Podcasts about cves

  • 198PODCASTS
  • 496EPISODES
  • 48mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 17, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about cves

Show all podcasts related to cves

Latest podcast episodes about cves

The CyberWire
AI is calling the shots.

The CyberWire

Play Episode Listen Later Sep 17, 2026 29:56


AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire service. A data broker loses its domains. U.S. Cyber Command names a new AI chief. Ethan Cook is joining Dave Bittner and Ben Yelin to discuss the industry-proposed and administration-opposed AI slowdown. CISA's field of schemes.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Ethan Cook, N2K's lead analyst, joins Dave Bittner and Ben Yelin for a discussion about the industry-proposed and administration-opposed AI slowdown, exploring the policy debate and what it could mean for the future of AI. If you enjoyed this conversation, be sure to check out the full interview on Caveat here. Selected Reading The era of AI warfare has arrived (Financial Times) Iran strikes on Amazon data centers caused permanent loss of customer data (Ars Technica) OpenAI Discloses Six New Incidents of ‘Concerning' A.I. Behavior (The New York Times) AISLE Discovers 16 CVEs in Wireshark, the World's Most Popular Network Protocol Analyzer (AISLE) TrustSink: How a Rogue External MFA Provider Steals Passwords (Varonis) RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts (Zimperium) US takes down NightmareStresser DDoS-for-hire platform (Bleeping Computer) Data Broker Radaris Loses Domains in Privacy Fight (Krebs on Security) Former NGA Executive Ronzelle Green Named USCYBERCOM Chief AI Officer (ExecutiveGov) CISA releases Cyber Decoys guide detailing tripwires, honeytokens to strengthen critical infrastructure detection and response (Industrial Cyber) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

AWS Morning Brief
Lambda Slowly Becomes EC2, One Feature at a Time

AWS Morning Brief

Play Episode Listen Later Sep 14, 2026 3:51


AWS Morning Brief for the week of September 14th with Corey Quinn. Links:Amazon API Gateway now supports 1 MB execution logs with configurable delivery destinationsAmazon S3 Object Lock now supports variable retention with event holdsLambda's slow-motion reinvention of EC2Amazon EC2 now supports specifying compatible instance types on AMIsAnnouncing second-generation single-rack AWS OutpostsHow AWS thinks about FinOps Automation and TrustIntroducing Amazon EBS Volume Clones across AWS accountsHow to migrate from Amazon CloudSearch to Amazon OpenSearch ServerlessIntroducing Pizza Bot, an open source inbox for AI agents that work in the backgroundThree consecutive CVEs, all AWS-authored code

Packet Pushers - Full Podcast Feed
TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Sep 4, 2026 44:03


Last year, 49,000 CVEs were published, more than 130 new vulnerabilities every day. So what actually happens with all of those CVEs in your network infrastructure? In this sponsored episode, Rekha Shenoy and Irfahn Khimji of BackBox join Scott Robohn to discuss why the math of manual network operations no longer works, where traditional tools... Read more »

Packet Pushers - Fat Pipe
TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)

Packet Pushers - Fat Pipe

Play Episode Listen Later Sep 4, 2026 44:03


Last year, 49,000 CVEs were published, more than 130 new vulnerabilities every day. So what actually happens with all of those CVEs in your network infrastructure? In this sponsored episode, Rekha Shenoy and Irfahn Khimji of BackBox join Scott Robohn to discuss why the math of manual network operations no longer works, where traditional tools... Read more »

Paul's Security Weekly
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

Paul's Security Weekly

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-398

Resilient Cyber
The Jagged Frontier of Finding and Fixing Vulns with AI

Resilient Cyber

Play Episode Listen Later Sep 1, 2026 42:28 Transcription Available


Ondrej Vlcek, CEO of AISLE and former CEO of Avast, on why AI vulnerability discovery is not as commoditized as the industry thinks, and why remediation is still the real bottleneck.In this episode I sit down with Ondrej Vlcek, Founder and CEO at AISLE. Ondrej spent roughly 30 years in cybersecurity, joining Avast as employee number six or seven doing kernel-mode driver work on Windows 95, eventually becoming CTO and then CEO, taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024 to close the loop from discovery through triage, remediation, and verification. His team has now disclosed 350 plus CVEs across projects like OpenSSL and curl.We get into why the moat sits in the system and not the model, why the gray market price of vulnerabilities has not collapsed even as models get cheaper, and what it actually takes to ship a patch a maintainer will accept.In this episode:- Going from Avast intern to CEO, and why vulnerability management was the next problem- The jagged frontier, and why bigger models do not always mean better results- Which classes of bugs got cheap to find and which are still genuinely hard- Why vulnerability prices have not collapsed despite all the model progress- Building a model-agnostic system with bespoke benchmarks for model selection- Sovereign AI, on-prem and air-gapped deployment, and why findings are the real crown jewels- Triage, reachability, and why most findings are not actually exploitable- Patch verification, regression risk, and mitigations for embedded systems that cannot be patched- How AISLE earned trust from curl after Daniel Stenberg killed the bug bounty- Whether a CVE count is a vanity metric- Build versus buy as model capability keeps getting cheaper- What breaks first in the CVE and open source maintainer ecosystem- What AppSec leaders should change next quarterChapters0:00 Intro0:24 From Avast employee number six to a $9 billion exit3:26 Why vulnerability management, and why now5:15 The jagged frontier and what bigger models miss10:36 The economics of finding bugs, and why prices have not collapsed12:11 Building a model-agnostic system with real benchmarks14:30 Sovereign AI, air-gapped deployment, and who sees your findings19:42 Triage, reachability, and why remediation is the bottleneck24:48 Patches that break things, and systems you cannot redeploy25:39 curl, Daniel Stenberg, and death by a thousand slops29:35 Is a CVE count a vanity metric?31:34 Build versus buy when capability keeps getting cheaper34:41 What breaks first in the next 18 months39:46 What AppSec leaders should do next quarter41:13 ClosingOndrej Vlcek on LinkedInAISLEAISLE research and blogResilient Cyber SubstackSubscribe for more conversations with security practitioners and leaders.

