POPULARITY
Interview Highlights: A Layered Toolset: LSU runs dual EDR platforms (Microsoft Defender and CrowdStrike), Splunk as its SIEM for log management, and Splunk SOAR (via partner TekStream) to coordinate incident response across the statewide SOC program. Phishing Remains Enemy #1: Across higher ed generally, phishing is the top entry point for attackers; Jain recalled a pre-MFA, pre-COVID incident where compromised accounts cascaded across multiple universities, forcing account suspensions every five minutes. AI on the Email Front Line: LSU uses AI specifically to catch executive impersonation—fake emails posing as the chancellor or vendors like Dell requesting changed payment routing numbers—flagging them for review before delivery. On the SOC side, AI builds context around alerts (device mismatches, unusual IP patterns) that a human analyst then validates before escalating—keeping a human in the loop rather than fully automating decisions. Fighting AI With AI—Proactively: LSU deploys honeypots, like a dummy Moodle instance, to lure AI-driven attackers, capture their IPs and techniques, then feed that threat intelligence into production systems to auto-block similar attacks before they happen. The Real AI Risk Is Data, Not the Tool: Jain's biggest concern with staff using ChatGPT, Copilot, or Claude isn't the AI itself—it's uploading sensitive student, HR, or research data to platforms that may train on it. Louisiana state law bars public institutions from using Chinese-linked LLMs; Jain flagged that individual (non-Enterprise) Cursor licenses can violate this because some underlying models have Chinese ties. Building Homegrown AI Tools: LSU faculty built "MikeGPT," an internal GPT-based tool on Azure, letting departments create custom agents—like one that lets students query a syllabus directly or an in-progress agent that answers questions from an 80-90 page data governance policy. Both hosts agreed that narrow, tailored AI tools solving specific institutional pain points—rather than general chatbot use—represent the most valuable and lowest-risk way to bring AI into daily operations.
Industrial Talk/BCC is talking to Rubin Domingo and Antonio Delgado, about "CISO Roundtable, Real Threats and Real Decisions impacting the market". Overview The roundtable examined practical cybersecurity risks and emphasized that security is a business responsibility, not solely an IT function. Key Risks Rubenidentified concentration among major service providers and uneven cybersecurity maturity among smaller public bodies as significant threats.Antoniohighlighted ransomware, phishing, social engineering, and third-party risk as more immediate concerns than highly publicized AI attack scenarios. Resilience Priorities Organizations should prepare before an incident through containment plans, crisis communications, tested backups, alternate service instances, and provider redundancy.Manufacturing environments need asset visibility, IT/OT network separation, and controls for legacy systems and connected devices.Leadership should evaluate cyber risk alongside financial and legal risk; cyber insurance increasingly requires evidence of controls such as MFA, backups, incident response, training, EDR, and vulnerability management. Open Questions How can smaller organizations achieve adequate cybersecurity maturity with limited resources?How should organizations adopt AI while protecting sensitive and critical data? Action Items Broadcast from the Barcelona Cybersecurity Congress in Barcelona on November 3–5, 2026. (@Scott Mackenzie) Outline Participants and Roles Ruben: Technology and cybersecurity director for a public organization representing Catalan municipalities and the regional government; advisory board member of the Global CISO Council Spain chapter.Antonio: CISO in an international education group serving schools across Europe, Latin America, and the United States. Real Threats Versus Noise Service-provider concentration can create broad systemic outages.Smaller municipalities and organizations often lack dedicated cybersecurity resources.Ransomware, phishing, social engineering, and third-party weaknesses remain operationally relevant. Incident Preparedness Contain affected systems first, coordinate communications, and restore services from prepared alternate environments.Regulation and frameworks such as ISO 27001 and Spain's National Security Scheme can drive preparedness. Manufacturing and Education Manufacturing requires IT/OT separation, visibility into connected assets, and legacy-system risk management.Schools require layered identity controls, MFA, awareness training, phishing simulations, and protection of minors' data. AI, Leadership, and Insurance AI should be adopted with policies, training, and controls against sensitive-data exposure.CISOs should communicate business impact and risk to boards rather than focusing only on technical controls.Cyber insurance validates organizational maturity and can support recovery after an attack. If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation. Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy! RUBEN CORTES DOMINGO'S CONTACT INFORMATION: Personal LinkedIn: https://www.linkedin.com/in/rubencortes/ Company LinkedIn: https://www.linkedin.com/company/consorci-aoc-2/home/ Company Website: https://www.aoc.cat/en/ ANTONIO DELGADO'S CONTACT INFORMATION: Personal LinkedIn: https://www.linkedin.com/in/antoniodelgadociso/ Company LinkedIn: https://www.linkedin.com/company/affinitas-education/home/ Company Website: https://www.affinitasedu.com/ PODCAST VIDEO: https://youtu.be/eQThmKVowOY THE STRATEGIC REASON "WHY YOU NEED TO PODCAST": OTHER GREAT INDUSTRIAL RESOURCES: NEOM: https://www.neom.com/en-us Hexagon: https://hexagon.com/ Arduino: https://www.arduino.cc/ Fictiv: https://www.fictiv.com/ Hitachi Vantara: https://www.hitachivantara.com/en-us/home.html Industrial Marketing Solutions: https://industrialtalk.com/industrial-marketing/ Industrial Academy: https://industrialtalk.com/industrial-academy/ Industrial Dojo: https://industrialtalk.com/industrial_dojo/ We the 15: https://www.wethe15.org/ YOUR INDUSTRIAL DIGITAL TOOLBOX: LifterLMS: Get One Month Free for $1 – https://lifterlms.com/ Active Campaign: Active Campaign Link Social Jukebox: https://www.socialjukebox.com/ Business Beatitude the Book Do you desire a more joy-filled, deeply-enduring sense of accomplishment and success? Live your business the way you want to live with the BUSINESS BEATITUDES...The Bridge connecting sacrifice to success. YOU NEED THE BUSINESS...
Replay of Episode 178, originally published April 22, 2026.We are re-running this one because it is the question we get asked moston internal pen test debriefs: of everything on the list, what actuallyslows an attacker down? Spencer and Tyler answer it from the attackerside, using what has and has not stopped them on real engagements.What's covered:- Application control done right, including where ThreatLocker and WDAC actually block a payload and where they get bypassed- MFA, the Protected Users group, and least privilege as attacker-facing controls rather than compliance checkboxes- Why mismanaged admin privileges and service accounts remain the fastest route from foothold to domain admin- Network segmentation and zero trust, and what separates a real implementation from a diagram- Deception techniques and EDR baselining for catching activity that looks legitimateIf you are deciding where the next dollar of your security budget goes,this is the episode that tells you what attackers hope you skip.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-475
Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-475
Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-475
Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-475
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 112: The 'OpenAI hacks Hugging Face' fallout has turned into a story about AI civilizations rising from the ashes, politicians calling for super-intelligence bans, and the emergence of well-funding non-profits doing AI safety work. Who are these people and what's their security expertise? Plus, GPT-6 Astra lands in a trusted-access program nobody can get into, Costin ranks the local models he runs next to his desk, and CrowdStrike sinkholes a botnet that's been alive since 2003. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 1:02 Conference season: LabsCon, Offensive AI Con, Countermeasure 5:40 The Hugging Face story hits the front page 7:04 Dwarkesh, Greenblatt, and the AI-pilled framing 11:51 Swap "agents" for "Python" and the panic goes away 16:34 Does anyone actually know what happened? 21:18 Bernie Sanders wants to ban superintelligence 34:03 Defending against swarms: the 2026 SOC 39:15 Logs, Splunk, and the business model in the way 44:11 What EDR vendors are actually building with AI 56:16 The security poverty line and the endgame 1:07:53 GPT-6 Astra, Fable 5.1, and local model rankings 1:27:25 Google's Fairwind, CodeMender, and agents running Linux 1:45:31 Apple's bet on local inference 1:53:21 The Sality takedown and endgame advice
When someone calls 911, help doesn't begin when the first responder arrives at the door. It begins with the person on the other end of the phone.Public safety telecommunicators are often the first point of contact during someone's worst moments. They must gather critical information, make decisions under pressure, communicate with people in crisis, coordinate resources and, in some situations, provide lifesaving instructions while remaining calm and focused.In this episode of Bluegrass Beat, host Critley King-Smith and Andrea Hale, Kentucky Department of Criminal Justice Training Public Safety Dispatch Supervisor, discuss what it takes to be an effective public safety telecommunicator and how the Public Safety Dispatch Academy's new curriculum is preparing dispatchers for the realities of the job.Andrea explains the many roles a dispatcher must fill: detective, crisis communicator, multitasker, decision-maker, lifeline and more. They take a look at PSDA's updated curriculum, what's changed and how the new training is designed to develop the skills dispatchers need in today's public safety environment.…The Bluegrass Beat is recorded and produced by the Kentucky Department of Criminal Justice Training's Public Information Office, a proud member of Team Kentucky. Like what you hear? We appreciate everyone who takes the time to subscribe and rate this podcast.Have a suggestion? Email host Critley King-Smith at critley.kingsmith@ky.gov to share feedback. Music by Digital Juice and StackTraxx.Sound Effects• Phone ring by EdR from Pixabay• Phone answer by freesound_community from PixabayAll episodes are edited for clarity and content.
