Podcasts about enterprise security weekly

  • 15PODCASTS
  • 1,332EPISODES
  • 54mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 21, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about enterprise security weekly

Latest podcast episodes about enterprise security weekly

Paul's Security Weekly
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477

Paul's Security Weekly

Play Episode Listen Later Sep 21, 2026 97:53


Interview with Rob Sadowsky from Cohesity Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act. In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality. With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell. To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries. This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience. https://www.cohesity.com/dm/global-cyber-resilience-report/ This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them! Topic: When should we use AI for writing and when should we avoid it? I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words. Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other. https://charity.wtf/p/confessions-of-an-unrepentant-slop When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it. I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine. In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language. And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review Weekly Enterprise News Finally, in the enterprise security news, We check the vibes, funding, and acquisitions Tenable now has Mythos built-in??? We check in on how vulnerability remediation is going Microsoft is creating a code of conduct for AI OpenAI just got called to the principal's office Booz Allen created new cybersecurity AI benchmarks 50% of CISOs see Mythos as a sign to resign??? Ayman read the latest Anthropic AI misuse report MIT explains the 12 possible AI outcomes (very ominous) a 9-year old decided to promote his YouTube account… with his dad's corporate card All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-477

Enterprise Security Weekly (Audio)
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477

Enterprise Security Weekly (Audio)

Play Episode Listen Later Sep 21, 2026 97:53


Interview with Rob Sadowsky from Cohesity Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act. In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality. With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell. To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries. This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience. https://www.cohesity.com/dm/global-cyber-resilience-report/ This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them! Topic: When should we use AI for writing and when should we avoid it? I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words. Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other. https://charity.wtf/p/confessions-of-an-unrepentant-slop When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it. I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine. In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language. And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review Weekly Enterprise News Finally, in the enterprise security news, We check the vibes, funding, and acquisitions Tenable now has Mythos built-in??? We check in on how vulnerability remediation is going Microsoft is creating a code of conduct for AI OpenAI just got called to the principal's office Booz Allen created new cybersecurity AI benchmarks 50% of CISOs see Mythos as a sign to resign??? Ayman read the latest Anthropic AI misuse report MIT explains the 12 possible AI outcomes (very ominous) a 9-year old decided to promote his YouTube account… with his dad's corporate card All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-477

Paul's Security Weekly TV
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477

Paul's Security Weekly TV

Play Episode Listen Later Sep 21, 2026 97:53


Interview with Rob Sadowski from Cohesity Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act. In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality. With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell. To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries. This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience. https://www.cohesity.com/dm/global-cyber-resilience-report/ This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them! Topic: When should we use AI for writing and when should we avoid it? I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words. Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other. https://charity.wtf/p/confessions-of-an-unrepentant-slop When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it. I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine. In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language. And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review Weekly Enterprise News Finally, in the enterprise security news, We check the vibes, funding, and acquisitions Tenable now has Mythos built-in??? We check in on how vulnerability remediation is going Microsoft is creating a code of conduct for AI OpenAI just got called to the principal's office Booz Allen created new cybersecurity AI benchmarks 50% of CISOs see Mythos as a sign to resign??? Ayman read the latest Anthropic AI misuse report MIT explains the 12 possible AI outcomes (very ominous) a 9-year old decided to promote his YouTube account… with his dad's corporate card All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-477

Enterprise Security Weekly (Video)
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477

Enterprise Security Weekly (Video)

Play Episode Listen Later Sep 21, 2026 97:53


Interview with Rob Sadowski from Cohesity Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act. In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality. With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell. To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries. This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience. https://www.cohesity.com/dm/global-cyber-resilience-report/ This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them! Topic: When should we use AI for writing and when should we avoid it? I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words. Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other. https://charity.wtf/p/confessions-of-an-unrepentant-slop When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it. I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine. In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language. And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review Weekly Enterprise News Finally, in the enterprise security news, We check the vibes, funding, and acquisitions Tenable now has Mythos built-in??? We check in on how vulnerability remediation is going Microsoft is creating a code of conduct for AI OpenAI just got called to the principal's office Booz Allen created new cybersecurity AI benchmarks 50% of CISOs see Mythos as a sign to resign??? Ayman read the latest Anthropic AI misuse report MIT explains the 12 possible AI outcomes (very ominous) a 9-year old decided to promote his YouTube account… with his dad's corporate card All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-477