Paul's Security Weekly TV
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Nidhi Aggarwal, Gil Geron, Braden Russell - ASW #398

Paul's Security Weekly TV

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Show Notes: https://securityweekly.com/asw-398

Application Security Weekly (Audio)
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

Application Security Weekly (Audio)

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-398

Application Security Weekly (Video)
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Nidhi Aggarwal, Gil Geron, Braden Russell - ASW #398

Application Security Weekly (Video)

Play Episode Listen Later Sep 1, 2026 68:01


AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Show Notes: https://securityweekly.com/asw-398

Defense in Depth
Market Confusion Is Responsible for the Biggest Gaps in Cybersecurity

Defense in Depth

Play Episode Listen Later Aug 27, 2026 29:47


All links and images can be found on CISO Series Check out this post from Joe Head of RELEX Solutions for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining is Mary Rose Martinez, CISO, and vp of digital technology services, Marathon Petroleum Corporation. In this episode: Left behind A hypothetical sale The philosophy problem Stop shifting the problems A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at activestate.com.

Open Source Security Podcast
CVEs vs Advisories with Paul Asadoorian

Open Source Security Podcast

Play Episode Listen Later Aug 24, 2026 38:07


Josh chats with Paul Asadoorian about a tool he wrote called fettle and a recent report Paul published on CVEs. Fettle is a tool to help update and manage Linux systems. The big sell on this one is checking if your firmware is out of date. We then talk about a report Paul created that doesn't obsess over CVEs, but rather the vendor updates. It makes more sense to worry about advisories as those are actionable, where CVEs often are not. It's a great chat and Paul is a legend in the industry. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-paul-fettle-cve  

linux advisories cves paul asadoorian
Postgres FM
Estimating work_mem

Postgres FM

Play Episode Listen Later Aug 21, 2026 50:03


Nik and Michael are joined by Shaun Thomas to discuss estimating work_mem, memory management in general, and writing an extension to help. Here are some links to things they mentioned: Shaun Thomas https://postgres.fm/people/shaun-thomaswork_mem https://www.postgresql.org/docs/current/runtime-config-resource.html#GUC-WORK-MEMpg_stat_database https://www.postgresql.org/docs/current/monitoring-stats.html#MONITORING-PG-STAT-DATABASE-VIEWALTER ROLE SET configuration_parameter https://www.postgresql.org/docs/current/sql-alterrole.html#SQL-ALTERROLE-PARAMS-CONFIGURATION-PARAMETERhash_mem_multiplier https://www.postgresql.org/docs/current/runtime-config-resource.html#GUC-HASH-MEM-MULTIPLIERRecent Postgres releases with 28 CVEs fixed https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/Systemic Risks in the Managed PostgreSQL Industry (part 1 of 6, Mehmet Ince) https://mehmetince.net/part-1-6-systemic-risks-in-the-managed-postgresql-industry-extension-risks-are-real-exploiting-postgis-memory-corruption-bug-at-neondb-supabase-and-many-more/Improving Postgres Connection Scalability: Snapshots (blog post by Andres Freund) https://techcommunity.microsoft.com/blog/adforpostgresql/improving-postgres-connection-scalability-snapshots/1806462~~~What did you like or not like? What should we discuss next time? Let us know via a YouTube comment, on social media, or by commenting on our Google doc!~~~Postgres FM is produced by:Michael Christofides, founder of pgMustardNikolay Samokhvalov, founder of Postgres.aiWith credit to:Jessie Draws for the elephant artwork

The Cyber Threat Perspective
Your IT Job Doubled. Nobody Told Your Boss. | Ep 193

The Cyber Threat Perspective

Play Episode Listen Later Aug 20, 2026 39:41 Transcription Available


In July 2026, Microsoft alone released 622 CVEs. In the 2010s, the monthly average was about a dozen. Nobody handed IT teams more time, budget, or headcount to match, and that gap is what burnout is actually made of.Somewhere in the last five to ten years, "keeping the lights on" became "and also prevent cyberattacks." Spencer Alessi and Brad Causey talk through how security landed on IT's plate, why capable admins end up feeling like they're failing, and what to do about it when hiring a dedicated security person isn't on the table.The core of the episode is a four-question framework for prioritizing when you can't do everything:- Harm: what would cause the greatest damage to the business?- Likelihood: what is most likely to actually be attacked?- Improve: what can you realistically fix with the people and tools you have today?- Accept: what risk must leadership explicitly own because your team can't address it?Brad's addition: don't start from the scan report, start from the crown jewels. Client matters if you're a law firm, financial data if you're a bank. From there, draw lines outward to whatever touches them. And executives need to get comfortable accepting risk, because zero risk tolerance isn't a strategy, it's a phrase.We also get into the language that works with leadership. "You gave me four things and I have time for two" is adversarial and doesn't give anyone enough to decide with. "I recommend A and C, here's why, and here's when B and D land if nothing else gets added" is managing up. Same for new projects: price the work honestly, including cost, timeline, and tradeoffs, then hand the decision back to the people with full business context.We close with the four things IT teams need to succeed: authority, budget, team, and support, including a trusted outside partner for the specialized work you shouldn't be doing yourself.Planning your next penetration test? Book a call with us at https://securit360.comIf you enjoyed this episode, please share it with your network. See you next week.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Packet Pushers - Full Podcast Feed
NB587: US Calls for CyberSec Privateers; Oracle To Rent Out Quantum Computers

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Aug 17, 2026 35:37


Take a Network Break! Our red alert goes to cluster of CVEs for Canonical's LXD Linux Container system. On the news side, Palo Alto Networks adds AI-powered security evaluations as a service engagement, SonicWall introduces an endpoint security agent for SMBs, and the White House outlines a plan to authorize private companies to conduct cyber... Read more »

Paul's Security Weekly
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Paul's Security Weekly

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a “mouthpad”? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-472

Packet Pushers - Network Break
NB587: US Calls for CyberSec Privateers; Oracle To Rent Out Quantum Computers

Packet Pushers - Network Break

Play Episode Listen Later Aug 17, 2026 35:37


Take a Network Break! Our red alert goes to cluster of CVEs for Canonical's LXD Linux Container system. On the news side, Palo Alto Networks adds AI-powered security evaluations as a service engagement, SonicWall introduces an endpoint security agent for SMBs, and the White House outlines a plan to authorize private companies to conduct cyber... Read more »

Packet Pushers - Fat Pipe
NB587: US Calls for CyberSec Privateers; Oracle To Rent Out Quantum Computers

