversation shifts to email security: Microsoft's "impossible travel" detection and API reporting versus Google's weaker reporting, alongside odd Google reauthentication/password-change loops and MFA fatigue leading to a Google account breach. They cover deploying Claude Enterprise in healthcare with BAA needs and using Microsoft Purview/Defender to block pasting PHI into Claude, then discuss risks of fake password prompts, password managers (1Password vs LastPass), and end-user security training.

CISO Stories Podcast
Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226

CISO Stories Podcast

Play Episode Listen Later Jul 13, 2026 30:53


AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows, and sensitive data systems. Brent shares practical insight on AI governance, identity and access, cloud security controls, and the risks that emerge when experimentation moves into production. The conversation explores how security leaders can support innovation without losing visibility, accountability, or trust. Brent also breaks down the questions CISOs should be asking before AI tools scale deeper into the enterprise. Because AI may be unavoidable, but unmanaged AI risk is optional. Segment Resources: RapidScale's IT Talent Gap Report: https://try.rapidscale.net/the-talent-gap/ This segment is sponsored by Arctic Wolf. Visit https://cisostoriespodcast.com/arcticwolf to learn more about them! Visit https://cisostoriespodcast.com for all the latest episodes! Show Notes: https://cisostoriespodcast.com/csp-226

Cloud Security Podcast
The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

Cloud Security Podcast

Play Episode Listen Later Jul 9, 2026 42:44


Traditional SCA and SAST tools are notorious for drowning security teams in false positives, historically flagging nine out of ten alerts incorrectly. But while generative AI seems like a magic bullet, simply wrapping an out-of-the-box LLM around your code can result in confident hallucinations and astronomical costs extrapolating to as much as $52 million a year for a large enterprise using frontier models.In this episode, Ashish sits down with Harry Wetherald, CEO and co-founder of Maze, to discuss the evolution of AI-native AppSec and Cloud Security. Harry breaks down the critical difference between vulnerability reachability (is the code active?) and true exploitability (can an attacker actually trigger it logically?). He also explains why the historical walls between cloud security and application security teams are finally crumbling as AI acts as a perfect translator between the two domains.If your team is debating "Build vs. Buy" for AI security tools, this episode is essential. Harry shares the biggest red flags to watch out for in AI vendors (beware the "black box"), how to intelligently route across models to optimize token costs by 100x, and how a true "security brain" orchestrates multiple investigations to provide reliable context across your entire environment.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠⁠Harry's Linkedin ⁠Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction to AI in AppSec(01:50) Harry Wetherald's Background and the Founding of Maze(02:30) Reachability vs. Exploitability Explained(04:45) The "Build vs. Buy" Dilemma for AI Security Tools(08:30) Bridging the Gap Between Siloed AppSec and CloudSec Teams(11:30) Evaluating Out-of-the-Box LLMs vs. Specialized Security Tools(14:20) Solving the Historic AppSec False Positive Problem(18:50) AI Vendor Red Flags: The Danger of "Black Box" Products(20:50) How to Build a True AI-Native Security Architecture(24:45) The Hidden Cost of AI Models: Why Optimization is Crucial(28:00) When to Keep a Human in the Loop for Remediation(34:00) Building a "Security Brain" to Inform AI Coding Agents(39:20) The Launch of Maze Code for Deep Cloud and Code Investigations

RunAs Radio
Implementing Azure Policies with Barbara Forbes

RunAs Radio

Play Episode Listen Later Jul 8, 2026 35:42


How can Azure Policies help you? While at Techorama in Belgium, Richard sat down with Barbara Forbes to discuss how Azure Policies have evolved and the techniques sysadmins are using to improve security, cost controls, efficiency, and more. Barbara talks about how the default policies are designed to get folks started in Azure quickly - not necessarily optimally. And there are plenty of policy templates out there, but before you implement them, it's worthwhile to review each policy and ask the question "why?" Keeping good documentation on policies makes it easier to know intent, especially when it comes to changing them - and you'll need to change them! There are a number of ways to apply policies, but in the end, they are just more Infrastructure-as-Code, and so easily repeatable. Azure Policies are there to help you provide freedom with guardrails if you implement them carefully! Links Azure Policy Microsoft Cloud Security Benchmark Azure Management Groups Azure Bicep Terraform on Azure Recorded May 12, 2026

The InfoQ Podcast
Spite-Driven Engineering: A New Blueprint for Cloud Security in the AI Native Era

The InfoQ Podcast

Play Episode Listen Later Jul 6, 2026 40:44


In this episode, Alex Zenla (CTO/Co-founder, Edera) challenges the "laissez-faire" attitude toward modern infrastructure. She promotes "spite-driven development", building software to solve genuine technical pain points rather than passively accepting flawed abstractions, as a philosophy of improving the world of software. The discussion touches on the fragility of the current cloud-native stack, the security risks of multi-tenant Linux kernels, and the inefficiency of repurposing consumer-grade GPUs for AI workloads. Zenla also offers a pragmatic framework for the "AI-native" engineer: treat LLMs as symbiotic assistants for deep learning, not replacements for system-level expertise. Read a transcript of this interview: https://bit.ly/3QZQhxc Newsletter: Subscribe to the Software Architects' Newsletter, a monthly roundup of the patterns and technologies senior practitioners are working through, with the news and lessons from people doing the work: https://www.infoq.com/software-architects-newsletter InfoQ Online Certification Programs: 5-week online cohorts for senior engineers and architects, built around QCon talks. Programs now cover software architecture, AI engineering, and organizational architecture. Each week you join a four-hour live session with a confidential peer group of practitioners from other companies, apply frameworks from QCon talks to the decisions you're making at work, and earn an InfoQ certification. You leave with new approaches, or confirmation that the calls you're already making are the right ones. Learn more: https://certification.qconferences.com/ Upcoming Events: QCon San Francisco 2026 (November 16-20, 2026) https://qconsf.com/ QCon London 2027 (April 13-16, 2027) https://qconlondon.com/ The InfoQ Podcasts: Weekly conversations with senior software leaders about how they build systems and teams, including what they'd do differently. Listen to all our podcasts and read interview transcripts: The InfoQ Podcast: https://www.infoq.com/podcasts/ Engineering Culture Podcast by InfoQ: https://www.infoq.com/podcasts/#engineering_culture Generally AI: https://www.infoq.com/generally-ai-podcast/ Follow InfoQ: Mastodon: https://techhub.social/@infoq X: https://x.com/InfoQ LinkedIn: https://www.linkedin.com/company/infoq/ Facebook: https://www.facebook.com/InfoQdotcom Instagram: https://www.instagram.com/infoqdotcom/ YouTube: https://www.youtube.com/infoq Bluesky: https://bsky.app/profile/infoq.com Write for InfoQ: Share what you've learned building software with a community of senior practitioners, and get your work in front of the people who read InfoQ. https://www.infoq.com/write-for-infoq