Last year Snehal Antani keynoted Black Hat alongside the NSA to share a number that should worry every security leader: full domain compromise on a defense industrial base supplier in 77 seconds. Antani is the co-founder and CEO of Horizon3.ai, and he built the autonomous AI hacker, NodeZero, that ran that test.In this conversation we get into why "compliant" and "secure" stopped being the same thing, why AI attackers are actually more gullible than most people assume, and what changes when a security team can pentest its own environment continuously instead of once a year.What you'll learn: why security has become an evidence problem, not a visibility problem, and what that means for GRC teams who spend their careers documenting controls. How a 9-year-old used Horizon3's product to hack a bank in 4 minutes and 12 seconds with no prior experience. Why AI attackers are more gullible than human ones, and how honeypots and honey tokens exploit that gullibility. What NodeZero Tripwires are, and how they turn a completed pentest into an early warning system for real attackers. Why NodeZero's 325,000-plus production-safe pentests make Horizon3 a data company first and a pentesting company second. What made web applications the hardest domain for autonomous pentesting to crack, and why that's changing fast. How blue team agents now auto-fix problems like a misconfigured EDR in real time, during the pentest itself. Why "prove you're resilient" is replacing "hope you are" as the new standard for CISOs.This video was produced in partnership with Horizon3.ai. All opinions are Snehal's own. Learn more about Horizon3's autonomous pentesting platform: https://horizon3.ai/simplycyber If this was useful, subscribe to Simply Cyber for more conversations like this one.Chapters:0:00 Cold Open, "If You Can't Stop Us in 76 Seconds, It's Game Over"1:04 Why Security Has Become an Evidence Problem, Not a Visibility Problem2:36 How AI Compressed Attacker Economics From Weeks to Minutes3:39 Why AI Attackers Are Gullible, and How Honeypots Exploit It4:27 What Evidence Actually Looks Like for a Security Team on an Ordinary Tuesday5:55 Where AI Makes Defenders Faster vs Where It Makes Them Complacent7:26 Inside NodeZero, How an Autonomous AI Pentest Actually Works9:44 What 325,000 Pentests Taught Horizon3 That Annual Testing Never Could11:26 NodeZero Tripwires, Turning a Completed Pentest Into a Threat Hunt12:49 Why Web Applications Are the Hardest Target for Autonomous Pentesting15:00 How to Prove an Autonomous AI Pentest Is Safe to Run in Production18:27 Inside the $250M Raise and the Road to a $2 Billion Valuation20:50 What It Takes to Earn Trust From the NSA and CISA23:00 Why "Prove You're Resilient" Is Replacing "Hope You Are"=========================Simply Cyber empowers people who want a rewarding cybersecurity career
If someone on your team clicks a phishing email tonight, the tools your SOC already has running decide whether you catch it in minutes — or read about it in a breach report six months from now.In this episode: the 8 core tool categories every blue team runs — SIEM, EDR, network detection, vulnerability management, SOAR, threat intelligence, forensics, and free open-source practice tools — the specific products that show up most in real SOC analyst job postings, and how to start building hands-on skill with them before you have a job title that says "security."Full written breakdown: https://blueteam-academy.com/blog/top-cybersecurity-tools-blue-teams/Watch the video version: https://blueteam-academy.com/videos/top-cybersecurity-tools-blue-teams-2/Ready to move from IT into cybersecurity? https://www2.blueteam-academy.com/from-it-to-cybersecurity/Get the next episode before it's old news — Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signupTIMESTAMPS00:00 Why the tools you run decide the outcome01:15 The 8 core tool categories02:15 SIEM & log analytics03:16 EDR & XDR04:56 Network detection05:57 Vulnerability management06:50 SOAR & automation07:51 Threat intelligence09:40 Forensics & incident response10:19 Free tools to build a SOC on your own laptop11:11 The mistake most teams — and learners — make12:20 How to build hireable skill with this stack
Shortly after the final Enduro World Cup race of the 2026 season, Warner Brothers Discovery and the UCI made the surprise announcement that the series will not continue for 2027. Despite the uncertain future that leaves for top-tier professional Enduro racing, the announcement was met with a surprising amount of excitement from athletes, and a real sense of optimism that something better can rise from the ashes of the short-lived EDR series. So we brought professional racer Eric Olsen back on the show to discuss all of it. The full press release from the UCI can be read here. Note: We Want to Hear From You! Please share with us the questions, topics, or stories you'd like us to cover on Bikes & Big Ideas. You can email us at: info@blisterreview.com RELATED LINKS: Momentous: livemomentous.com use code: Blister OneSkin: oneskin.co/BLISTER Get Yourself Covered: BLISTER+ Blister Mountain Bike Buyer's Guide TOPICS & TIMES: The state of professional Enduro racing (1:42) Online perception vs. reality on the ground (4:13) Broadcasting & marketing Enduro racing (9:29) The Enduro World Series becoming the Enduro World Cup (12:53) New possibilities for Enduro racing (17:43) Eric's vision for what comes next (20:28) Crankworx's announcement of a new series (32:21) How has (and hasn't) the series changed in recent years? (35:39) Optimism for the future (40:24) CHECK OUT OUR OTHER PODCASTS: The Vault Blister Cinematic CRAFTED GEAR:30 Blister Podcast
The concept of EDR is flawless, but complex federal environments present distinct operational hurdles. In this week's episode of Feds At The Edge, we dive into Endpoint Detection and Response (EDR) in the federal government and explore how expert-suggested approaches can help agencies overcome today's barriers. While EDR provides continuous monitoring and automated containment across agency devices, federal civilian networks face unique challenges in practice. Broadcom's Paul Miller admits that EDR's core weakness is its reactive nature, discussing how AI can be applied to "move left" of an attack by leveraging historical data to predict threats before they strike. Meanwhile, Broadcom's Sam Romo breaks down the difficulty of defending against machine-speed attacks as AI increases the velocity of standard signature-based threats. Together, the panel examines how today's AI-assisted, adaptive EDR can serve as a vital protective layer for the fragile legacy systems embedded throughout agency cybersecurity stacks. Tune in on your favorite podcast platform for practical insights on how federal agencies can strengthen endpoint security and stay ahead of increasingly sophisticated threats.
Shortly after the final Enduro World Cup race of the 2026 season, Warner Brothers Discovery and the UCI made the surprise announcement that the series will not continue for 2027.Despite the uncertain future that leaves for top-tier professional Enduro racing, the announcement was met with a surprising amount of excitement from athletes, and a real sense of optimism that something better can rise from the ashes of the short-lived EDR series. So we brought professional racer Eric Olsen back on the show to discuss all of it.The full press release from the UCI can be read here.Note: We Want to Hear From You!Please share with us the questions, topics, or stories you'd like us to cover on Bikes & Big Ideas. You can email us at: info@blisterreview.comRELATED LINKS:Momentous: livemomentous.com use code: BlisterOneSkin: oneskin.co/BLISTERGet Yourself Covered: BLISTER+ Blister Mountain Bike Buyer's GuideTOPICS & TIMES:The state of professional Enduro racing (1:42)Online perception vs. reality on the ground (4:13)Broadcasting & marketing Enduro racing (9:29)The Enduro World Series becoming the Enduro World Cup (12:53)New possibilities for Enduro racing (17:43)Eric's vision for what comes next (20:28)Crankworx's announcement of a new series (32:21)How has (and hasn't) the series changed in recent years? (35:39)Optimism for the future (40:24)CHECK OUT OUR OTHER PODCASTS:The VaultBlister CinematicCRAFTEDGEAR:30Blister Podcast Hosted on Acast. See acast.com/privacy for more information.
The episode highlights the structural shift toward platform consolidation in security services, illustrated by Coro's unified security platform and its positioning for lean IT teams and MSPs. The mechanism involves the bundling of diverse security tools—email protection, endpoint detection and response (EDR), DLP, security awareness, backup, and cloud app integrations—into a single, managed service. This reduces the operational overhead associated with managing multiple vendors, products, and contracts, a trend now pursued by both established enterprise providers and emergent channel-focused companies. The most significant development cited is Coro's integration of AI and automation within its platform, claiming, according to the company, that 92% to 96% of alert tickets generated by security modules are closed automatically by machine intelligence, depending on the month. The conversational AI integrations such as ChatGPT and Claude are presented as front-end layers through which practitioners can execute mundane security tasks—ticket management, host isolation, incident correlation—without direct console interaction. The claim of offloading 95% of workloads to automation is specified as relating to ticket processing volume, as clarified in the discussion. Supporting evidence centers on the operational layering of AI, with commentary on new risk profiles introduced by integrating large language models (LLMs) into security workflows. Concerns raised include rising exposure to prompt injection, shadow AI (untracked AI usage by end users), and unmanaged cost escalation linked to token-based billing models for third-party AI platforms. Coro's approach distinguishes between AI-related costs incurred internally (absorbed by the vendor) and those incurred when practitioners interact with external AI tools (borne by the MSP or their clients). The need for visibility into AI usage and structured user training is highlighted as a risk mitigation measure. Operationally, MSPs and IT providers face both increased efficiency and new complexity. Vendor dependency consolidates, reducing contract sprawl and administrative burden but raising questions about single-point-of-failure and stack lock-in. Billing risk shifts with AI consumption models, introducing liability for unexpected operational cost surges if token limits are not enforced. The requirement for effective governance intensifies as traditional security controls are extended by AI-managed processes and the detection of unauthorized AI activity becomes part of standard oversight. Providers are advised to scrutinize stack overlap, evaluate whether platform consolidation minimizes genuine operational friction, and remain cautious about over-relying on automated outcomes without maintaining direct accountability. Supported by: Pax8Proofpoint
Mai menü: EDR without kernel mode Clamav sérülékenységek AI assistant hacks gym website in first known Australian autonomous cyber attack - ABC News Elérhetőségeink:TelegramTwitterInstagramFacebookMail: info@hackeslangos.show
Got a question or comment? Message us here!Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.