Packet Pushers - Fat Pipe

Play Episode Listen Later Aug 17, 2026 35:37


Take a Network Break! Our red alert goes to cluster of CVEs for Canonical's LXD Linux Container system. On the news side, Palo Alto Networks adds AI-powered security evaluations as a service engagement, SonicWall introduces an endpoint security agent for SMBs, and the White House outlines a plan to authorize private companies to conduct cyber... Read more »

Enterprise Security Weekly (Audio)
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a "mouthpad"? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-472

Paul's Security Weekly TV
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Paul's Security Weekly TV

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Joe Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a "mouthpad"? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-472

Enterprise Security Weekly (Video)
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Enterprise Security Weekly (Video)

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a "mouthpad"? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-472

Autonomous IT
Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

Autonomous IT

Play Episode Listen Later Aug 11, 2026 22:45


August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only actively exploited vulnerability of the month, CVE-2026-68820, a use-after-free in the Windows AFD driver that trades a race condition for SYSTEM privileges. Serena breaks down CVE-2026-62832, a User Profile Service privilege escalation that lets an attacker load another user's registry hive with no user interaction required.Then there's the perfect 10.0 in Microsoft Teams that nobody needs to patch. Jason explains how cloud CVEs ended up in Patch Tuesday releases, why a third of this month's critical count requires zero customer action, and why the industry needs a separate disclosure mechanism before monthly CVE volume becomes pure noise. The crew also covers an ugly macOS screen sharing vulnerability that allowed authentication without credentials, the Linux kernel community's shift to issuing CVEs at scale, fresh takes from Black Hat and DEF CON on AI-driven vulnerability discovery, and why frontier models are forcing patching decisions to happen by policy instead of one CVE at a time.Patch your stuff. See you next month.

Cyber Security Today
AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

Cyber Security Today

Play Episode Listen Later Aug 10, 2026 16:31


AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile. A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 01:08 AI Patches Fail Often 03:19 WordPress Login XSS 05:40 Wipers Target Infrastructure 08:02 North Carolina Ports Hit 09:49 DEF CON Favorite Talks 10:15 GPS Trackers Takeover 11:28 Noreply Domain Email Leak 12:37 AI Finds HTTP Desyncs 13:47 Cliff Stoll Keynote 15:09 Wrap Up And Thanks 15:31 NordLayer Sponsor Close

Check Point CheckMates Cyber Security Podcast
S08E09: Unexpected Boundaries

Check Point CheckMates Cyber Security Podcast

Play Episode Listen Later Aug 10, 2026 10:32


On this episode of CheckMates Go, PhoneBoy talks about Check Point-specific CVEs, AI News, and Rulebase Evaluation, Maestro Troubleshooting, and Rate Limiting.CVE-2026-16232 - Authentication bypass with SmartConsole login process using application tokenCVE-2026-62144 - Management Authentication Bypass and Privilege EscalationCVE-2026-62145 - Local privilege escalation in Gaia PortalCVE-2026-18574 - Management Authentication BypassCheck Point Gateway and Management Hardening GuideWhen The Sandbox Stops Being a BoundaryAI Assist for Security ProfessionalsUnified Policy: Column-Based Rule MatchingMaestro Troubleshooting in PracticeExperience with SecureXL DoS FeaturesHow to configure Rate Limiting rules for DoS Mitigation in R82 and higherHow to configure Rate Limiting rules for DoS Mitigation in R80.20 - R81.20

Risky Business News
Risky Bulletin: Hacker breaches Hungary's State Treasury

Risky Business News

Play Episode Listen Later Aug 5, 2026 10:08


A hacker breached Hungary's State Treasury, Russia will mandate 40 apps on all smartphones next year, hackers steal Liechtenstein's business database, and an AI agent got real CVEs for hallucinated vulnerability reports. Show notes Risky Bulletin: Hacker breaches Hungary's State Treasury

Open Source Security Podcast
VulnCheck's State of Exploitation Report with Patrick Garrity

Open Source Security Podcast

Play Episode Listen Later Aug 3, 2026 36:45


Josh chats with Patrick Garrity about the VulnCheck State of Exploitation 1H-2026 report. Patrick explains the current trends we are seeing around vulnerabilities right now. While the number of CVEs is way up, the number of actually exploited vulnerabilities isn't growing year over year. This tells us there is a lot of FUD and hype. We also ask where are all the vulnerabilities that project Glasswing found. They should be going public by now, but we're not seeing that play out in the data. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-08-vulncheck-state-of-exploitation  

Complex Systems with Patrick McKenzie (patio11)
Cheap cognition, supercharged surveillance, and AI risks, with Garrison Lovely

Complex Systems with Patrick McKenzie (patio11)

Play Episode Listen Later Jul 30, 2026 80:55


Patrick McKenzie (patio11) is joined by Garrison Lovely, journalist and author of Obsolete: The AI Industry's Trillion-Dollar Race to Replace Us and How to Stop It, to map the three-sided debate over AI risk and why the arguments keep talking past each other. They then turn to what cheap cognition does to surveillance that already exists: FinCEN receives roughly 4 million suspicious activity reports a year and reads almost none of them, ICE agents run about a million queries against that database annually, and every podcast ever recorded is now transcribable for approximately nothing. The conversation covers capabilities denialism, ablated open-weights models, the fraud supply chain, and why AI is also unusually good at writing the Regulation E letter that gets your bank to fix your problem.–Full transcript available here: https://www.complexsystemspodcast.com/cheap-cognition-and-the-end-of-practical-obscurity-with-garrison-lovely/ –Presenting Sponsors: Mercury, MongoDB & ChainguardComplex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. –Links:Obsolete: The AI Industry's Trillion Dollar Race to Replace Us―and How to Stop It: https://www.amazon.com/Obsolete-Power-Profit-Machine-Superintelligence/dp/1682196305 –Timestamps:(00:00) Preview(00:43) Intro(01:51) The three-sided debate over AI risk(05:32) Power, politics, and the tech backlash(09:49) Capabilities denialism and AI tells(14:54) The obsoleting machine(17:09) The Turing test is dead(18:56) Languages for free, then software engineering(22:37) Sponsors: Mercury | MongoDB(25:09) How high up the stack do the models decide?(29:11) Surveillance and cheap cognition(32:38) Podcasts, FinCEN, and the end of practical obscurity(38:35) Section 702 and the data broker loophole(39:35) Sponsor: Chainguard(40:55) Section 702 and the data broker loophole (cont'd)(47:23) Institutional friction and a million ICE queries(53:29) Security through obscurity no longer works(54:54) Scams, fraud, and ablated models(1:00:20) Personal utility versus societal backlash(1:02:16) AI as a tool for redress(1:06:34) State capacity and regulating what you understand(1:12:37) Tobacco, nuclear, and AlphaFold: strangle it or steer it(1:18:37) Where to find Garrison and the book(1:20:32) Wrap