Cracking Cyber Security Podcast from TEISS
teissTalk: How AI is forcing a redesign of security itself

Cracking Cyber Security Podcast from TEISS

Play Episode Listen Later Jul 2, 2026 46:02


Why only 5% of organisations have full visibility into AI tool usage - what a credible approach to access controls and runtime behavioural monitoring looks likeMoving beyond policy intent to architecture that governs AI workloads, autonomous agents and machine-driven workflowsMoving from fragmented controls to unified, policy-driven security architectures that deliver consistent enforcement across hybrid and multi-cloud environmentsJonathan Craven, Host, teissTalkhttps://www.linkedin.com/in/jonathanbcraven/Satyam R., Director of Information Security & DevOps, BAMKOhttps://www.linkedin.com/in/hackersatyamrastogi/Paul Barbosa, V P & General Manager, Cloud Security & SASE, Check Point Softwarehttps://www.linkedin.com/in/paulbarbosa/

The Future of ERP
Episode 91: Always Watching: 24/7 Security Monitoring and the Shared Responsibility Model

The Future of ERP

Play Episode Listen Later Jul 1, 2026 22:08


Moving ERP to the cloud doesn't mean security becomes someone else's problem. Discover how leading organizations balance shared responsibilities, AI-powered monitoring, and cyber resilience to protect the business around the clock.=====As ERP systems become the digital core of modern enterprises, security can no longer be treated as an afterthought. In this episode, EY's Michelle DeLiberty joins Richard Howells and Öykü Ilgar to explore 24/7 security monitoring, the realities of the shared responsibility model, and the growing impact of AI on cybersecurity. Learn where organizations often get security ownership wrong, how to improve cyber resilience, and what the future of ERP security looks like.⁠⁠⁠⁠⁠⁠⁠⁠⁠Download Episode Transcript⁠⁠⁠⁠⁠⁠⁠⁠⁠Useful Links: SAP Cloud ERPEY-SAP AllianceFollow Us on Social Media!SAP S/4HANA Cloud ERP: ⁠⁠⁠⁠⁠LinkedIn⁠⁠⁠⁠⁠=====Guest: Michelle DeLiberty, EYHost 1: Richard Howells, SAPRichard Howells has been working in the Supply Chain Management and Manufacturing space for over 30 years. He is responsible for driving the thought leadership and awareness of SAP's ERP, Finance, and Supply Chain solutions and is an active writer, podcaster, and thought leader on the topics of supply chain, Industry 4.0, digitization, and sustainability.Follow Richard Howell on ⁠⁠⁠⁠⁠⁠⁠⁠⁠LinkedIn⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠X⁠⁠⁠⁠⁠⁠⁠⁠⁠Host 2: Oyku Ilgar, SAPOyku Ilgar is a marketer and thought leader specializing in SAP's digital supply chain and ERP solutions since 2017. As a marketer, blogger, and podcaster, she creates engaging content that highlights innovative SAP technologies and explores key topics including business trends, AI, Industry 4.0, and sustainability.Follow Oyku Ilgar on ⁠⁠⁠⁠⁠⁠LinkedIn⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠SAP Community⁠⁠⁠⁠⁠⁠=====Key Topics: Cloud ERP, Cybersecurity, Security Monitoring, Shared Responsibility Model, SAP Security, AI Security, Cyber Resilience, Cloud Security, ERP Transformation, Risk Management, Identity Access Management, Threat Detection, Security Operations, Incident Respo.

Cybercrime Magazine Podcast
Mitiga Mic. Beyond Standard Data Lakes. Amir Gabrieli & Yosi Navaro, Mitiga.

Cybercrime Magazine Podcast

Play Episode Listen Later Jun 30, 2026 24:58


Amir Gabrieli, Product Executive, Cloud Security at Mitiga and Yosi Navaro, Data Engineering Team Lead at Mitiga, join host Brian Contos in this episode of Mitiga Mic to discuss their experiencing building the backbone of zero impact SOC. This series is brought to you by Mitiga, the leader in Agentic Runtime Security for cloud, SaaS, and AI, delivering Zero-Impact Breach Prevention. To learn more about our sponsor, visit https://www.mitiga.ai.

The Shared Security Show
Jay Beale on Kubernetes, DEF CON, and AI Attack Paths

The Shared Security Show

Play Episode Listen Later Jun 29, 2026 38:20 Transcription Available


This week on Shared Security, Tom and Kevin sit down with Jay Beale — founder of InGuardians, long-time Black Hat trainer, creator/contributor behind Kubernetes security training, and part of the team behind the DEF CON Kubernetes CTF. Jay shares stories from decades of offensive security work, including the time Tom hired him for a physical penetration test and Jay somehow ended up inside a call center instead of stuck in the lobby. The crew also digs into what makes good security training, why Kubernetes is such a natural platform for both defenders and attackers to understand deeply, and how the DEF CON Kubernetes CTF is designed to be welcoming for both competitors and learners. The episode closes with a practical look at AI infrastructure risk. Jay explains how production AI stacks running on Kubernetes can be attacked like any other cluster — and how modifying a vector database behind a RAG system can turn indirect prompt injection into a persistent, high-impact attack path.** Links mentioned on the show **Jay's Black Hat USA Course: Agentic AI-aided Kubernetes Attack and Defensehttps://blackhat.com/us-26/training/schedule/index.html?day=4daysattue#agentic-ai-aided-kubernetes-attack-and-defense-51318Jay Beale on LinkedInhttps://www.linkedin.com/in/jaybeale/InGuardianshttps://www.inguardians.com/DEF CONhttps://defcon.org/** Watch this episode on YouTube **https://youtu.be/aMHk62dprDA** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

Government Information Security Podcast
How Cloud Security Risks Grow With Home-Based Care