When Claude Cowork hits a roadblock, it doesn't give up, it writes a custom Python script and downloads an untrusted NPM package just to bypass its restrictions and finish its goal. Are your security tools close enough to stop it? In this episode, Ashish sits down with Michael Leland, VP, Field CTO at Island, to discuss the critical need for an Agentic Control Plane. Michael breaks down why traditional security silos (EDR, DLP, CASB) fail to provide visibility when autonomous AI agents execute tasks outside the network, and why the browser is the ultimate line of defense for monitoring user intent. We explore the massive reality of Shadow AI and the hidden danger of well-intentioned employees accidentally hooking up sensitive data to public LLMs. Finally, Michael shares practical strategies for solving token waste through "model fit steering" and managing the complex "two-hop problem" when an agent calls another agent.Guest Socials - Michael's Linkedin Podcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter If you are interested in AI Security, you can check out our sister podcast - AI Security PodcastQuestions asked:(00:00) Introduction to the Agentic Control Plane(01:50) Michael Leland's Background (Cabletron, Nitro Security, SentinelOne)(03:20) Why Island Evolved from the Browser to the Desktop for AI(05:50) The Failure of Traditional Siloed Security (EDR, DLP, CASB)(07:20) Goal-Oriented AI: How Claude Cowork Downloads Untrusted NPM Packages(08:30) Model Fit Steering: Routing Users to the Right LLM for the Right Price(10:30) The Threat of Malicious AI Skills and Plugins(11:30) The Well-Intentioned Insider Threat (The Next Cambridge Analytica)(13:00) Uncovering Shadow AI: From 8 Tools to 243(15:10) Token Brokering at the MCP Gateway(16:40) Protecting Non-Human Identities (NHI)(18:20) Solving the "Two-Hop" Problem (Agent-to-Agent Communication)(21:00) Fixing Hallucinations with Corporate RAGs(25:40) Calculating AI ROI Beyond "Token Maxing"(28:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge
Recorded on site at Black Hat USA 2026 in Las Vegas, Seth Summersett joins Sean Martin to talk through the volume problem that shapes a modern security operations team. Seth Summersett spent about a decade at the NSA and roughly a decade at Mandiant, finishing there as head of innovation and custom engineering, then a couple of years at Meta supporting business unit level CISOs. He co-founded Embed Security with Jeffrey Johns, who ran the data science team alongside him at Mandiant. The catalyst came from watching a managed service run on human scale day after day. Two analysts and a hundred forwarded phishing emails means someone is choosing which ones to open and carrying the ones they cannot reach. Embed Security sits downstream of existing detection investments, taking signals from SIEM, EDR, identity, and email rather than asking a team to rip and replace what it already runs. What do security analysts actually want from AI in the SOC? According to Seth Summersett, it is not a verdict. Analysts want the work off their plate in a way they can verify, which is why Embed Security built what it calls chain of evidence, showing every question asked and the path to each conclusion. Teams also test it in reverse, running previously dispositioned alerts back through the platform to compare results against their own analysts. The numbers come from a competitive bake off at one of the company's largest clients. Embed Security dispositioned roughly 75% of that client's alerts to the point where the team stopped treating them as primary work, against a daily volume above 10,000 alerts. Why not build this in house? Seth Summersett says the demo is the easy part. What follows is evaluation loops that measure a change across hundreds of thousands of alerts rather than one, governance, and a way to capture organizational knowledge automatically. In regulated sectors, auditors may ask a team to prove how a conclusion was reached and that it holds consistently. There is a people side to this as well. Embed Security has supported a wellness program at BSides across its last two events, backing a calming kit and curriculum for analysts working under incident pressure. Seth Summersett closes with consistency for leaders, since a leader looking at 10% of alerts does not have a full risk profile, and career longevity for analysts who would rather build a long run in security operations than burn out in two or three years. GUEST Seth Summersett, Co-Founder and CEO, Embed Security LinkedIn: https://www.linkedin.com/in/summersett/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Embed Security: https://www.embedsecurity.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS seth summersett, embed security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, security operations, soc analyst burnout, alert triage, agentic ai security, chain of evidence, siem alert fatigue, edr alerts, ai soc platform, security analyst workflow, build versus buy security ai, security operations governance, threat investigation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K's Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund' to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
The episode details a structural shift for MSPs and IT service providers: the separation of security license resale from the value of human-led security services, and the resulting pricing and margin risks. Companies like N-able, SentinelOne, and SonicWall exemplify how technology offerings and delivery mechanisms are forcing providers to re-examine what differentiates their services beyond the products they resell. N-able's financial results illustrate the risk of relying on product-based security revenue. The company reported a drop in annual recurring revenue, driven by lower renewal rates in Unified Endpoint Management and Endpoint Detection and Response lines—both of which relied on reselling portable licenses, notably SentinelOne's product. In contrast, revenue from services tied to human expertise—through the acquired Adlumen's managed detection and response (MDR)—grew, according to both N-able management and analysts. The episode states that when customers can move licenses without losing service continuity, price becomes the only differentiator, undermining provider margins. Related developments reinforce this dynamic. SonicWall launched a combined antivirus and EDR solution available as both a product and a managed service—explicitly marketed for MSP resale—where SonicWall's analysts handle detection and response. Additionally, Proofpoint expanded its managed services platform, providing security, backup, and compliance through an MSP-oriented, multi-tenant console. These offerings blur the line between manufacturer-managed services and traditional MSP-delivered security work, increasing vendor competition at the service layer. For MSPs and IT leaders, these shifts expose the risk in revenue models that bundle security services with third-party product resale, particularly when those products are easily substitutable. The transcript urges providers to re-evaluate their pricing strategies: separating human service from license cost, justifying it independently, and moving away from device- or seat-based billing. The clear risk is that failing to articulate and defend the value of human-led activities will leave providers vulnerable to vendor undercutting and margin erosion, as seen in recent N-able outcomes. 00:00 Recurring Revenue Went Backwards 03:24 They Stopped Saying RMM 06:04 You Already Own It 09:18 Why Do We Care? Supported by: Guardz
Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams. So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it. Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first. How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities. He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop. His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sumedh Thakar, President and CEO at Qualys On LinkedIn: https://www.linkedin.com/in/sumedhthakar/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned.In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire left and right, while Spencer runs nearly identical tooling against the same product at another client and the SOC sees nothing all week. Same CrowdStrike. Same version. Different checkboxes.From there it's a tactical walkthrough of Endpoint Security → Prevention Policies and the settings worth your attention: Enhanced Exploitation Visibility, which unlocks command-line and PowerShell telemetry that Microsoft disables by default; Enhanced DLL Load Visibility for side-loading attacks; WSL2 Visibility, which closes a sandbox threat actors have been using to run Kali tooling under the radar; memory scanning for in-memory C# tradecraft; Office malicious macro removal; file system containment for ransomware over SMB; vulnerable driver protection, the direct mitigation for BYOVD attacks and EDR killers; and cloud-based anomalous process execution for living-off-the-land binaries.They also cover custom IOA rule groups for blocking unauthorized RMM tools, centralized firewall policy management, device policies for USB control, and a warning on exclusions — especially wildcard paths, which Tyler calls a threat actor's best dream.The takeaway is simple: you're paying real money for EDR, and default configurations aren't giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment.TOPICS COVERED- Why EDR vendors ship deficient defaults on purpose- Enhanced Exploitation Visibility and the telemetry gap in PowerShell attacks- DLL side-loading, WSL2 abuse, and vulnerable driver attacks- Memory scanning and in-memory tooling detection- Blocking RMM tools with custom IOA rule groups- Exclusion hygiene and the wildcard path problem- Device policies, USB blocking, and insider threatSentinel One and Defender for Endpoint are next — let us know what else you want covered.Blog: https://offsec.blogWork with us on an internal pen test: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
“Let your engineers get back to doing what makes you money.” In this Technology Reseller News podcast recorded at ChannelCon 2026, Heather Harlos, Demetrios “Deme” Georgiou and Benjamin Morrell, of Coro Cybersecurity discuss how consolidating security tools can help MSPs reduce complexity, improve margins and serve more customers. Coro brings email security, endpoint protection, EDR, data loss prevention, VPN, secure web gateway, security awareness training, cloud protection and backup into a single platform. It is designed primarily for SMBs and midsized organizations with limited internal IT and security resources. Many MSPs recognize that they have a tool-sprawl problem but hesitate to replace products and vendor relationships they have relied on for years. “Consolidation is a very big objective for channel partners,” the Coro team says. “The challenge is making that change their new normal.” For MSPs, the value extends beyond lowering software costs. A unified platform reduces the time engineers spend moving between consoles, investigating alerts and managing separate systems. That additional capacity can be used to onboard customers, develop new services and increase revenue. Coro uses AI to filter security noise and surface the information that requires attention. The platform is also designed to scale easily across customers of different sizes. The team says smaller businesses are increasingly being targeted by phishing, ransomware and automated attacks. Although these organizations may lack enterprise security budgets, they still expect their MSPs to deliver effective protection. At the same time, MSPs must differentiate themselves through service rather than simply reselling a collection of tools. “Customers should buy from the channel partner because of the partner—not just because of the software being sold,” the team says. By simplifying security operations, Coro aims to help MSPs support more customers without continually adding personnel. Time and resources can then be redirected toward higher-value services, including new AI projects and business growth. Visit Coro.net to learn more.