Security Now (MP3)
SN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your Engines

Security Now (MP3)

Play Episode Listen Later Jul 29, 2026 187:56


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

All TWiT.tv Shows (MP3)
Security Now 1089: Models Go Rogue & ExploitGym

All TWiT.tv Shows (MP3)

Play Episode Listen Later Jul 29, 2026 187:56 Transcription Available


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

Security Now (Video HD)
SN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your Engines

Security Now (Video HD)

Play Episode Listen Later Jul 29, 2026 187:56


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

Security Now (Video HI)
SN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your Engines

Security Now (Video HI)

Play Episode Listen Later Jul 29, 2026 187:56


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

Radio Leo (Audio)
Security Now 1089: Models Go Rogue & ExploitGym

Radio Leo (Audio)

Play Episode Listen Later Jul 29, 2026 187:56 Transcription Available


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

Security Now (Video LO)
SN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your Engines

Security Now (Video LO)

Play Episode Listen Later Jul 29, 2026 187:56


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

All TWiT.tv Shows (Video LO)
Security Now 1089: Models Go Rogue & ExploitGym

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Jul 29, 2026 187:56 Transcription Available


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

Radio Leo (Video HD)
Security Now 1089: Models Go Rogue & ExploitGym

Radio Leo (Video HD)

Play Episode Listen Later Jul 29, 2026 187:56 Transcription Available


What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL vulnerability claims victims. Amazing details about "Rocky" from Andy Weir. The new AI exploit ranking benchmark that caused the breakout Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: adaptivesecurity.com XBOW.com cohesity.com/Resilience threatlocker.com/twit

The Cloud Pod
365: Linux Drops 432 CVEs, Sysadmins Drop Everything Else

The Cloud Pod

Play Episode Listen Later Jul 28, 2026 87:12


Welcome to episode 364 of The Cloud Pod, where the forecast is always cloudy! Ryan is out trying to find Hotel California, but Justin, Matt, and Jonathan are in the studio today, and they've got a lot of news and some great convo – from privacy in the digital age to Nova models (and a lot of employees) getting the ax, there's a ton of stuff to cover this week, so let's get started!  Titles we almost went with this week Windows Tattletale ID Has No Off Switch Amazon’s Nova Models Enter Witness Protection Program Your PC Has a Secret Name, and Windows Won’t Erase It CloudWatch Watches Your ALB Like a Hawk One Log Group to Trace Them All Duress Code Wipes Phone, Activist Wipes Out Legally Project Perception Sees Vulnerabilities Before You Even Blink Azure DDoS Protection Trades Autopilot for Manual Control Kernel Panic Optional, CVE Overload Mandatory OpenAI’s Keypad: Key Confusion for 230 Dollars China DIYs Its Way Around DUV Export Bans OpenAI Hugged some serious Face Google must pay the EU $1 Billion… that’s a lot of Crepes Amazon apparently doesn't believe in their AGI A big thanks to this week's sponsors: We're sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You've come to the right place! Send us an email or hit us up on our Slack channel for more info. Follow Up  01:10 Linux kernel team publishes 432 CVEs in two days Update: Linux Kernel CVE Volume The Linux kernel team published 432 CVEs in a two-day span, continuing the high-volume vulnerability disclosure approach the kernel security team adopted after taking over CVE assignment duties directly. This follows the kernel team’s earlier decision to assign CVEs to a broad range of bug fixes, including minor or low-severity code changes, rather than reserving CVEs strictly for exploitable security flaws. The practice remains controversial among sysadmins and security teams, since large batches of CVEs can overwhelm vulnerability scanners, patch management systems, and compliance reporting workflows. For cloud operators running custom or long-term-support kernels, this reinforces the need for tooling that can filter and triage kernel CVEs by actual risk rather than treating every entry as an urgent patch target. The recurring pattern suggests this is now standard operating procedure for the kernel team rather than a one-time anomaly, so listeners managing fleets of Linux-based cloud infrastructure should expect similar large CVE batches going forward. 01:46 Justin – “Everyone is doing a lot of patching these days.”  04:42 I tried out OpenAI’s new AI keypad — which will be fun for some coders and slightly mystifying to everyone else 

This Week in Linux
353: Codeberg Bans AI, 432 Linux CVEs, Valve wants Arch on ARM, Jellyfin Leaders Left & more Linux news