Government Information Security Podcast

Play Episode Listen Later Jun 29, 2026


Data Breach Today Podcast
How Cloud Security Risks Grow With Home-Based Care

Data Breach Today Podcast

Play Episode Listen Later Jun 29, 2026


Banking Information Security Podcast
How Cloud Security Risks Grow With Home-Based Care

Banking Information Security Podcast

Play Episode Listen Later Jun 29, 2026


Healthcare Information Security Podcast
How Cloud Security Risks Grow With Home-Based Care

Healthcare Information Security Podcast

Play Episode Listen Later Jun 29, 2026


Careers Information Security Podcast
How Cloud Security Risks Grow With Home-Based Care

Careers Information Security Podcast

Play Episode Listen Later Jun 29, 2026


Info Risk Today Podcast
How Cloud Security Risks Grow With Home-Based Care

Info Risk Today Podcast

Play Episode Listen Later Jun 29, 2026


Credit Union Information Security Podcast
How Cloud Security Risks Grow With Home-Based Care

Credit Union Information Security Podcast

Play Episode Listen Later Jun 29, 2026


DailyCyber The Truth About Cyber Security with Brandon Krieger
Infrastructure Resilience & Business Risk | DailyCyber 294 with Ben Wilcox

DailyCyber The Truth About Cyber Security with Brandon Krieger

Play Episode Listen Later Jun 28, 2026 62:31


Infrastructure Resilience & Business Risk | DailyCyber 294 with Ben Wilcox   Artificial intelligence is reshaping enterprise technology, accelerating innovation while introducing new security, governance, and operational challenges.   In this live episode of DailyCyber, Brandon Krieger sits down with Ben Wilcox, CTO & CISO at ProArch, to discuss how organizations can securely adopt AI, manage infrastructure risk, and prepare for the next generation of cyber threats.   As both CTO and CISO, Ben offers a unique perspective on balancing technology enablement with cybersecurity leadership. His work focuses on helping organizations build secure, resilient environments while navigating the complexities of AI, cloud infrastructure, compliance, and modern cyber risk. Recent discussions from Ben have focused heavily on AI governance, agent visibility, DevSecOps maturity, and the security implications of rapidly accelerating AI adoption.    Topics covered: • AI security and governance challenges • Shadow AI and organizational risk • Infrastructure resilience and cloud security • Balancing innovation with cyber risk management • Emerging AI-driven threat landscapes • Security leadership in the AI era • What businesses should do before scaling AI initiatives   Guest: Ben Wilcox — CTO & CISO, ProArchhttps://www.linkedin.com/in/ben-wilcox/https://www.proarch.com   Host: Brandon Krieger — CEO & vCISO Advisorhttps://www.linkedin.com/in/brandonkriegerhttps://www.DailyCyber.ca  

No Password Required
No Password Required Podcast Episode 74 - Shane Tews

No Password Required

Play Episode Listen Later Jun 22, 2026 51:54


Shane Tews — Non-Resident Senior Fellow at AEI and the person who explained the internet to Capitol Hill No Password Required Season 7: Episode 7 – Shane Tews Shane Tews is a Non-Resident Senior Fellow at the American Enterprise Institute, where she focuses on cybersecurity, privacy, artificial intelligence, and internet governance. She is also President of Logan Circle Strategies, a strategic advisory firm working at the intersection of technology and policy. Before her think tank work, Shane helped introduce modems to the George H.W. Bush White House, walked the halls of Capitol Hill explaining the internet to blank-staring legislators, and spent years at VeriSign helping shape the foundational frameworks of how the internet would be governed. In this episode, Shane traces her unlikely path from the Bush administration to becoming one of Washington's most trusted voices on tech policy. She breaks down why regulating outcomes rather than inputs is the only sensible approach to technology governance, why the US and EU are operating from fundamentally different innovation philosophies, and why a national privacy bill is long overdue. She also explains why most organizations and individuals are far less protected than they think and why nobody knows who to call when something goes wrong. Jack Clabby and co-host Kayley Melton talk with Shane about legacy system vulnerabilities, the cybersecurity implications of agentic AI, and what policymakers absolutely must get right over the next decade. She also reflects on what the CISA reauthorization limbo means for companies that don't even know they've lost liability protection. In the Lifestyle Polygraph, Shane reveals she has 20,000 emails across eight accounts, admits she fakes laughs at bad jokes out of Midwestern politeness, shares her obsession with The Bear and Peaky Blinders, and tells us about her children's book project using Google Omni called "Shane on a Train." Follow Shane on LinkedIn and on X at @ShaneTews. Find her work at AEI.org and TechPolicyDaily.com. No Password Required is presented by ThreatLocker   In this episode: Shane's path from the George H.W. Bush White House to becoming Capitol Hill's go-to internet explainer (00:34 - 02:22) Why the Clinton-era multi-stakeholder model got internet governance right and what that means for policy today (04:40 - 06:13) The case for a national privacy bill and why 50 state standards aren't working (07:24 - 09:27) What AEI covers and how Shane thinks about riding the top of the wave across the entire tech policy stack (09:35 - 11:23) Legacy systems, vendor debt, and why outdated software is the easiest entry point for bad actors (11:30 - 13:34) The gap between how protected people think they are and how exposed they actually are, including a generational perspective on MFA (14:07 - 16:25) The biggest disconnect between everyday cyber reality and the policy world (16:59 - 20:35) Government readiness for a major cyber attack and why most people don't have a plan (20:54 - 22:32) How the US and EU innovation philosophies differ and why Europe's banking system is the real tech problem (22:41 - 25:38) The DeepSeek false narrative and where the US is leading vs. reacting on AI (25:45 - 29:21) The shift from AI features to AI coordination and what agentic AI means for cybersecurity permissions (29:28 - 32:16) What policymakers must get right on AI over the next 10 years (32:25 - 34:11) The Lifestyle Polygraph: inbox chaos, fake laughs, The Bear, and Shane on a Train (00:04 - 12:48)   Timestamp Highlights: (00:34) Shane's origin story: modems at the White House and blank stares on the Hill (04:40) Why the internet got policy right early on and what we can learn from it (07:24) The case for harmonizing breach standards with a national framework (11:30) Legacy systems and vendor debt as the easiest attack vectors (14:07) The real gap between how protected people think they are and how exposed they actually are (20:54) Government cyber readiness: do you know who to call when something goes wrong? (22:41) US vs. EU innovation: why Europe's banking system is the real tech problem (29:28) Agentic AI and the cybersecurity risks of permissions you forgot you gave (32:25) What policymakers must get right on AI over the next decade (06:44) Shane on a Train: using Google Omni to write a children's book series   Resources & Links: AEI.org — Shane's think tank home base TechPolicyDaily.com — Daily tech policy coverage ThreatLocker — Supporter of this podcast Cyber Florida — The Mother Ship  