Max talks with Maya Shpak, CEO of SkyPath, about how pilots can avoid turbulence and find smoother air by combining crowdsourced observations, aircraft data, and machine-learning predictions. The idea for SkyPath came from an airline captain and check airman who encountered turbulence and realized that the iPad already carried in the cockpit contained accelerometers capable of measuring aircraft movement. Much like a traffic app gathers information from phones on the road, SkyPath could collect ride-quality observations from participating aircraft, send them to the cloud, and return an updated turbulence picture to other pilots. Maya says the system now receives data from about 40,000 users each day. An iPad observation is only one of five sources used by SkyPath. The system filters accelerometer readings, removes noise, and normalizes each report for aircraft type. That adjustment is important because light turbulence in a large business jet may feel moderate in a smaller general aviation airplane. When two pilots have iPads aboard the same aircraft, SkyPath can compare the two devices and identify a questionable reading. SkyPath also derives turbulence information from ADS-B vertical-rate data. Many aircraft provide both ADS-B reports and iPad observations, allowing the company to compare the two and refine its conversion algorithm. This expands coverage into areas where no participating iPad-equipped aircraft has recently passed. The platform also incorporates PIREPs and eddy dissipation rate, or EDR, reports. EDR is an aircraft-independent measure of atmospheric turbulence widely used in commercial aviation. SkyPath can convert its sensor information into EDR-compatible reports while using existing EDR data to supplement its own observations. The fifth source is SkyPath's predictive model. More than 200 meteorological parameters from NOAA and other government sources are fed into a machine-learning system trained with SkyPath's observational data. This produces estimated ride conditions where direct reports are limited. Maya says this is particularly useful to general aviation pilots flying below normal airline cruise altitudes, although the company generally sees better accuracy above about 5,000 feet. Pilots can use SkyPath before takeoff or during a flight. They may enter a call sign or flight number, paste a route from another electronic flight bag, or operate without a filed IFR flight plan. In its bearing mode, the app monitors an area approximately 100 miles ahead and 15 degrees to either side of the aircraft's direction of flight. It can run in the background and generate an alert about ten minutes before the airplane reaches significant turbulence. For larger operators, the same information can also be delivered through SkyPath's own flight-following tools or integrated EFB systems. Pilots can set the alert threshold, place the app in the background, and continue using their primary navigation display. Dispatchers may receive warnings when an aircraft is approaching rough air and then contact the crew through the operator's normal communications system. Maya says SkyPath was not yet integrated with ForeFlight at the time of the interview, although routes can be copied from ForeFlight into the app. The altitude slider helps pilots compare ride conditions above and below their planned or current altitude. This can support a decision to climb, descend, or choose a different cruising altitude before departure. SkyPath also displays validated smooth-air observations as white hexagons. Knowing where the air is smooth can be more actionable than simply seeing where rough air has been reported. The display uses familiar aviation colors to represent smooth, light, light-to-moderate, moderate, and occasional severe turbulence. Observed and predicted areas appear differently, allowing pilots to distinguish between actual aircraft encounters and conditions generated by the forecast model. Users can filter the display to emphasize the severity levels most relevant to their aircraft and operation. Maya says access to better turbulence information can change pilot behavior. One business aviation operator using SkyPath reported nearly a 50 percent reduction in moderate-turbulence encounters. SkyPath also reviewed 180 published turbulence incidents and found that matching information had been available beforehand in 79 percent of them. The app may also improve communication with passengers. Maya describes pilots showing charter passengers where rough air is expected and when it should end. That visual explanation can help nervous flyers understand why they need to remain seated and keep their seatbelts fastened. Unexpected turbulence can produce injuries, diversions, medical expenses, airport fees, passenger accommodations, replacement-aircraft costs, and schedule disruptions. Even an unsecured passenger, flight attendant, or hot drink can create a serious event. Better information gives pilots more opportunity to avoid the roughest areas or prepare everyone aboard before reaching them. Finally, SkyPath allows pilots to submit a digital PIREP from the app directly into the FAA reporting system. Individual pilots can begin with a free trial and choose between subscription levels. Maya explains how SkyPath is designed to supplement the navigation and weather tools pilots already use while providing a more detailed picture of where they may find rough or smooth air. If you're getting value from this show, please support the show via PayPal, Venmo, Zelle or Patreon. Support the Show by buying a Lightspeed ANR Headsets Max has been using only Lightspeed headsets for nearly 25 years! I love their tradeup program that let's you trade in an older Lightspeed headset for a newer model. Start with one of the links below, and Lightspeed will pay a referral fee to support Aviation News Talk. Lightspeed Delta Zulu Headset $1299NEW – Lightspeed Zulu 4 Headset $1099 Lightspeed Zulu 3 Headset $949Lightspeed Sierra Headset $749 My Review on the Lightspeed Delta Zulu Send us your feedback or comments via email If you have a question you'd like answered on the show, let listeners hear you ask the question, by recording your listener question using your phone. News Stories FAA Expands Approval List For Swift Fuels' 100R Unleaded Avgas FAA Accepts New MOSAIC Light-Sport Standards ForeFlight's Newest Feature ClearNOTAMs Industry urges Congress to provide $20 billion for air traffic control upgrades New Sentry SkyPlay Brings ForeFlight to the Instrument Panel Redbird Unveils G1000 NXi Emulator, Enhanced Simulator Panel Lightspeed Headset Customized For Rotax Power Bad Boy's File: Florida Speeder May Miss His Checkride Mentioned on the ShowBuy Max Trescott's G3000 Book Call 800-247-6553 SkyPath Turbulence App Free Index to the first 282 episodes of Aviation New Talk So You Want To Learn to Fly or Buy a Cirrus seminars Online Version of the Seminar Coming Soon – Register for Notification Check out our recommended ADS-B receivers, and order one for yourself. Yes, we'll make a couple of dollars if you do. Get the Free Aviation News Talk app for iOS or Android. Check out Max's Online Courses: G1000 VFR, G1000 IFR, and Flying WAAS & GPS Approaches. Find them all at: https://www.pilotlearning.com/ Social Media Like Aviation News Talk podcast on Facebook Follow Max on Instagram Follow Max on Twitter Listen to all Aviation News Talk podcasts on YouTube or YouTube Premium "Go Around" song used by permission of Ken Dravis; you can buy his music at kendravis.com If you purchase a product through a link on our site, we may receive compensation.