This Week in Linux

Play Episode Listen Later Jul 27, 2026 26:42


video: https://youtu.be/mytY-cyk76U This week in Linux, hundreds of Linux security alerts landed but the headlines leave out the most important part. Codeberg, a major open-source code hosting platform, is drawing a new line around AI-generated code, Valve is stretching out their ARM for a new Frame of mind for running Linux, and Jellyfin is entering a major new chapter behind the scenes. All of this and more on This Week in Linux, Your Source for Linux GNews! Download as MP3 Support the Show Become a Member = tuxdigital.com/membership Store = tuxdigital.com/store Chapters: 00:00 Intro 00:30 Become a Member of the channel by July 31st 01:39 Codeberg bans mostly AI-generated projects 05:31 Valve and Collabora develop Arch Linux for ARM64 08:08 Jellyfin Leadership Departures 11:57 Linux publishes 432 kernel CVEs in 2 days 14:53 Canonical fixes 3 Snap vulnerabilities 17:26 Firefox 153 adds Containers and Vulkan Video 21:11 TWIL Speedrun or Linux Lightning Round 21:37 AMD's open-source AI and robotics announcements 22:34 Final MPEG-4 Visual patent expiration 23:31 OBS Studio 32.2 Released 24:05 Raspberry Pi launches a 10-inch Touch Display 2 25:18 Outro Links: Become a Member of the channel by July 31st https://tuxdigital.com/membership Codeberg bans mostly AI-generated projects https://blog.codeberg.org/protecting-our-floss-commons-from-llms.html https://www.omgubuntu.co.uk/2026/07/codeberg-bans-ai-generated-code https://itsfoss.com/news/codeberg-bans-ai-contributions/ OpenAI on Vibe Coding - https://x.com/karpathy/status/1886192184808149383 Valve and Collabora develop Arch Linux for ARM64 https://www.collabora.com/news-and-blog/news-and-events/building-an-arch-linux-aarch64-port-for-holo-core.html https://gitlab.steamos.cloud/holo/holo-core-aarch64-preview https://www.gamingonlinux.com/2026/07/collabora-announce-a-preview-of-holo-core-an-aarch64-port-of-arch-linux-for-steam-frame/ https://www.phoronix.com/news/Holo-Core-Experimental-ARM64 https://9to5linux.com/valve-and-collabora-announce-official-arch-linux-arm64-port-for-steam-frame Jellyfin Leadership Departures https://www.boniface.me/posts/on-my-jellyfin-resignation/ https://itsfoss.com/news/jellyfin-leadership-crisis/ https://linuxiac.com/jellyfin-loses-project-leader-and-core-team-member-in-major-shake-up/ https://jellyfin.org/posts/state-of-the-fin-2026-05-24/ Linux publishes 432 kernel CVEs in 2 days https://lore.kernel.org/linux-cve-announce/ https://seclists.org/oss-sec/2026/q3/198 https://seclists.org/oss-sec/2026/q3/210 https://www.theregister.com/security/2026/07/22/linux_kernel_team_publishes_432_cves_in_two_days/5276497 https://docs.kernel.org/process/cve.html https://utcc.utoronto.ca/~cks/space/blog/linux/KernelBugfixCVEsAStory Canonical fixes 3 Snap vulnerabilities https://ubuntu.com/security/notices/USN-8579-1 https://seclists.org/oss-sec/2026/q3/191 https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txt https://www.cve.org/CVERecord?id=CVE-2026-15226 Firefox 153 adds Containers and Vulkan Video https://www.firefox.com/en-US/firefox/153.0/releasenotes/ https://blog.mozilla.org/en/firefox/firefox-containers-preview/ https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153 https://brave.com/blog/containers/ TWIL Speedrun or Linux Lightning Round which do you prefer of those names? AMD's open-source AI and robotics announcements https://www.amd.com/en/corporate/events/advancing-ai.html https://www.amd.com/en/blogs/2026/rocm-ai-the-ai-native-developer-experience-for-building.html https://www.amd.com/en/products/system-on-modules/kria/ai.html https://www.amd.com/en/products/system-on-modules/kria/ai/robotics-developer-platform.html Final MPEG-4 Visual patent expiration https://www.phoronix.com/news/Last-MPEG-4-Patent-Expired https://itsfoss.com/news/mpeg-4-visual-patent-expiry/ https://meta.wikimedia.org/wiki/Have_the_patents_for_MPEG-4_Visual_expired_yet%3F OBS Studio 32.2 Released https://github.com/obsproject/obs-studio/releases/tag/32.2.0 https://9to5linux.com/obs-studio-32-2-released-with-new-filter-to-compose-sdr-into-hdr https://linuxiac.com/obs-studio-32-2-makes-adding-sources-easier/ Raspberry Pi launches a 10-inch Touch Display 2 https://www.raspberrypi.com/news/a-new-10-raspberry-pi-touch-display-2-available-now-at-80/ https://pip-assets.raspberrypi.com/categories/1083-raspberry-pi-touch-display-2 https://www.phoronix.com/news/10-inch-Raspberry-Pi-Touch-2 https://www.theregister.com/2026/07/22/raspberry-pi-goes-large-with-101-inch-touch-display-2/ https://9to5linux.com/raspberry-pi-launches-10-inch-raspberry-pi-touch-display-2-at-80 Support the show https://tuxdigital.com/membership https://store.tuxdigital.com/

The Bitcoin Matrix
Bitcoin Secures $1 Trillion and Has No Security Team | Luke de Wolf

The Bitcoin Matrix

Play Episode Listen Later Jul 25, 2026 160:57


"Bitcoin secures over a trillion dollars in value. It has no security team." Luke de Wolf is a cybersecurity professional and author of Defending Bitcoin. Luke spent his career defending critical infrastructure, the control systems behind power grids and gas pipelines. His claim: Bitcoin is the world's first decentralized critical infrastructure, and it should be defended with the same risk-management frameworks that protect the physical world. A trillion-dollar network with no security team. And Luke is a former BIP-110 skeptic who flipped to supporting it making him a moderate who pisses off both sides. We get into the CIA triad and why availability is the whole game, people as the weakest link and the Stuxnet lesson, the real cost of running a node over time, spam as a DDoS and the hidden tax on Bitcoin, the two CVEs behind inscriptions, and the full BIP-110 fight. We discuss why he flipped, the game theory of activation, soft fork vs hard fork, the intolerant minority, and whether BIP-110 even has a failed state. This is the defender's case for Bitcoin, and the fight is happening right now. Subscribe so you never miss an episode.

Defense in Depth
Identity and Access Management (IAM) in an Agentic AI World

Defense in Depth

Play Episode Listen Later Jul 23, 2026 30:20


All links and images can be found on CISO Series Check out this post by Tomás Maldonado, CISO, NFL, for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Will Gregorian, vp of information technology & security, Galileo Medical. In this episode: From who to what The manipulation problem Cryptographic accountability The audit gap A huge thanks to our sponsor, ActiveState ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at ActiveState.com.