AWS re:Think Podcast
Episode 51: Rethinking Cloud Security in the Age of Zero-Days and AI

AWS re:Think Podcast

Play Episode Listen Later Jun 10, 2026 42:20


Modern cloud environments are evolving faster than traditional security models can keep up. In this episode, we sit down with Yarin Pinyan, VP Products at Upwind, to explore how real-time runtime visibility and behavioral baselining are reshaping how organizations detect and respond to threats, especially zero-day and supply chain attacks that emerge before signatures or CVEs exist. We'll also discuss how AI is enabling a new generation of cloud security, where detection, investigation, and response happen continuously and automatically. The conversation highlights how organizations can reduce risk, improve operational efficiency, and protect critical workloads in dynamic, cloud-native environments.AWS MP offering: https://aws.amazon.com/marketplace/pp/prodview-ff3am62vjukrw?sr=0-1&ref_=beagle&applicationId=AWSMPContessaWebsite: https://www.upwind.io/Customer success story: https://www.upwind.io/case-studiesAWS Hosts: Nolan Chen & Ashok MahajanEmail Your Feedback: rethinkpodcast@amazon.com

CISSP Cyber Training Podcast - CISSP Training Program
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 4, 2026 24:26 Transcription Available


Send us Fan MailThe breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach private repository files and ultimately an NPM token that could enable a supply chain attack.From there, we zoom out to the bigger cloud security problem: non-human identities. Service accounts, API keys, and OAuth tokens multiply fast, and they are frequently overprivileged, poorly tracked, and left active long after an integration is retired. We also talk about why SaaS-to-SaaS connections are so hard to secure, and why agentic AI makes visibility even more urgent. If you do not know what systems are connected, what data crosses those links, and who owns the risk, you are effectively trusting an invisible tunnel into your environment.To make this actionable, we lay out a four-phase third-party risk management (TPRM) framework you can apply immediately: build a vendor and integration inventory with tiering, run real due diligence (SOC 2 Type II, ISO 27001, data access scope, subprocessors and fourth parties), lock protections into contracts (DPA language, right to audit, breach notification expectations), then enforce ongoing monitoring and governance with quarterly token reviews, logging, and incident response playbooks. If you are studying for the CISSP, you will also see exactly how this maps to Domain 1, Domain 3, Domain 4, and Domain 5.Subscribe for more practical CISSP training, share this with a teammate who owns vendor approvals, and leave a review so more security pros can find it. What is the one integration you would audit first?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Defense in Depth
What Does the Next Generation of Cloud Security Look Like?

Defense in Depth

Play Episode Listen Later May 28, 2026 33:22


All links and images can be found on CISO Series We know human-paced security controls can't be applied to autonomous AI agents. So what needs to change with CNAPP and cloud security? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Dan Benjamin, vp product - data, identity, and AI security, Palo Alto Networks. In this episode: The detection ceiling A category gap, not a feature gap Resilience by design An insider threat with no face A huge thanks to our sponsor, Palo Alto Networks Cortex Cloud unifies code, cloud, and SOC on a single data, risk, and control plane — giving teams the context, workflows, and agentic intelligence to turn risk into resolution. Native AI agents investigate and act within enterprise guardrails, delivering real-time protection from workload to network edge. Cloud security that outpaces machine-speed threats. Visit Palo Alto Networks and search cortex cloud.  

Cloud Security Podcast by Google
EP279 Native Cloud Security: Is 'Good Enough' Actually Winning?

Cloud Security Podcast by Google

Play Episode Listen Later May 25, 2026 29:02


Guests: Gal Ordo, Co-founder & CPO @ Native  Topics:  In Episode 186, we debated 'Native vs. Third-Party' as a binary choice. Native seems to be a third-party vendor whose entire existence depends on the belief that cloud-native controls are superior. Does your platform validate the 'Cloud Provider' side of the debate (that their controls are enough), or does the fact that you exist prove the 'Third-Party' side (that native interfaces aren't enough)? A key argument against native controls is an AWS WAF and a Google Cloud Armor don't behave the same way. If your tool manages native controls across multi-cloud, how do you handle the 'lowest common denominator' problem? Do you dumb down the policy to fit all clouds, or do you expose the unique complexity of each one? GuardDuty and SCC produce similar but meaningfully different results. How do you abstract across that so an analyst or IR team isn't having to dig into the exact meaning of the different JSON fields in their output? We often say native tools are 'good enough' for 80% of use cases but lack the depth of specialized third-party vendors (like a dedicated CNAPP or DLP). By betting your company on orchestrating native controls, are you effectively betting that 'good enough' is the future of the market? What happens when a customer needs a feature that the CSP hasn't built yet? What fraction of your users are taking this from a "I'm 80% this one cloud, I need great coverage there and good enough elsewhere" vs "I'm truly multi-cloud" or even scarier "I have a workload that is active spanning clouds"?  Do your customers push you towards helping with the kinds of SaaS platforms that SSPM vendors cover? If AWS and Google Cloud suddenly decided to make their native security UIs perfect and unified tomorrow, would your company cease to exist? Or is the complexity of the cloud strictly increasing, guaranteeing you job security forever? Related: Video version EP186 Cloud Security Tools: Trust the Cloud Provider or Go Third-Party? An Epic Debate, Anton vs Tim EP160 Don't Cloud Your Judgement: Security and Cloud Migration, Again! The Great Cloud Security Debate: CSP vs. Third-Party Security Tools native.security blog

Smart Software with SmartLogic
Cloud Fragility & Distributed Systems with Somtochi Onyekwere