No Password Required: Next Gen - Ep. 3 - Kieran Human How Lead Cybersecurity Engineers Actually Think In this episode of No Password Required: Next Gen, Yazzel interviews Kieran Human, Lead Cybersecurity Engineer at ThreatLocker. From research to working directly with ThreatLocker's CEO on new security initiatives, Kieran gives an inside look at what it's really like to work on the front lines of cybersecurity. Kieran stands out as a cybersecurity professional by hares why curiosity, strong communication, and understanding the bigger picture are just as valuable as technical skills. He also reflects on one of his proudest career moments, writing a compliance white paper that earned praise from ThreatLocker's CEO Danny Jenkins, and explains how that experience reinforced the importance of research, writing, and always looking for ways to improve. Kieran also explains why Zero Trust security is becoming essential, teaches viewers a few cybersecurity terms that are guaranteed to impress at dinner, and even reveals why the Terminator would be his ultimate cybersecurity teammate! Whether you're exploring a career in cyber or looking for practical advice from someone working in the field every day, this episode is packed with insights for the next generation of cybersecurity professionals. Presented by ThreatLocker Supported by DerScanner Follow Kieran on Linked in here: https://www.linkedin.com/in/kieran-human-5495ab170/ Chapter List: 00:00 Introduction to Cybersecurity and Career Path 02:54 Key Skills and Qualities for Success in Cybersecurity 06:07 Impact of AI and Zero Trust in Cybersecurity 06:56 Fun Insights and Closing Thoughts
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs
Hackers target Thailand's Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
In this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections. LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR products. What once might have taken months of manual reversing can now be accelerated by “burning tokens”. The takeaway is that defenders increasingly need to assume attackers have visibility into how their endpoint security products work. Show notes
Nadav Cornberg, CEO of Eve Security, highlights the need for real-time security for agentic AI in healthcare environments to enforce policies and map agentic activities within an organization. There are unique risks posed by AI, such as ambiguity from natural language commands, the potential for unintended or malicious actions, and the amplified impact of a single AI error compared to human error. Nadav points out that many hospitals are likely unaware of the extent to which agentic AI is already active in their systems, and of why conducting risk assessments and policy reviews should be a priority. Nadav explains, "Eve Security provides two main services. One is our runtime security solution, which allows us to enforce policies when you connect any type of AI agent to a critical data source or system. The other solution that we provide is our AIDR, where we give you a full topology of what agentic activities are running in your organization. We do that by connecting to security systems like an EDR, NextGen Firewall, or your SIM." "Just like we'll see a manager in the employee environment, in the physical world, that's why we have managers as well to guide employees on the work they want to do. How that works is we sit either on top of existing gateways or proxies, and that's how you will connect those agents to critical systems, or we connect to hooks." "At the end of the day, the reality of how we're communicating and engaging with agents brings that new necessity. Existing security tools do not deal well with natural language. In addition to not dealing well with natural language, they're not doing well with trying to understand the true intent behind an action, and it's more built on static parameters. And that's the real gap that introducing AI agents into environments has brought. The risks are ambiguity and the unpredictable, non-deterministic behavior." #EveSecurity #AgenticAISecurity #SecurityatRuntime #AISecurity #HealthcareAI #PatientSafety #HospitalSecurity #AgenticAI #CyberSecurity #HealthIT #DataProtection Eve.security Download the transcript here
Nadav Cornberg, CEO of Eve Security, highlights the need for real-time security for agentic AI in healthcare environments to enforce policies and map agentic activities within an organization. There are unique risks posed by AI, such as ambiguity from natural language commands, the potential for unintended or malicious actions, and the amplified impact of a single AI error compared to human error. Nadav points out that many hospitals are likely unaware of the extent to which agentic AI is already active in their systems, and of why conducting risk assessments and policy reviews should be a priority. Nadav explains, "Eve Security provides two main services. One is our runtime security solution, which allows us to enforce policies when you connect any type of AI agent to a critical data source or system. The other solution that we provide is our AIDR, where we give you a full topology of what agentic activities are running in your organization. We do that by connecting to security systems like an EDR, NextGen Firewall, or your SIM." "Just like we'll see a manager in the employee environment, in the physical world, that's why we have managers as well to guide employees on the work they want to do. How that works is we sit either on top of existing gateways or proxies, and that's how you will connect those agents to critical systems, or we connect to hooks." "At the end of the day, the reality of how we're communicating and engaging with agents brings that new necessity. Existing security tools do not deal well with natural language. In addition to not dealing well with natural language, they're not doing well with trying to understand the true intent behind an action, and it's more built on static parameters. And that's the real gap that introducing AI agents into environments has brought. The risks are ambiguity and the unpredictable, non-deterministic behavior." #EveSecurity #AgenticAISecurity #SecurityatRuntime #AISecurity #HealthcareAI #PatientSafety #HospitalSecurity #AgenticAI #CyberSecurity #HealthIT #DataProtection Eve.security Listen to the podcast here
Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It's shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability scans. Meta faces trillion dollar fines in state lawsuits. Our guest is Russ Anderson, COO and co-founder of RapidFort, sharing a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. When it comes to breaches, mum's the word. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Russ Anderson, COO and co-founder of RapidFort, is sharing the Linux Foundation's Akrites initiative, a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. Selected Reading Accenture confirms breach after hacker offers stolen data for sale (Bleeping Computer) Nationwide Telstra outage disrupts thousands, raises questions of foreign launched cyberattack (The Nightly) Britain plans to build autonomous AI 'Cyber Shield' to defend nation (The Record) CISA Eyes September Date for Final Cyber Incident Reporting Rule (MeriTalk) HUMAN Security Disrupts CTV Device Spoofing Operation "NewsJunkie" (Globe Newswire) When AI agents look like attackers: what behavioral telemetry tells us (SOPHOS) Space Force adds Relativity, Impulse Space to national security launch program. (Space News) CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code (Security Affairs) Mark Zuckerberg's biggest legal nightmare yet could cost Meta $1.4 trillion (The Independent) Most cybersecurity workers have been told to conceal a breach, report finds (Cybersecurity Dive) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections. This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do we solve security? And how much of that solution is about agents, vs building a good graph? And if you're going to build a good graph, do you want to build it for a person to use, or an agent to use? This is truly a conversation for the security nerd's nerd. Enjoy! This episode is also available on YouTube Show notes
Face à des cyberattaques toujours plus furtives, Benoit Grunemwald, expert cybersécurité chez ESET, décrypte les nouvelles stratégies des cybercriminels. Il explique comment l'intelligence artificielle, la supervision humaine et les nouveaux outils de protection transforment la défense numérique.
The US restores exports of Anthropic's most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran's long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. Selected Reading Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC) Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer) RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs) Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb' Attack (SecurityWeek) Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs (Expel) Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire) Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq) Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ) Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft (Zero Day) Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of high-value accounts, emerging phishing campaigns abusing OpenAI invitations and Microsoft 365 device code authentication, and recent Oracle security updates. They also cover convictions tied to the Transport for London and U.S. healthcare intrusions, Google's Android earthquake warning system, concerns over MITRE ATT&CK evaluation methodology, and the ongoing debate surrounding threat intelligence researchers interacting with cybercriminals.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis
Enduro World Cup is back and there are new names at the sharp end of the results sheets. We've had breakout performances, surprise winners, and riders stepping into the spotlight who maybe weren't on everyone's radar a few weeks ago. But it's not just what's happening on track. The coverage itself feels like it's taken a step forward too. More access, more insight, and a better window into what's actually going on inside an EDR weekend. So in this episode, we're breaking it all down. The standout rides, the new characters emerging in the series, what's changed already in 2026, and what it might be telling us about where enduro racing is heading this year. Morgane and Greg join me to provide insight into what went on at the first two rounds in Loudenvielle and Leogang. Thiis is the start of something that already feels like a new era for EDR. So sit back, hit play and listen to this episode with Morgane Charre and Greg Callaghan. You can also watch this episode on YouTube here. Follow these accounts for great enduro coverage – @nextstagemtb, @catalyst.cc and @endurochronicles. You can download the UCI MTB World Series app here. Thanks Patreon I would love it if you were able to support the podcast via a regular Patreon donation. Donations start from as little as £3 per month. That's less than £1 per episode and less than the price of a take away coffee. Every little counts and these donations will really help me keep the podcast going and hopefully take it to the next level. To help out, head here. Merch If you want to support the podcast and represent, then my webstore is the place to head. All products are 100% organic, shipped without plastics, and made with a supply chain that's using renewable energy. We now also have local manufacture for most products in the US as well as the UK. So check it out now over at downtimepodcast.com/shop. Newsletter If you want a bit more Downtime in your life, then you can join my newsletter where I'll provide you with a bit of behind the scenes info on the podcast, interesting bits and pieces from around the mountain bike world, some mini-reviews of products that I've been using and like, partner offers and more. You can do that over at downtimepodcast.com/newsletter. Follow Us Give us a follow on Instagram @downtimepodcast or Facebook @downtimepodcast to keep up to date and chat in the comments. For everything video, including riding videos, bike checks and more, subscribe over at youtube.com/downtimemountainbikepodcast. Are you enjoying the podcast? If so, then don't forget to follow it. Episodes will get delivered to your device as soon as it's available and it's totally free. You'll find all the links you need at downtimepodcast.com/follow. You can find us on Apple Podcast, Spotify, Google and most of the podcast apps out there. Our back catalogue of amazing episodes is available at downtimepodcast.com/episodes Photo – Rick Schubert