Complex Systems with Patrick McKenzie (patio11)
What you're actually getting paid in, with Leila Clark

Complex Systems with Patrick McKenzie (patio11)

Play Episode Listen Later Jul 23, 2026 64:00


In this episode, Patrick McKenzie (patio11) is joined by Leila Clark, founder of Stardrift and formerly a software engineer at Jane Street, to discuss her essay "What Are You Getting Paid In?"  They cover how a Jane Street manager staffed the firm's least lucrative corner by paying people in culture, why Ken Griffin is worth roughly fifty Taylor Swifts, and how a longtime Google product manager quietly ends up with Grammy-winner money. The conversation ranges from academia's brutal tournament structure and YC as a script to founderdom to the one currency Taylor Swift holds that Ken Griffin's $50 billion buys only awkwardly: a restaurant reservation anywhere in New York.–Full transcript available here: https://www.complexsystemspodcast.com/what-youre-actually-getting-paid-in-with-leila-clark/ –Presenting Sponsors: Mercury, Chainguard & MongoDB Complex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/.What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.–Links:What are you getting paid in: https://www.approachwithalacrity.com/p/what-are-you-getting-paid-in –Timestamps:(00:00) Intro(01:23) What are you getting paid in?(03:16) Scripts, teacher figures, and hitting capitalism(08:18) The academia trap(11:08) Paying people in culture: Jane Street's back office(14:03) Ken Griffin vs. Taylor Swift(16:53) Learning about finance by osmosis (or not)(20:44) Sponsors: Mercury | Chainguard(23:46) Musician money vs. Google money(30:03) Keeping up with the Joneses and the meritocratic ladder(33:12) YC as a script to founderdom(36:19) What entrepreneurship pays you in(39:12) Gratitude, culture, and quirky preferences(40:11) Sponsor: MongoDB(43:48) Does winning this script look like winning to you?(48:29) Don't end the week with nothing(51:06) Fame and living in bubbles(56:57) Restaurant reservations as a currency(1:02:57) Where to find Leila(01:03:35) Wrap

Risky Business News
Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breach

Risky Business News

Play Episode Listen Later Jul 22, 2026 6:50


Rogue OpenAI models were behind last week's Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service. Show notes Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in

Passwort - der Podcast von heise security
Die IETF knirscht, Cisco knirscht und die Rikscha auch

Passwort - der Podcast von heise security

Play Episode Listen Later Jul 22, 2026 110:20 Transcription Available


Im Podcast geht es mal wieder um einen bunten Strauß an Themen der vergangengen Wochen, angefangen mit einer sehr unangenehmen aber auch wichtige Diskussion zur zukünftigen Absicherung von TLS. Weiter geht es mit LLMs, die angeblich autonom Ransomware ausliefern, und Cisco, die keine einzelnen CVEs mehr ausliefern. Außerdem besprechen die Hosts elektrische Infrastruktur, die man fernsteuern und insbesondere aus der Ferne abschalten kann – leider kann das jeder der mag.

Security Conversations
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack

Security Conversations

Play Episode Listen Later Jul 18, 2026 127:29


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation. Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 3:51 Hugging Face discloses end-to-end agentic hack 9:42 Why Hugging Face couldn't use frontier models 13:28 AI guardrails hampering defenders 16:22 Codex vs Claude for real malware work 23:43 Flash attacks vs. going low and slow 30:27 Was it targeted, or did Hugging Face pwn itself? 38:11 Long-horizon coherence: what GLM 5.2 still can't do 41:27 Kimi K3 leapfrogs, and Xi's AI speech 52:15 Exceptionalism vs. distribution 1:11:05 Gold Eagle: the White House vulnerability clearinghouse 1:15:05 Microsoft patches 622 CVEs — a record 1:20:29 APT corner: Daxin resurfaces after 13 years of dwell time 1:29:45 Balochistan police, and Microsoft's attribution-free wiper 1:34:26 Denis Obrezkov, leaked Kaspersky records, and the wrong questions 1:46:01 Magnet Forensics sues over a burned iPhone bug 1:57:57 Shout-outs

Complex Systems with Patrick McKenzie (patio11)
What LLMs can and can't do for writers, with Clara Collier of Asterisk Magazine

Complex Systems with Patrick McKenzie (patio11)

Play Episode Listen Later Jul 16, 2026 95:35


Patrick McKenzie is joined by returning guest Clara Collier, editor-in-chief of Asterisk Magazine, to discuss how working writers and reporters actually use LLMs. Patrick walks through the machinery behind his recent SPLC reporting, including "parallel construction" with LLMs: when sources can't go on the record, models can surface public confirmation of the same facts in unguarded podcast interviews, press releases, and prepared remarks. They also cover why the best smoking gun sat unnoticed on the coalition's own Twitter account, the David O. Selznick theory of the corporate memo, and where hardball politics in a democracy ends and crimes begin.–Full transcript available here: https://www.complexsystemspodcast.com/llms-and-writers-with-clara-collier-of-asterisk-magazine/–Presenting Sponsors: Mercury, MongoDB & ChainguardComplex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. –Links:Complex Systems on YouTube: https://www.youtube.com/@patio11podcast Asterisk Magazine: https://asteriskmag.com/ –Timestamps:(00:00) Preview(00:51) Intro(01:16) How legacy media feels about LLMs(05:02) Writing as thinking: why the byline matters(08:51) LLMs as feedback partners and simulated readers(12:39) The future of the corporate memo(15:58) Sponsor: Mercury | MongoDB(18:30) Memos, de-skilling, and thinking on paper(20:02) David O. Selznick's memos and the MrBeast production doc(23:28) Can models introspect on their own work?(30:06) Sponsor: Chainguard(31:27) The SPLC investigation(37:07) Chains of evidence and protecting sources(45:20) Parallel construction with LLMs(49:41) Mining podcasts for unguarded admissions(59:35) Deepen your strengths, don't just patch weaknesses(1:03:34) The smoking gun the LLM missed(1:04:48) Hardball politics versus crimes(1:10:48) Why a payments newsletter reported a political story(1:16:19) Reporting stories that will be weaponized(1:20:24) The tech right and internal company politics(1:23:44) Debanking discourse and drawing distinctions(1:30:21) Hate speech, social sanctions, and owning decisions(1:34:51) Wrap

Complex Systems with Patrick McKenzie (patio11)
YouTube economics now, with Justin Kuiper

Complex Systems with Patrick McKenzie (patio11)