Smart Software with SmartLogic

Play Episode Listen Later May 21, 2026 46:06


In Elixir Wizards S15E04, Charles Suggs and Emma Whamond are joined by Somtochi Onyekwere, a software engineer at Fly.io and contributor to the Corrosion distributed database project, to talk about distributed systems, infrastructure resilience, and the growing fragility of centralized cloud platforms.   We discuss what recent outages across major providers reveal about modern infrastructure and why more teams are starting to rethink assumptions around reliability, failover, and system design. Somtochi explains how Fly.io approaches geographic distribution, eventual consistency, and replication across nodes, along with the trade-offs that come with building systems this way.   The conversation explores CRDTs (Conflict-free Replicated Data Types), consensus, split-brain prevention, and what actually happens when distributed systems fail in production. We also talk about testing strategies, rollback planning, property-based testing tools, and how teams can reduce blast radius when things inevitably go wrong.   Along the way, we discuss AI infrastructure, sandboxing AI agents, and how newer workloads may add pressure to already centralized systems. The episode closes with practical advice for developers who want to build more resilient applications without over-complicating their architecture. Topics Discussed in this Episode: Corrosion and distributed database replication Centralized cloud fragility and recent outage patterns Distributed systems versus traditional cloud architectures Multi-region deployment strategies for Phoenix applications CRDTs and conflict resolution in distributed systems Eventual consistency versus strict consistency tradeoffs Consensus, leader election, and split-brain prevention Testing failover and recovery scenarios Property-based testing and Antithesis Rollback planning for database schema migrations Reducing blast radius through system isolation Health checks and blue-green deployment strategies Fly Proxy request routing and replay behavior Cross-region synchronization and replication challenges Single points of failure inside “redundant” systems Backup restoration testing and disaster recovery planning Network partitions and failure handling in production Infrastructure monitoring and operational visibility AI infrastructure workloads and operational strain Sandboxing and securing AI agents Sprites and AI workflows at Fly.io Latency improvements from geographic distribution Distributed systems tradeoffs in real-world environments Transitive dependency failures across cloud providers Practical resilience strategies for modern engineering teams Links Mentioned: https://fly.io https://github.com/superfly/corrosion https://docs.gitops.weaveworks.org/ FluxCD https://fluxcd.io/ Fly.io Stateful Sandbox Environments https://sprites.dev/ Cloudflare Workers AI Inference Platform https://www.cloudflare.com/products/workers-ai/ “An AI Agent Just Destroyed Our Production Data. It Confessed in Writing” Twitter post from PocketOS founder: https://x.com/lifeof_jer/status/2048103471019434248 Oct 2025 AWS Outage https://www.theguardian.com/technology/2025/oct/24/amazon-reveals-cause-of-aws-outage Dec 2025 Cloudflare Outage https://www.theguardian.com/technology/2025/dec/05/another-cloudflare-outage-takes-down-websites-linkedin-zoom July 2025 Crowdstrike Outage https://www.ibm.com/think/news/recent-crowdstrike-outage-what-you-should-know March 2026 Stryker Cyber Attack https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html https://aws.amazon.com/ https://cloud.google.com/ https://azure.microsoft.com/en-us https://fly.io/docs/elixir/ CRDTs!! https://smartlogic.io/podcast/elixir-wizards/s13-e03-local-first-liveview-svelte-pwa/ https://antithesis.com/docs/resources/property_based_testing/ https://hex.pm/packages/proper

Risky Business
Soap Box: Where does AI fit into cloud security?

Risky Business

Play Episode Listen Later May 15, 2026 33:37


In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler. Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it's now a venture-funded cloud security business. In this interview Toni talks us through how AI is changing the game for him as an open source project owner, and as a vendor. In short, reports of the death of IT and security tooling at the hands of frontier models have been greatly exaggerated. This episode is also available on Youtube. Show notes

We Talk Cyber
Give Me 45 Min and I'll Show You How to Go from 0 to 6-Figures

We Talk Cyber

Play Episode Listen Later May 5, 2026 43:36


The cybersecurity industry in 2025 is evolving faster than ever. While companies lay off thousands, they're also desperately hiring cybersecurity leaders who can bridge AI, business, and security. In this ultimate tutorial, I share 20+ years of hard-earned lessons that took me from a $40K coder to a $250K cybersecurity leader and consultant.What You'll Learn: how to pivot before everyone else in cybersecurity, why skills beat credentials, the AI edge you MUST develop right now, leadership & communication skills that fast-track promotions, 5 career paths (Hacker, IAM, Cloud Security, GRC/Privacy, CISO), real strategies that helped me 10x my career. Whether you're entry-level, mid-career, or aiming for CISO, this roadmap is designed to help you secure, scale, and lead.Looking to go from chaos and unpredictability to resilience in the world of AI? Start here with The Predictability Factor newsletter at The Monica Talks Cyber (https://www.monicatalkscyber.com).

Blue Security
Copy Fail, Claude Security, and Microsoft's AI Defense Playboo

Blue Security

Play Episode Listen Later May 5, 2026 40:39


SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss significant topics in cybersecurity, including the discovery of a critical Linux vulnerability known as Copy Fail, the introduction of Cloud Security in public beta, and Microsoft's comprehensive AI security strategy. They explore how AI is revolutionizing vulnerability scanning, the implications of the Copy Fail bug, and the proactive measures organizations can take to enhance their security posture. The conversation emphasizes the importance of timely patching and the evolving landscape of cybersecurity driven by AI advancements.----------------------------------------------------YouTube Video Link: https://youtu.be/5Hrt9QdI7bY----------------------------------------------------Documentation: https://www.theverge.com/tech/922243/linux-cve-2026-3141-copy-fail-exploithttps://copy.failhttps://claude.com/blog/claude-security-public-betahttps://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Blue Security
Copy Fail, Claude Security, and Microsoft's AI Defense Playbook

Blue Security

Play Episode Listen Later May 5, 2026 40:33


SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss significant topics in cybersecurity, including the discovery of a critical Linux vulnerability known as Copy Fail, the introduction of Cloud Security in public beta, and Microsoft's comprehensive AI security strategy. They explore how AI is revolutionizing vulnerability scanning, the implications of the Copy Fail bug, and the proactive measures organizations can take to enhance their security posture. The conversation emphasizes the importance of timely patching and the evolving landscape of cybersecurity driven by AI advancements.----------------------------------------------------YouTube Video Link: https://youtu.be/5Hrt9QdI7bY----------------------------------------------------Documentation: https://www.theverge.com/tech/922243/linux-cve-2026-3141-copy-fail-exploithttps://copy.failhttps://claude.com/blog/claude-security-public-betahttps://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Cloud Security Podcast
The Rise of Agentic Cloud Security: Code-to-Cloud Shrinks to 3 Days