We'd love to hear from you. Send us fan mail!Workplace dispute resolution is one of the least discussed and most costly blindspots in executive leadership. In this episode of Shedding the Corporate B!tch, executive coach Bernadette Boas sits down with Felicia Harris Hoss, of Harris Hoss Mediations & Arbitration, a nationally recognized mediator with 30 years of trial law experience, to break down early dispute resolution and why it is one of the most powerful, underutilized tools available to corporate executives and HR leaders.Felicia explains why less than five percent of filed lawsuits ever reach trial, what that means for how executives should be approaching conflict, and why the decision to mediate early is not a sign of weakness, it is a strategic move that preserves relationships, resources, and reputation. She walks through the four Cs of mediation, the questions every executive should be asking their attorney, and how to shift from a reacting posture to a responding one in any dispute.If you lead people, manage HR concerns, or sit in any seat where workplace conflict can escalate into legal action, this conversation will change how you think about resolution. What You Will Learn• What early dispute resolution (EDR) is and why it is ABA official policy• When to engage a mediator before a lawsuit is filed• Why litigation means surrendering control — and what executives can do instead• The four Cs of mediation: confidentiality, control, creativity, certainty• What questions to ask your attorney about workplace disputes and resolution options• How the respond vs. react mindset shifts negotiation outcomes• What 'winning' actually looks like in a corporate dispute Key Quote"If you go to the courthouse, you pass that baton called control to strangers. — Felicia Harris Hoss" Episode Chapters00:00:00 — The Legal Dispute Already Living in Your Organization 00:02:00 — Why Staying in the Room Changes Everything 00:03:00 — Meet Felicia Harris-Hoss: From Trial Partner to Neutral 00:06:00 — What Mediation Actually Is (And Isn't) 00:09:00 — Workplace Scenarios That Call for a Mediator 00:12:00 — Why Early Mediation — Before Positions Harden 00:13:00 — The Human Cost Behind Every Corporate Lawsuit 00:15:00 — Why Early Mediation Wasn't Working — And What Changed 00:17:00 — Ego, Fear, and the Real Reason Leaders Avoid Resolution 00:18:00 — The Courtroom Hands Control to Strangers 00:21:00 — The Four C's of Mediation: Confidentiality, Control, Creativity, Certainty 00:26:00 — Key Questions Every Leader Should Ask Their Attorney 00:27:00 — What to Know Before You Bring a Dispute to HR 00:31:00 — Why Even Lawyers Get Confirmation Bias 00:32:00 — Respond, Don't React: The Mindset That Changes Outcomes 00:34:00 — Bernadette's Takeaways for Every Leader and HR Professional About the GuestFelicia Harris Hoss, of Harris Hoss Mediations & Arbitration, is a 30-year trial attorney and nationally credentialed mediator who specializes in early dispute resolution for executives, corporations, and complex business conflicts. She co-authored Resolution 500 for the American Bar Association, which was unanimously adopted in 2024, making early dispute resolution official ABA policy. She also helped establish the American Arbitration Association's EDR Mediation Panel.Learn more at HarrisHossPLLC| Connect on LinkedIn HERE Related Episodes Employee Engagement Strategies That Actually Move the Needle with Ian Watts— HEREYour Calendar is Lying - The Timer Leadership Framework— HERESlow Down To Go Fast with Loretta Stagnitto — HERE Subscribe CTAIf this conversation gave you a new way to think about conflict, leadership, and control, subscribe to Shedding the Corporate Bitch on YouTube at @ShedtheCorpBitchTV for new episodes every week. You can also DOWNLOAD our free Leadership Gap Diagnostic and identify where your leadership needs the most attention right now. Support the show
A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration credential involved, and engaged CrowdStrike as Icarus threatens extortion, echoing earlier Salesforce token-theft campaigns affecting nearly 1,000 companies. Researchers also detail AriStinger, a new botnet infecting 4,000+ end-of-life D-Link routers to scan, proxy, tunnel, execute commands, and hijack DNS, with many infections in South Korea and China. The episode covers federal cyberstalking charges against Anthony Belford for allegedly using fake accounts and AI-generated nude images, and ESET's report that the "Gentleman" ransomware crew is developing modular EDR-killing tools to disable endpoint defenses. 00:00 Top Stories Teaser 00:29 Clue OAuth Token Breach 02:32 Salesforce Token Attack Trend 04:14 AryStinger Router Botnet 05:33 AI Deepfake Cyberstalking Case 07:50 Gentleman EDR Killer Arsenal 09:37 Wrap Up And Sign Off
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-591
International law enforcement disrupts the SocGholish botnet. The UK's cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU's cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Critical patches land from F5, Atlassian, and Splunk. Agentjacking targets AI coding assistants. And Kodak confirms a breach claimed by ShinyHunters. Our guest is Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies on the failure of FISA section 702 to reauthorize. Criminal coders face automation anxiety. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies, and coh-host of Caveat, as he discusses the failure of FISA section 702 to reauthorize. Selected Reading Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp (Bleeping Computer) Hostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns (Infosecurity Magazine) Cyberspace Locked in a Nation-State Contest, Says NCSC CEO (BankInfo Security) EU grants Ukraine access to cybersecurity reserve for major attacks (The Record) Killing me gently: Inside Gentlemen's EDR killer framework (ESET) ShapedPlugin update flow hacked to infect WordPress sites (Bleeping Computer) F5 issues out-of-band patches for critical NGINX vulnerabilities (Bleeping Computer) Atlassian, Splunk Patch Critical Vulnerabilities (SecurityWeek) Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents (HackRead) Kodak Admits Data Breach After ShinyHunters Hack Claims (SecurityWeek) Cybercriminals Are Worried About AI Taking Their Jobs Too (Infosecurity Magazine) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
At Infosecurity Europe 2026 in London, Matt Ellison, Director of Sales Engineering EMEA & APAC at Corelight, joins Sean Martin to unpack the visibility gap widening across security operations. The SOC is either drowning in data or missing the data that matters most. Corelight, custodian of the open-source Zeek project, builds a platform that turns raw network traffic into evidence teams can actually use. Why do today's most evasive attacks slip past endpoint detection? Because they are designed to. Ellison points to typhoon-style campaigns staged from network and hardware devices specifically to avoid EDR. When a platform sees all of the network traffic moving backwards and forwards, those moves stop being invisible. Seeing more is only half the battle. Ellison describes teams trapped by a fear of missing something, switching on every "just in case" detection until alert volume becomes its own crisis. The real question shifts from "what fired" to "what does this actually mean for my environment." How do you investigate a detection you cannot see inside? A black box hands down a verdict with no evidence behind it. Corelight takes an open approach, exposing the data behind every conclusion so analysts can follow a flow to its root cause and apply the one thing no vendor ships: their own knowledge of the network. The proof tends to show up fast. Ellison recalls a proof of value where, within thirty minutes, the team surfaced sensitive information moving unencrypted across the network. Other finds are smaller but telling, like a finance team's certificate using a weak cipher. Corelight even names its catch-all logs plainly, the "weird" log and the "unknown" log. Visibility feeds compliance too. Frameworks like NIS2, DORA, and GDPR demand evidence, not a tool humming in the corner that no one reviews. Ellison previews a coming release that adds asset classification, identifying every device on the network and explaining the why behind it. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTMatt Ellison, Director of Sales Engineering EMEA & APAC, Corelight LinkedIn: https://www.linkedin.com/in/matthewrellison/ RESOURCES Learn more about Corelight, including customer stories: https://corelight.com Zeek, the open-source NDR project Corelight maintains: https://zeek.org Infosecurity Europe 2026 coverage from ITSPmagazine: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Matt Ellison, Corelight, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, network detection and response, NDR, Zeek, open source security, network visibility, threat hunting, SOC alert fatigue, EDR evasion, encrypted traffic analysis, NIS2, DORA, GDPR, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
In this episode, Raghu Nandakumara sits down with two heavyweights in cybersecurity: Dr. Anton Chuvakin (Google Cloud) and Erik Bloch (Illumio), for a candid, often funny, and occasionally sobering look at why detection and response keeps fighting the same battles it was fighting 20 years ago. From the birth of SIEM and the coining of "EDR," to the short-lived reign of XDR, to today's AI hype cycle, Anton and Erik trace the full arc of the industry's evolution and interrogate why, despite decades of tooling investment, the fundamental outcomes haven't changed. Alert fatigue, signal-to-noise ratios, and the needle-in-the-haystack problem remain as stubborn as ever –and the slides security teams are building in 2025 look suspiciously like the ones from 2003. Raghu, Anton, and Erik discuss: Why the SOC still largely runs on a 1990s operating model and what it would actually take to change that How compliance pulled SIEM away from detection for over a decade and why that hangover still lingers Why a handful of engineering-led organizations (Google, Netflix, a European bank) have cracked the code while nearly everyone else keeps applying band-aids The pharmaceutical industry analogy that explains why security startups keep building band-aids instead of solving root causes What MDRs are doing right and why enterprise SOCs have no incentive to learn from them Why AI is accelerating tooling but, for some organizations, actually slowing down the harder transformation work How securing AI is repeating the exact same mistakes made in the early days of cloud Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com