Play Episode Listen Later Jul 9, 2026 79:27


In this episode of Complex Systems, Patrick McKenzie (patio11) is joined by Justin Kuiper, a longtime writer for MatPat's Game Theory family of channels and now creator of Proof Positive, to discuss the microeconomics of YouTube. They break down how creators actually get paid — from $3–$20 CPMs and the leaky funnel where a million views yields perhaps 50,000 actual ad views, to sponsor reads, Super Chats, and MrBeast selling chocolate bars as his own advertiser of last resort. Along the way, they explore how a successful channel becomes a firm that absorbs specialist labor from less successful peers, why the algorithm gives every upload a trial by attention, and what parasocial spending has in common with Mark Twain's speaking circuit.–Full transcript available here: https://www.complexsystemspodcast.com/justin-kuiper-youtube/ –Presenting Sponsors: Mercury, Chainguard & MongoDB Complex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.–Links:Proof Positive on YouTube: https://www.youtube.com/channel/UCns_C7cPAguFSv2YdltaOsg –Timestamps:(00:00) Preview(00:45) How creators make money on YouTube(04:06) CPMs and the international ad market(06:36) From solo creator to firm: working for MatPat(09:28) Sponsors: Mercury | Chainguard(12:30) From solo creator to firm: working for MatPat (cont'd)(13:49) YouTube as a farm league for other industries(17:15) Why now is the best time to start: discovery and universal basic attention(20:47) Power users and how recommendations work(24:23) Brand safety, rabbit holes, and the money laundering short(27:38) Fads, timing, and the day-two piece(35:52) The production function: scripts, shot lists, and editing labor(42:14) The aesthetics of authenticity(46:58) Sponsor: MongoDB(47:47) Why more people should make videos(53:52) Content marketing, sponsor reads, and remnant inventory(01:00:24) Chocolate bars, paint sets, and creator products(01:05:00) Parasocial relationships and the market in status(01:16:43) Where to find Justin: Proof Positive(01:18:58) Wrap

Resilient Cyber
Why Finding Vulnerabilities Was Never the Hard Part

Resilient Cyber

Play Episode Listen Later Jul 5, 2026 36:39


Every headline wants you to believe AI has rewritten the rules of cybersecurity. Eric Doerr, the Chief Product Officer at Tenable a Resilient Cyber Partner, is not so sure. After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded. The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that.Why this conversation mattersEric sits at a rare intersection, having lived the post-breach world of the SOC and now building the pre-breach world of exposure management. That vantage makes him a sharp guide to what AI actually shifts for defenders, from why cheaper discovery makes prioritization more valuable to how AI becomes its own attack surface once agents start touching your data. If you own vulnerability or exposure management and you are trying to spend your next dollar well, this conversation is a practical map of where the real risk lives and what to automate first.Key takeawaysAttackers are ruthlessly economical. Eric calls bad actors the perfect capitalists, spending the least effort needed to hit their goal, which is why so many still get in through unpatched basics rather than anything AI-powered.AI has not rewritten the offense-defense balance. The attacker only ever had to be right once, layered defense and zero trust still hold, and the real lever is accelerating your program with fewer human loops rather than lamenting the asymmetry.Cheaper discovery makes context more valuable, not less. Reachability and exploitability mean most findings are not worth chasing, so as AI floods teams with more of them, telling the truly scary hundred from the theoretical ten thousand becomes the whole game.Being too small to target is a strategy on borrowed time. As automation drives the cost of attacks toward zero, the quiet bet that adversaries will hit weaker neighbors stops paying off, and Eric would move off that mentality now.Humans should not be the bottleneck on every fix. Getting the workflow and tooling right is most of the work, and the rest is the organizational willingness to let validated automation act, even when a business partner would feel better with a human in the loop.AI is special and not special at the same time. It is mostly just another attack surface, and Eric estimates 80 to 90 percent of securing it maps to patterns the industry already learned during the move to cloud.Shadow AI is the first surprise in almost every environment. When teams scan the endpoints they already interrogate for AI artifacts, nearly all of them find something they never sanctioned, which is why discovery has to come before control.The real AI risk is interconnection. A misconfigured database was a needle in a haystack until you wire it to an agent, and then a harmless question about the budget quietly returns data the asker should never see.Most breaches are not even CVEs. Citing the Verizon DBIR, Eric notes roughly two-thirds of breaches trace to misconfigurations, and since about a third of Tenable's findings are non-CVE, a third of your findings can carry two-thirds of your risk.Agentic automation is finally killing the toil. Early users are automating drudgery like asset tagging and full remediation workflows, with one manufacturing customer letting automation handle 80 to 90 percent and scheduling the rest for change windows with a human notified.Notable quotes“Bad actors are the most perfect representation of capitalism”Eric Doerr, on why attackers do the least work necessary and often skip AI entirely.“a third of their findings are two-thirds of their risk”Eric Doerr, on why misconfigurations, not CVEs, drive most breaches.“you're on the wrong side of history”Eric Doerr, on insisting a human eyeball every automated fix.

Complex Systems with Patrick McKenzie (patio11)
The structural footprint of a bank run

Complex Systems with Patrick McKenzie (patio11)

Play Episode Listen Later Jul 2, 2026 40:09


Patrick McKenzie (patio11) reads his 2023 essay "Deposit Franchises as Natural Hedges," written seven weeks into that year's banking crisis, making the case that deposit franchises are a natural hedge against interest rate risk (one regional banks were quietly encouraged to sell off by loading up on agency MBS). He walks through why "sweat and smiles" deposits were assumed to be sticky enough to fund long-duration assets, why that assumption broke down for retail and sophisticated depositors alike once rates rose, and how the resulting losses moved through bank balance sheets. Patrick closes with two years of hindsight: what the essay got right and wrong about how bad it would get.–Full transcript available here: https://www.complexsystemspodcast.com/deposit-franchises/ –Presenting Sponsors: Mercury, MongoDB & ChainguardComplex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. –Links:Deposit franchises as natural hedges: https://www.bitsaboutmoney.com/archive/deposit-franchises-as-natural-hedges/ –Timestamps:(00:00) Intro(03:48) Natural hedges(07:38) Deposit franchises as an asset(10:53) The value of a deposit franchise increases with interest rates(11:30) A brief aside about deposit beta(14:58) Sponsors: Mercury | MongoDB(17:30) A brief aside about deposit beta(18:05) The deposit franchise as a hedge(21:52) Regional banks were instructed to load up on agency MBS(25:09) Why did the hedge bust?(29:42) Sponsor: Chainguard(31:03) Further bad news: the problem is bigger than MBS(34:01) It is no longer February(34:51) “Why didn't the hedger hedge?!”(35:37) So what do we do now?(37:59) Postscript(39:45) Wrap