Cloud Security Podcast

Play Episode Listen Later Apr 21, 2026 26:53


Is your cloud security strategy ready for the "messy middle" of AI adoption? With developers pushing code from inception to production in under three days using "vibe coding," and adversaries capable of exfiltrating data in just 25 minutes, human-led security is no longer fast enough .In this episode, Ashish sits down with Elad Koren from Palo Alto Networks (Cortex Cloud) to discuss the shift toward Agentic Cloud Security. Elad spoke to us about why bolting an AI chatbot onto legacy security tools doesn't work, and why you must run AI directly where your data lies . Elad shared a real-world case study: an organization that rapidly spun up an "internal" AI workload to test the market, only to have a red team discover it was exposed to the public internet with zero authentication .If you want to know how the role of cloud security practitioners will evolve from manual analysts to AI orchestrators within the next five years, listen to this episode.Guest Socials -⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Elad's LinkedinPodcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction(02:50) Who is Elad Koren? (Palo Alto Networks / RSA Security) (04:00) The Explosion of "Vibe Coding" and AI Applications (05:10) How CNAPP is Evolving from Posture to Active Protection (07:20) The New Threat Model: 25-Minute Exfiltration Windows (09:30) What is "Agentic Cloud Security"? (Fighting Machines with Machines) (11:40) The "Messy Middle" and the Evolution of Security Practitioners (14:30) Platformization: Why Security Can No Longer Survive in Silos (16:50) Blurring the Lines Between Cloud and Enterprise Estates (18:20) Case Study: An Unauthenticated "Internal" AI Workload Exposed (20:30) How AI is Shrinking Code-to-Cloud Cycles to 3 Days (22:30) The Coming Crisis: Security Token Budgets vs. Speed (23:30) Fun Questions: Kangaroo Jerky Tasting (25:20) Hobbies & Family: Cycling, Audiobooks, and Fatherhood (26:30) Favorite Food: Thai Cuisine in the Bay Area Resources spoken about during the episode:- Cortex Cloud- Symphony 26 - The Agentic SOC Summit- Palo Alto Networks Linkedin Page- Elad's Linkedin

ITSPmagazine | Technology. Cybersecurity. Society
Post-RSAC Conference 2026 Recap: Agentic AI, Data Sovereignty, and the New Security Perimeter | A Brand Highlight Conversation with Thyaga Vasudevan, EVP, Product of Skyhigh Security

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 15, 2026 12:15


If you walked RSAC Conference 2026 expecting incremental updates, you left with something very different. Thyaga Vasudevan, EVP, Product at Skyhigh Security, describes this year as unlike any prior conference -- not because of a single announcement, but because the customers asking how to secure agentic AI were the same customers already building and deploying it. The urgency was real, immediate, and universal across organization sizes. The defining theme was agentic security. Vasudevan frames it around three core questions every security team now needs to answer: who is acting (agent identity), what are they accessing (data and APIs), and what are they trying to do (actions and permissions). The ChatGPT launch in November 2022 marked a generational shift -- and at RSAC 2026, Skyhigh Security observed that the industry had moved decisively from data-in and data-out protection to governing the actions of autonomous agents themselves. Data sovereignty was the other major conversation thread, driven by geopolitical realities and tightening regional data regulations. Vasudevan spoke with CISOs from financial services, healthcare, public sector, and not-for-profit organizations, each with different infrastructure approaches -- from on-prem data centers to sovereign clouds to full cloud deployments -- but all navigating the same fundamental challenge. DSPM and hybrid architectures are no longer optional for global enterprises. And quietly but significantly, browser security emerged as a front-and-center priority, reflecting the browser's growing role as a primary cloud endpoint. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Thyaga Vasudevan, EVP, Product, Skyhigh Security LinkedIn: https://www.linkedin.com/in/thyaga12/ RESOURCES Skyhigh Security: https://www.skyhighsecurity.com RSAC Conference 2026 Coverage: https://itspmagazine.com/rsac26 Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Thyaga Vasudevan, Skyhigh Security, Sean Martin, Marco Ciappelli, brand story, brand marketing, marketing podcast, brand highlight, agentic AI security, data sovereignty, SSE, Security Service Edge, DSPM, zero trust, browser security, cloud security, RSAC Conference 2026, RSAC 2026, AI agent security, MCP security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Cloud Security Podcast by Google
EP272 More Than Just Packets: Is NDR a "First-Class" Cloud Security Control?

Cloud Security Podcast by Google

Play Episode Listen Later Apr 13, 2026 34:11


Guest: Raja Mukerji, Co-Founder & Chief Scientist, Extrahop Rafal Los, VP of Client Relations and Strategic Initiatives, Extrahop Topics: Is Network Detection and Response (NDR) coming back after being shoved to the side by EDR a bit? Is this for real? What's the value proposition of NDR in 2026, because some people still don't understand it? How does NDR apply to the world of WFH, cloud/SaaS, encryption, high bandwidth, etc? Is the value of NDR the same, or different, when it comes to public (or private) cloud? How does NDR fill visibility gaps that identity and agent-based solutions cannot? What does NDR offer that built-in cloud security tooling (as of right now) does not? Would you call NDR a key cloud security control? Does NDR help with shadow AI? NDR elephant in the room is sometimes cost. How does cost change the value prop when compared to on-premise or physical infrastructure? Resources: Video version EP267 AI SOC or AI in a SOC? Cutting Through Hype, Pricing Models, and SIEM Detection Efficacy with Raffy Marty EP113 Love it or Hate it, Network Security is Coming to the Cloud EP154 Mike Schiffman: from Blueboxing to LLMs via Network Security at Google EP115 How to Approach Cloud in a Cloudy Way, not As Somebody Else's Computer? EP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI) "The GC+CISO Connection Book" book

Bare Knuckles and Brass Tacks
AI Security Is Just as vague as "Cloud Security", but With Sparkle Emojis

Bare Knuckles and Brass Tacks

Play Episode Listen Later Apr 6, 2026 40:41


Amber Bennoui calls it like she sees it: most of what gets sold as "AI security" is just cloud security with sparkle emojis on it.She's co-founder of AISECA, a veteran product leader, and a more honest voices in a space that isn't exactly famous for honesty right now.We sat down with her fresh off RSA, and the conversation got very real:The real AI risk isn't the sci-fi scenario. It's the DevOps engineer at a 900-person company arguing they should be able to send commands via a remote control feature, with three security people in the building who don't even know the conversation is happening. It's the tools already embedded in software your finance and HR teams use every day, making decisions nobody gave explicit permission for.Amber's argument is simple and uncomfortable: most organizations have a discoverability problem they haven't solved yet, and vendors are selling dashboards to people who don't even know what's running in their own house. That's not security. That's theater.We also got into what it actually takes to build something vendor-agnostic and practitioner-led when the companies with the biggest budgets are also the ones racing to define what AI security means. And whether the tension between speed and safety is even something security teams get to resolve — or whether that decision has already been made for them.Mentioned: MIT Paper, "Sycophantic Chatbots Cause Delusional Spiraling, Even in Ideal Bayesians"