https://youtu.be/sUyjA0muVgM Tom Kirkham, Founder and CEO of Kirkham IronTech, believes business should create value for everyone involved — employees, clients, vendors, and the broader community. After overcoming major personal challenges and rebuilding his perspective on leadership, Tom embraced stakeholder capitalism and built a company culture focused on long-term partnerships, trust, and continuous learning. In this conversation, Tom shares the IronTech Framework — a practical approach to modern IT management built around three core pillars: Generate ROI and Productivity, Make Cybersecurity Core, and Surround it with a Governance Layer. He explains why businesses should stop treating IT as an expense and instead view it as a strategic investment that improves productivity, protects the company from cyber threats, and aligns technology with leadership goals. Tom also dives into the massive scale of the cybercrime industry, why governance is often the missing piece in cybersecurity, and how proactive IT strategy can dramatically improve business performance. — Turn Your IT into Your Growth Engine with Tom Kirkham Good day. Steve Preda here with the Management Blueprint Podcast, and today’s guest is Tom Kirkham, the Founder and CEO of Kirkham IronTech, where he helps businesses build strong, secure IT foundations, whether fully managed, co-managed, or cybersecurity only. Tom is a keynote speaker on cybersecurity, and he’s the author of two books, Hack the Rich and The Cyber Pandemic. Tom, welcome to the show. Oh, it’s great to be here, Steve. Well, great to have you here. And I am curious to dive in, and would like to ask you my favorite question. What is your personal ‘Why’, and how are you manifesting it in Kirkham IronTech? That’s a great question. So the company’s about twenty-six years old. I went through a lot of personal health problems, and then my wife was real sick, and she ended up passing away—it's been about eleven years ago now. And I was fortunate enough to put a friend of mine in the company, and he was able to take over while I was dealing with this for a couple of years. And when most of it was done, I took some time off and did a lot of traveling and a lot of thinking and a lot of reading. And I’m a lifelong reader, a lifelong learner, and I went back through my history of investing techniques, understanding what makes a good company great. If you’ve read Jim Collins, you know what I’m talking about. And so during those times, I was reflecting, studying philosophy, studying biographies of other CEOs like Elon Musk, Steve Jobs, Andy Grove—gosh, the list goes on and on. Whether you like them or hate them, it doesn’t matter, right? There’s always something you can learn. And I came upon and read a lot about stakeholder capitalism. Like Peter Drucker says, “Culture eats strategy for breakfast.” And I understood what that meant, and it was kind of weird. So when I re-engaged with the company, I identified one of the weaknesses, and I said, “Well, if we need to do marketing in this business—which we have to do in any business—I really need to master marketing.” So I spent a lot of time with marketing gurus, most of them are what I would consider household names these days, and re-engaged with the company to do marketing to establish a great culture around stakeholder capitalism. In other words, we exist as a for-profit business not just for the shareholders but for everyone—the community, vendors, employees. And I really wanted to be around people I enjoyed being around. I wanted them to enjoy coming into work.Share on X And so we’ve been trying to perfect that system in the culture for the past ten years. Of course, no one's perfect, but if you pursue perfection, you can achieve excellence. And I think we've done a really good job. We have very low turnover. Everyone seems genuinely happy to be there, and it's really fulfilling. It's more of a personal feeling because I've been a successful investor practically my whole adult life. I started investing in stocks when I was nineteen, and I'm sixty-four now. So I didn't really need the company. I could have just closed it up or sold it or whatever. But I really wanted to have my own reasons. Those are the things that drive me, and I hope they drive everyone else too. What resonated with you with this idea of stakeholder capitalism? It just made sense. The obvious part is with employees—all of that is true. That's obvious to any good leader or manager, right? As you well know, there's a difference between leadership and management, and understanding that distinction, and the difference between sales and marketing, and understanding those things. A good example is dealing with vendors. There are all sorts of vendors that supply products and services to us, so we carefully vet these tools and vendors to see if their values align with ours, just like we do with prospects. But especially with vendors, if it's something new—a new tool that we're going to invest a lot of time, money, and energy into to make their product or service successful for us and successful for them—we make a commitment to that vendor. So it's not about the money or how cheap I can get it. What I want is a good partnership with every stakeholder. And I want to make sure that when I'm dealing with a vendor, if it fails for us, it's not our fault—it's their fault, right? Either they oversold the product or they didn't deliver on the service component. I didn't want it to be because we failed to do the right training, or didn't communicate properly, or missed all the other things that are just part of doing business the right way. And that applies to our employees, our local community, and every stakeholder in the company. Yeah. I like it. So you're looking for partnership-based relationships where it's win-win. And yeah, if you want people to stick around, it has to make sense for them too. You can't exploit your partners forever without consequences. So that makes a lot of sense. So Tom, let me ask you this other question. This podcast is called The Management Blueprint because I'm always looking for frameworks—something practical that helps businesses achieve results. Usually it's some kind of three-to-five-step process that helps you grow the business, get customers, improve operations, or understand something at a deeper level. So when I ask about your favorite business framework, what comes to mind? Well, we have a thing we call the IronTech Framework. Okay. And it was something that we came up with many years ago and started practicing seven or eight years ago, and it's a framework. It's like the NIST Cybersecurity Framework. I looked at NIST and there's five components to it, and it's about cybersecurity. And I looked at this and I go, “None of this works without the right policies and procedures in place.” The security training—it's not enough just to throw it out there and tell all your people to take it. You've got to follow up, you've got to manage, and coach, and everything like that. And so I started adding this governance component to the way we sold it, presented it, and practiced what we do for our clients day in and day out. Help them develop the policies and procedures for all of the different things, the protocols. If somebody accidentally fires off a ransomware attack, they need to know they're not going to be penalized for it. We need to know as soon as possible to stop it. And just little things like that, there's a lot that really improve the effectiveness of all of these tools and services that we provide to their clients. And unbeknownst to me, NIST, who has the cybersecurity framework, they added governance about three years ago to the other five things. And so that was kind of nice to know that we were exhibiting some thought leadership. And so when we go in, it's all well and good if you want to put these protections in and these particular products, but we're a best-of-breed company. Like one of our critical tools that's required for our clients to put in place, to buy it and use it every single day on every single computer, is what's known as an EDR. And it's basically an AI-based super turbo antivirus. To even call it an antivirus is not doing it justice. So there's three legs to the IronTech Framework. We want to make sure that you're getting a return on your investment in IT, because that's why you buy it. If you treat IT as an expense, you need to kind of change the way you're thinking. You want to improve productivity and efficiency.Share on X The second leg is cybersecurity, because a bad cyberattack can put you out of business. I think the last stats I saw were something like 40 to 60% of businesses go out of business within two years of a significant cyberattack. And then finally, the third is governance. That's the three legs of our IronTech Framework. So part of governance is engaging with our clients' management and leadership—the CEO, finance, of course the CIO, the CISO or security officer, and maybe even the board sometimes. Really getting to know: what are your objectives, and how can we utilize our services to best help your company realize those objectives? Because for most companies, there's no other vendor they engage with as much as us. We're talking to Susie every day. We're talking to Bill every day. We know that Mary's out sick and Steve's on vacation. I mean, when you're running help desk, stopping attacks, providing training, and all the support we provide along those lines, we get to know their company better than practically any other vendor by far. So it really helps if our clients treat us as a partner to help them realize their goals and objectives. And when all of that clicks into place, then it makes recommending things easier.Share on X “Okay, you need to replace these 30 laptops that are four years old. You're not getting an ROI on them.” “This server's five years old. Let's start thinking about replacing it.” “We have this new tool that's really excellent. We're recommending everybody get it.” And because we've developed that trust, those conversations become pretty easy. For the most part, everybody just says yes. But of course, we don't sell just to sell, especially when it comes to things like hardware. That's not really what we're here for. We're here for the day-in, day-out work: keeping things running, stopping breaches, and putting the policies and procedures in place to run your company as smoothly as possible. Yeah. I love that. So when I had an IT back in the 2000s, I had an IT person who was a contractor, but he was very active in my business, and I always wanted to talk to him and pick his brain. What are the new things out there? How can we make our business more efficient, more effective, more attractive to employees? Cooler. I wanted to be cool. So I wanted everyone to have a PDA in the early 2000s with email on it—a PalmPilot. And we had multiple screens, and I was looking at, okay, how can we manage data in the cloud and on our server so we don't have to deal with it in the office? That kind of stuff. And I really thought about it as a great investment because it was much cheaper than hiring people. And if you give people good tools, they're going to be more motivated and more effective. So I thought it was a no-brainer. Yes, but there's still a subset of people that treat IT as an expense. Then there are some companies that tend to put IT under the finance guy because the finance guy usually has a lot of IT experience, but never actually did it as a career or a job, right? And those situations are hard because I need CEO-level or owner-level approval, and I need a direct route to that person. Yeah, that makes sense. So Tom, tell me, what drives growth in your business? Yeah. From a growth perspective, for us, number one is maintaining our clients and reducing churn. Number two is—I don't know if you're asking about tactics or strategy—but of course we want to get new clients for the right reasons. So we prefer inbound strategies. We don't cold call people unless we've already contacted them in another way, if that's what you're asking. Yeah. I'm asking what the real driver of growth is. I understand that you do marketing and inbound marketing, but what makes people want to have an IT service partner like you? Well, they understand those three pillars of the IronTech Framework. They may not believe in stakeholder