Resilient Cyber
Rain Versus Flood, Making Sense of the 2026 CVE Surge

Resilient Cyber

Play Episode Listen Later Jun 27, 2026 24:59


CVEs are on pace to hit nearly 70,000 in 2026, but Jerry Gamblin explains why the actual exploitable risk is staying surprisingly flat.DescriptionJerry Gamblin runs RogoLabs and built CVE.ICU, and he co-authored the FIRST mid-year vulnerability forecast that just put 2026 on pace for nearly 70,000 CVEs. He joins Resilient Cyber to separate the scary headline number from what actually matters for defenders. We get into why GitHub now publishes one in five CVEs, the rain versus flood distinction that explains why exploitable risk is flat even as raw volume explodes, what the NVD collapse means now that the CNAs have to step up, and how teams should really be triaging with EPSS and the CISA KEV catalog.Key takeawaysCVEs are on pace for nearly 70,000 in 2026, up more than 40 percent year over year. Much of the surge traces back to a single source, with GitHub now publishing one in five CVEs after scaling up its advisory team.The three drivers behind the surge are very different forces. AI-assisted discovery that nobody can definitively flag, a 449 percent jump in GitHub security advisories, and VulnCheck acting as a CNA of last resort all get lumped into one scary number.Rain versus flood is the frame that matters. Raw CVE volume is climbing fast, but once you filter for CISA KEV and EPSS the actionable, exploitable risk has stayed essentially flat.Most of the new findings are old human debt, not a new AI threat. The OWASP Top 10 has barely changed in 25 years, and tooling can now find those same mistakes at scale across mostly open source code.The AI moment is useful cover to finally patch. Jerry argues teams are using the AI hype cycle to win the time and resources to fix long-known issues, which is a genuinely good outcome.The NVD was the dam that fell. It was never fair to expect one small organization to enrich every CVE, so responsibility now shifts back to the CNAs and the large vendors that leaned on it for years.Treat CVE data as a product you pay for. Jerry's advice is to use procurement leverage, since demanding better CVE records before you renew a contract is one of the few real forcing functions available.What gets exploited has not really changed. VPN concentrators and the same old vulnerability classes still dominate, and the NSA's annual top 10 exploited bugs are reliably old, with no sign yet of AI driving widespread attacks.Asset inventory is still the real bottleneck. You cannot triage what you cannot see, and most organizations still cannot say with confidence whether they even run the software a given pile of CVEs affects.AI-accelerated exploitation is coming, but not as mass exploits. The bigger shift is a tireless attacker that loops on your network for days until it finds a way in, which is exactly what agents are best at.GuestJerry Gamblin, creator of CVE.ICU and founder of RogoLabs. Resources mentionedFIRST 2026 mid-year vulnerability forecastSubscribewww.resilientcyber.io

AWS re:Think Podcast
Episode 51: Rethinking Cloud Security in the Age of Zero-Days and AI

AWS re:Think Podcast

Play Episode Listen Later Jun 10, 2026 42:20


Modern cloud environments are evolving faster than traditional security models can keep up. In this episode, we sit down with Yarin Pinyan, VP Products at Upwind, to explore how real-time runtime visibility and behavioral baselining are reshaping how organizations detect and respond to threats, especially zero-day and supply chain attacks that emerge before signatures or CVEs exist. We'll also discuss how AI is enabling a new generation of cloud security, where detection, investigation, and response happen continuously and automatically. The conversation highlights how organizations can reduce risk, improve operational efficiency, and protect critical workloads in dynamic, cloud-native environments.AWS MP offering: https://aws.amazon.com/marketplace/pp/prodview-ff3am62vjukrw?sr=0-1&ref_=beagle&applicationId=AWSMPContessaWebsite: https://www.upwind.io/Customer success story: https://www.upwind.io/case-studiesAWS Hosts: Nolan Chen & Ashok MahajanEmail Your Feedback: rethinkpodcast@amazon.com

Darknet Diaries
175: Bayrob

Darknet Diaries

Play Episode Listen Later Jun 2, 2026 96:35


It started with a fake car listing on eBay.What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cryptocurrency for someone else. Millions of dollars siphoned from victims who had no idea.This is the story of Bayrob and the three men from Romanian who were behind it. And the long, strange road that led American investigators to their door.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that's built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This episode is sponsored by Chainguard. Chainguard builds container images the right way — minimal, hardened, and built from source every single day. We're talking images with zero known CVEs, designed from the ground up for production. No bloat. No mystery packages. No 2 a.m. patching marathons because some transitive dependency lit up your dashboard. Stop patching images that are insecure. Start shipping clean. Head to chainguard.dev to see how secure your software supply chain can really be.

Critical Thinking - Bug Bounty Podcast
Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam)

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later May 28, 2026 110:49


Episode 176: In this episode of Critical Thinking - Bug Bounty Podcast we're joined by top Adobe hacker Jim Green to deep-dive AEM. We talk through Sling selectors, Permissions, and how to spot AEM Red Flags.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Adobe. Earn more for AI bugs with Adobe's new AI Tier! https://blog.adobe.com/security/adobe-expands-bug-bounty-program-to-incentivize-ai-security-researchAlso don't forget to also grab a 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.Expires June 30, 2026. ====== This Week in Bug Bounty ======Scaling Bug Bounty triage in the AI era(https://www.yeswehack.com/security-best-practices/scaling-bug-bounty-triage-ai)The AI impact: a triager's perspectivehttps://www.intigriti.com/blog/business-insights/the-ai-impact-a-triagers-perspective====== Resources ======Sling Selectors - The Key to Unlocking AEM's Attack Surfacehttps://greenjam.co.uk/blog/sling-selectors/Just a Moment CTFhttps://poc.greenjam.co.uk/just-a-moment.htmlGeneral XSS jquery .text()https://poc.greenjam.co.uk/text-xss.htmlURL XXS Challengehttps://poc.greenjam.co.uk/url-xss.html====== Timestamps ======(00:00:00) Introduction(00:04:35) Background and AEM Bug(00:17:40) Sling Selectors & the Tech Stack(00:38:14) Permissions & Apache Sling Resolution(01:01:37) The Bugs & AEM Red Flags(01:31:55) Moment in Time CTF(01:40:38) General XSS jquery .text()(01:45:45) URL XXS Challenge