ITSPmagazine | Technology. Cybersecurity. Society
Securing Data Across the Hybrid Enterprise | A Brand Spotlight at RSAC Conference 2026 with Thyaga Vasudevan, EVP, Product of Skyhigh Security

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 2, 2026 22:12


Most organizations are not cloud-only and, according to Thyaga Vasudevan, EVP, Product at Skyhigh Security, they are unlikely to become cloud-only anytime soon. Legacy on-prem applications, new AI workloads kept inside the firewall, and the growing cost of routing all enterprise traffic through a cloud proxy are pushing organizations toward a hybrid security architecture -- one that needs to enforce consistent policy regardless of where the traffic goes or where the data lives. Skyhigh Security announced three major innovations at RSAC Conference 2026: a next-generation SSE hybrid platform with a single console managing on-prem and cloud enforcement under one policy construct; a patent-pending browser security capability that injects JavaScript controls dynamically into existing browser sessions without requiring a dedicated enterprise browser; and the general availability of its DSPM platform, which uniquely provides visibility into both data at rest and data in motion by combining proxy-layer inspection with posture management. The browser has quietly become the most important enforcement point in the enterprise. As AI tools like Microsoft Copilot operate through web socket connections that cannot be intercepted at the server level, security controls have to reach inside the browser session itself. Vasudevan describes a seamless approach: because Skyhigh Security already sees the traffic flowing through its SSE cloud, it can inject controls at the browser layer without asking employees to change the tools they use. Data sovereignty is no longer a compliance footnote -- it is an architectural driver. Vasudevan walked through a global manufacturer operating simultaneously in Europe, the United States, and China. Each region carries different regulatory constraints, different trust postures for cloud infrastructure, and different performance requirements. Skyhigh Security's hybrid platform handles all three scenarios under the same management framework and the same policy construct. The customer chooses where enforcement happens -- on-prem, cloud, or hybrid -- without rebuilding their security architecture. On AI agents, Vasudevan describes the evolution clearly: 2022 was about protecting data flowing into generative AI tools; 2025 became about protecting the actions of the agents themselves. Skyhigh Security positions itself as a proxy between agent traffic and the systems agents interact with -- whether MCP servers or SaaS applications -- monitoring what goes in and what comes out in real time. DSPM provides the baseline: know where sensitive data is and what risk it carries before any agent is given access to it. That distinction between sensitivity and risk is what allows organizations to make smart, dynamic decisions rather than blanket restrictions. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Thyaga Vasudevan, EVP, Product, Skyhigh Securityhttps://www.linkedin.com/in/thyaga12/ RESOURCES Skyhigh Security: https://www.skyhighsecurity.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Thyaga Vasudevan, Skyhigh Security, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, hybrid security, SSE, Security Service Edge, DSPM, data security posture management, zero trust, browser security, data sovereignty, AI agents, agentic AI, cloud security, RSAC Conference 2026, cybersecurity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
Closing the Exposure Window: From Vulnerability Management to Remediation Operations | A Brand Highlight at RSAC Conference 2026 with Sunil Gottumukkala, CEO & Co-Founder of Averlon

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 1, 2026 9:07


The cybersecurity industry is good at finding problems. What it has struggled with -- for decades -- is fixing them. Sunil Gottumukkala, CEO and Co-Founder of Averlon, calls this the exposure window: the gap between when a vulnerability is discovered and when it is actually resolved. That gap is where real risk lives, and closing it is the founding mission of Averlon. Speaking on location at RSAC Conference 2026, Gottumukkala draws on his experience as a security executive at Salesforce to explain why even the most well-resourced teams fall behind. More code, more acquisitions, and more attack surface means more findings -- but the capacity to remediate does not scale at the same rate. The answer, he argues, is not more people. It is better systems. Averlon approaches the problem by ingesting findings from across a customer's security stack, applying AI-driven analysis to determine what is actually exploitable in that specific environment, and eliminating noise. From there, rather than generating a ticket, the platform generates a fix -- actual code changes for application vulnerabilities, or compensating controls for situations requiring more time. The goal is not to manage vulnerabilities. It is to eliminate them. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Sunil Gottumukkala, CEO & Co-Founder, Averlonhttps://www.linkedin.com/in/sunilgottumukkala/ RESOURCES Averlon: https://www.averlon.ai Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Sunil Gottumukkala, Averlon, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, vulnerability remediation, remediation operations, exposure window, cloud security, agentic AI, CVSS, vulnerability management, RSAC Conference 2026, RSAC 2026, cybersecurity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

ITSPmagazine | Technology. Cybersecurity. Society
From Cloud to AI: Building Security Programs That Scale | A Brand Spotlight at RSAC Conference 2026 with Rich Mogull, Chief Analyst of Cloud Security Alliance