capitalism, but they don't treat IT as an expense. And they understand—especially after talking to me—the true risk of being hacked. A lot of people don't understand the size and scale of that industry. It's a $10 to $12 trillion industry now. Wow. If it were a country, it would have the third-largest GDP. The US would be first, China second, and then the hacking industry. It is an industry that hacks at scale. So when these companies—maybe a small 10-person accounting firm in North Dakota in the middle of nowhere—get these ransomware emails and someone tries to hack them, and we alert on it and trap it, and nothing goes wrong, everything's fine… If they don't already understand it, they go, “Well, why are they trying to hack me?” And I say, “You don't understand. That email was one of 100,000 emails that got blasted out. They don't know who you are, nor do they care who you are.” They're playing a numbers game. And it's kind of like marketing. They're looking at conversion numbers. Yeah. Let's say it's 100,000 emails. They got a list of all the certified public accountants in 10 different states. They set up the email, they send it all out, and let's say 1% become victims. And let's say they collect an average of $10,000 per victim. Well, that's a multi-million dollar payday for about a week or two of work. And then they rinse and repeat. It's done at scale, and it's a much bigger industry than that. That's just a taste of it. Some of our clients are targeted. In other words, hackers are investing time, money, and energy specifically into that company. We're one of them. Any law firm that does intellectual property law—especially around patents, manufacturing, and things like that—you've got China and other nation states not only trying to get into your client, but you're also a threat vector. You're a way to get into that client's patents and secrets. So we've got to treat that differently. It's not just about the money. There are different types of threat actors, and we have to educate clients, bring them up to speed, and say, “Well, because of this case, you need this other service and tool that we're offering to prevent China from breaking in.” Or, “You need to follow this practice.” Maybe you don't publicly talk about one of your clients being Ford Motor Company or NVIDIA. You just keep that quiet. You don’t want that to be public knowledge. That's one of the things we do. You spent time on our website, and you didn't see a single client name on there. And that's just one of the small things we do to protect our clients' security and privacy, because privacy and security go hand in hand. Yeah. That is fascinating. So what is it that you’re trying to figure out in your business right now? What’s the big thing for you? I think because of all the chaos in the United States, making a decision to do anything—everybody's kind of frozen. There are a lot of hiring freezes. I know we've got a freeze on right now because we're looking to see, well, do we really need to add somebody, or can we do this with AI? The hackers do the same thing. That's one of the challenges, is getting people over the hump. No matter what you do, if you've got an IT company doing your stuff and you only call them when things are broken, there's a much more profitable way to do that. You're spending more money. So there are benchmarks in industries, right? Basically, the research—and these aren't numbers we made up, this is legitimate research from many independent sources—says the average professional service provider, like law firms, accounting firms, healthcare providers, and on and on, should be spending 6 to 12% of their revenue on IT and cybersecurity. And that's everything. I'm talking servers, wiring, cloud, security, defense—all of those things should be 6 to 12%. We know that. That's the way it works. So when we engage with a prospect and find out they're only spending 3 or 4%, then I already know they have gaps. I don't even have to do an assessment to see what they're not doing. They're either not getting a return on investment, or they're not secure. That's it. If all the accounting firms are spending 6%, and you're only spending 4%, don't just pat yourself on the back. That's one of those moments where you should ask, “What am I missing?” Because I do that often. Someone on the management team will come up with an idea, and we all agree. Well, that's a red flag for me. I want to know: what are we missing? If we all agree on this, is there some gotcha or something we haven't uncovered? And those are some of the things we try to educate our clients on. They don't have to tell us their revenue. I can give them the numbers. I can do the math. I can show them the numbers for something like laptop replacement. Maybe it's $1,000 to $3,000 depending on the industry. If the employee using that laptop is making $100,000 a year, why are you trying to squeeze another year out of a $2,000 investment when it's hurting productivity by 10% or more? Yeah. That’s a no-brainer. Yeah. It should be. Yeah. It's not just in IT. I had a client years ago in civil engineering, and they had a rule that they would never keep equipment longer than four years. And they were selling equipment that still looked brand new. And I asked them, “Why are you doing this? It seems like this equipment still has a lot of life left in it. Why are you selling it or giving it back to the lease company?” And he said, “We did the math, and we figured out that this is the optimal time to replace it.” If they got rid of the equipment at that point, they wouldn't have to deal with fixing it. There would be less disruption. They would stay state-of-the-art all the time. And their clients would be impressed. And it actually worked for them. It was a high-margin civil engineering firm. Precisely. I mean, we're so tuned into that that we're a Mac house. We all use Macs. We all have laptops, and we all have setups with screens at home and in the office. We spare no expense on that. If somebody wants an extra screen for their house—alright, here it is. We'll order it and get it there for you. We're so tuned into that, that we went all Mac back when they were still Intel Macs. And I don't know how much you know about Macs, but they were… I have a couple. Okay. Yeah, we're Mac people too. Yeah, so they were running Intel processors. Well, Apple decided to build their own processor and moved to the M-chip. And so I bought an M1, and it was like, holy cow, everybody in the company has got to have one of these. And I don't think there was a single one more than two years old at that time. So we replaced them all. Now, the M-series generations themselves—M1, M2, M3, and on—those changes aren't as dramatic as going from Intel to the first M-series chip. But it's still unusual. I said two years, but there are probably people right now with a three-year-old laptop. But we definitely trade them in. That's where the sweet spot is on trade-in value. We rotate them every two to three years and they're out. I think mine is maybe a year old, but I'll probably keep this one for a couple more years. By the way, you're the first IT company and MSP I've met that doesn't use PCs—you use Macs. Yeah. And I long had this theory that all the IT companies I worked with were always anti-Mac, and I never understood why. And when I got my first Mac, I realized I actually didn't need them anymore since I had the Mac. Yeah, that's kind of funny because it really started with me during Covid. It may not have been seven years now, but whatever it was, it kind of started with Covid. And for years I was a PC guy. I tried Macs briefly back in the old MacBook days—you know, the white plastic ones? Whatever that was, 15 or more years ago. Yeah. Classic. Very classic. Yeah. But what I kept trying to do with a Windows laptop—and I like Dell, I had Dell XPSs, good Dell computers, and we're a Dell partner— What I could never get a Windows computer to do was seamlessly come off a docking station and then plug into another monitor at my house. It would always blue screen or something. So when I went back to a Mac, I was like, “Holy cow, it doesn't break. It doesn't mind being unplugged from a docking station. It just works.” Yeah. And then all the other things—that they're generally built better, they have a longer lifespan, and they hold their resale value longer, and all of that. Even as old as I was, I forced myself to really get proficient at using a Mac. And when we sent everybody home during Covid, I said, “Well, everybody's going Mac.” And, oh, there was a revolt. And I said, “Just give it a few months.” Yeah. About half the office resisted it. And I said, “You gotta try it because I think you'll like it, and if you don't, then we'll deal with it then.” We had Linux people, PC people. So then I said, “Well, maybe we should open it up and let people pick what they want.” Yeah, I love it. Yeah. So our time is coming to an end, but if someone is running on Mac and they're finally talking to an IT service company that's not anti-Mac, and they want to connect with you immediately, where should they go and where can they learn more about Kirkham IronTech and maybe connect with you personally? The website is the best place to go. It's www.kirkhamirontech.com. Just give us a call, fill out a form, let us know what you're thinking, because we want to know what you're thinking and see if there's a fit with the way we do things. Macs started becoming important with executives. That's where we first started seeing it. So even though they may still have to run Windows, the owners and executives wanted to carry Macs for the very reasons I mentioned. So we're perfectly happy with that. Yeah. Okay. Very good. So if you're listening to this and you enjoyed hearing about how to make your IT work—how to increase ROI, make sure you're doing cybersecurity right, and implement governance so you can use IT as a strategic tool to run your business better—then definitely reach out to Tom Kirkham. Or stay tuned to this show, because you're going to hear from other entrepreneurs who are very smart about business. And preferably do both. Tom, thank you for coming and sharing your wisdom, and thank you for listening. Oh, it’s been my pleasure, Steve. Important Links: Tom's LinkedIn Tom's website
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460
Agentic AI was the theme that pulled away from the pack at RSAC Conference 2026. Tony Anscombe of ESET makes the case that once AI shifts from being directed by humans to operating with its own objectives and logic, the security surface changes with it, and organizations are being forced to rethink what they protect and how. At the show, ESET announced two products that meet that moment head on. The ESET AI Skills Checker is a free-to-use tool coming to market. ESET AI Protection looks inside AI sessions on the endpoint, flagging sensitive data leakage, malicious links returned by AI systems, and suspicious behavior, and surfacing it all inside normal cybersecurity operations for investigation, blocking, or detection. Tony closes with a reminder worth keeping. His first RSA was in 1998, and the technology he worked on then (sandboxing, dynamic code, remote windowing, encryption, authentication) mirrors a lot of what walks the RSAC Conference floor today. The packaging evolves, the core principles do not. Build forward, but do not lose sight of what the past already proved. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES Learn more about ESET: https://www.eset.com ESET AI Skills Checker and ESET AI Protection: https://www.eset.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, agentic AI, AI security, RSAC Conference 2026, threat intelligence, MDR, EDR, endpoint security, AI Skills Checker, AI Protection, cybersecurity community, multifactor authentication, cybersecurity evolution Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-448