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 1, 2026 15:36


At RSAC Conference 2026, Sean Martin caught up with Rich Mogull at the Cloud Security Alliance booth for a candid conversation about where enterprise security programs stand -- and what it takes to keep pace with AI. Mogull, who joined CSA as Chief Analyst in October 2025, brings a practitioner's instinct to a research-first organization, and he arrived with a clear mandate: help organizations stop treating security frameworks as shelf documents and start treating them as operational tools. CSA operates across three pillars -- cloud, zero trust, and AI -- and Mogull is the first to acknowledge the identity tension that comes with that breadth. But his argument is consistent: each pillar represents a transformational technology that exposed the limits of existing security practices. "Our sweet spot is these transformational, disruptive technologies," he says. The same challenge that played out with cloud adoption is now repeating itself with AI, and CSA's job is to help security teams navigate it with research that is genuinely actionable. One of the most anticipated deliverables from Mogull's first year is the AI Security Maturity Model -- a structured framework that gives enterprise security programs a lens for assessing and improving their AI security posture. Modeled on CSA's Cloud Security Maturity Model (which Mogull also authored), it is built around measurable KPIs and designed to be as automatable as possible. After its first public draft drew over 600 comments from 60 international reviewers, Mogull is in the final stages of revision. The model covers governance, identity and access management, security monitoring, model security, AI infrastructure, agentic applications, MCP servers, and AI developer enablement -- a purpose-built lens for enterprise AI security programs, not a generic maturity template. Beyond the model itself, Mogull is building the operational infrastructure to help CSA members actually use it. The new Enterprise Membership program -- launched in March 2026 -- centers on the Operational Maturity Roadmap: a structured, year-long engagement where CSA analysts work directly with member organizations, providing monthly guidance, specific recommendations, and an annual progress report tied to measurable outcomes. The goal is to move CSA from research producer to implementation partner -- and to deliver the kind of decision support that scales beyond what any individual consultant can provide. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Rich Mogull, Chief Analyst, Cloud Security Alliance LinkedIn: https://www.linkedin.com/in/richmogull/ RESOURCES Cloud Security Alliance: https://cloudsecurityalliance.org CSA Enterprise Membership Program: https://cloudsecurityalliance.org/membership CSA AI Controls Matrix: https://cloudsecurityalliance.org/research/working-groups/ai-controls-matrix CSA Cloud Controls Matrix: https://cloudsecurityalliance.org/research/cloud-controls-matrix Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Rich Mogull, Cloud Security Alliance, CSA, Sean Martin, AI Security Maturity Model, cloud security, zero trust, AI security, enterprise security, security maturity model, RSAC Conference 2026, brand spotlight, brand marketing, marketing podcast Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The GovNavigators Show
Rewriting FedRAMP: Inside the Push to Modernize Federal Cloud Security

The GovNavigators Show

Play Episode Listen Later Mar 30, 2026 29:25 Transcription Available


This week on the GovNavigators Show, Adam and Robert sit down with Ryan Hoesing, Chief of Staff for FedRAMP, and Nicole Thompson, Security Director, for a deep dive into one of the most consequential federal IT programs undergoing transformation today.Ryan and Nicole walk through the sweeping changes to the FedRAMP program and explain what the new “FedRAMP 20x” approach means for agencies and industry. They unpack the shift from authorization to certification, the move toward continuous and machine-readable security data, and why redefining FedRAMP's role is critical to making cloud adoption actually work across government.Show Notes:Continued DHS appropriations uncertaintyLaunch of VP Vance's anti-fraud taskforceNew DEI EOWhat's on the GovNavigators' Radar:Mar 31: Oracle Federal ForumApr 8: ACT-IAC Contact Center Summit

Security Now (MP3)
SN 1066: Password Leakage - Zero Trust, Zero Knowledge

Security Now (MP3)

Play Episode Listen Later Feb 25, 2026 170:07 Transcription Available


ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us to urgently prepare for the inevitable. Three U.S. states attempt to ban 3D printed firearms. Denied ransom, ShinyHunters leaks 967,000 personal details. "Billions" of U.S. social security numbers leaked. Is Apple planning to add cameras to three new gadgets. No more security fixes for Firefox on Windows 7 & 8. Russia blocks the official Linux kernel site they need. Will the U.S."freedom.gov" site post EU blocked content. LLM's will offer secure passwords. Do Not Use Them. As predicted, the "ClickFix" attack strategy takes over. A listener believes his computer is compromised. How could three popular password managers get things wrong. Show Notes - https://www.grc.com/sn/SN-1066-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com bitwarden.com/twit zscaler.com/security hoxhunt.com/securitynow material.security

All TWiT.tv Shows (MP3)
Security Now 1066: Password Leakage

All TWiT.tv Shows (MP3)

Play Episode Listen Later Feb 25, 2026 170:07 Transcription Available


ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us to urgently prepare for the inevitable. Three U.S. states attempt to ban 3D printed firearms. Denied ransom, ShinyHunters leaks 967,000 personal details. "Billions" of U.S. social security numbers leaked. Is Apple planning to add cameras to three new gadgets. No more security fixes for Firefox on Windows 7 & 8. Russia blocks the official Linux kernel site they need. Will the U.S."freedom.gov" site post EU blocked content. LLM's will offer secure passwords. Do Not Use Them. As predicted, the "ClickFix" attack strategy takes over. A listener believes his computer is compromised. How could three popular password managers get things wrong. Show Notes - https://www.grc.com/sn/SN-1066-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com bitwarden.com/twit zscaler.com/security hoxhunt.com/securitynow material.security

Security Now (Video HD)
SN 1066: Password Leakage - Zero Trust, Zero Knowledge

Security Now (Video HD)

Play Episode Listen Later Feb 25, 2026 170:07 Transcription Available


ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us to urgently prepare for the inevitable. Three U.S. states attempt to ban 3D printed firearms. Denied ransom, ShinyHunters leaks 967,000 personal details. "Billions" of U.S. social security numbers leaked. Is Apple planning to add cameras to three new gadgets. No more security fixes for Firefox on Windows 7 & 8. Russia blocks the official Linux kernel site they need. Will the U.S."freedom.gov" site post EU blocked content. LLM's will offer secure passwords. Do Not Use Them. As predicted, the "ClickFix" attack strategy takes over. A listener believes his computer is compromised. How could three popular password managers get things wrong. Show Notes - https://www.grc.com/sn/SN-1066-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com bitwarden.com/twit zscaler.com/security hoxhunt.com/securitynow material.security

Security Now (Video HI)
SN 1066: Password Leakage - Zero Trust, Zero Knowledge

Security Now (Video HI)

Play Episode Listen Later Feb 25, 2026 170:07 Transcription Available


ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us to urgently prepare for the inevitable. Three U.S. states attempt to ban 3D printed firearms. Denied ransom, ShinyHunters leaks 967,000 personal details. "Billions" of U.S. social security numbers leaked. Is Apple planning to add cameras to three new gadgets. No more security fixes for Firefox on Windows 7 & 8. Russia blocks the official Linux kernel site they need. Will the U.S."freedom.gov" site post EU blocked content. LLM's will offer secure passwords. Do Not Use Them. As predicted, the "ClickFix" attack strategy takes over. A listener believes his computer is compromised. How could three popular password managers get things wrong. Show Notes - https://www.grc.com/sn/SN-1066-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com bitwarden.com/twit zscaler.com/security hoxhunt.com/securitynow material.security