Paul's Security Weekly
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476

Paul's Security Weekly

Play Episode Listen Later Sep 14, 2026 100:41


Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-476

Enterprise Security Weekly (Audio)
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476

Enterprise Security Weekly (Audio)

Play Episode Listen Later Sep 14, 2026 100:41


Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-476

Paul's Security Weekly TV
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476

Paul's Security Weekly TV

Play Episode Listen Later Sep 14, 2026 100:41


Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-476

Enterprise Security Weekly (Video)
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476

Enterprise Security Weekly (Video)

Play Episode Listen Later Sep 14, 2026 100:41


Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-476

Paul's Security Weekly
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475

Paul's Security Weekly

Play Episode Listen Later Sep 7, 2026 105:16


Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-475

Enterprise Security Weekly (Audio)
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475

Enterprise Security Weekly (Audio)

Play Episode Listen Later Sep 7, 2026 105:16


Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-475

Paul's Security Weekly TV
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475

Paul's Security Weekly TV

Play Episode Listen Later Sep 7, 2026 105:16


Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-475

Enterprise Security Weekly (Video)
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475

Enterprise Security Weekly (Video)

Play Episode Listen Later Sep 7, 2026 105:16


Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-475

Paul's Security Weekly
Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473

Paul's Security Weekly

Play Episode Listen Later Aug 24, 2026 99:19


Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. “Easy,” Rob Allen said, “it's already blocked if you're using Threatlocker.” Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting “cyber-enabled crime” mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-473

Enterprise Security Weekly (Audio)
Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 24, 2026 99:19


Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting "cyber-enabled crime" mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-473

Paul's Security Weekly TV
Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473

Paul's Security Weekly TV

Play Episode Listen Later Aug 24, 2026 99:19


Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting "cyber-enabled crime" mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-473

Enterprise Security Weekly (Video)
Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473

Enterprise Security Weekly (Video)

Play Episode Listen Later Aug 24, 2026 99:19


Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting "cyber-enabled crime" mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-473

Paul's Security Weekly
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Paul's Security Weekly

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a “mouthpad”? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-472

Enterprise Security Weekly (Audio)
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a "mouthpad"? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-472

Paul's Security Weekly TV
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Paul's Security Weekly TV

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Joe Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a "mouthpad"? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-472

Enterprise Security Weekly (Video)
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Enterprise Security Weekly (Video)

Play Episode Listen Later Aug 17, 2026 102:03


Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a "mouthpad"? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-472

Paul's Security Weekly
AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

Paul's Security Weekly

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

Enterprise Security Weekly (Audio)
AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

Paul's Security Weekly TV
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Paul's Security Weekly TV

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

Enterprise Security Weekly (Video)
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Enterprise Security Weekly (Video)

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

Paul's Security Weekly
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469

Paul's Security Weekly

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a “dumb phone”? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-469

Enterprise Security Weekly (Audio)
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a "dumb phone"? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-469

Paul's Security Weekly TV
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - O'Shea Bowens, Jeremiah Grossman - ESW #469

Paul's Security Weekly TV

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a "dumb phone"? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-469

Enterprise Security Weekly (Video)
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - O'Shea Bowens, Jeremiah Grossman - ESW #469

Enterprise Security Weekly (Video)

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a "dumb phone"? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-469

Paul's Security Weekly
AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

Paul's Security Weekly

Play Episode Listen Later Jul 20, 2026 102:29


Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions. In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution. Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting. Segment Resources: https://arcova.com/sectors/ https://arcova.com/category/blog/ For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova Topic: CMMC Pause creating chaos among federal contractors This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself. I think Howard Holton nails it here when he says: "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November." PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons. What this means: Phase II is paused Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work) NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required 60-day review aims to reform CMMC DoW opened an RFI for industry perspectives on what they should do CMMC characterized as a "compliance burden" and "red tape" False Claims Act and DOJ's cyber-fraud enforcement are still on the table More resources: CIO Davies' post on Twitter Administrator of the Small Business Administration, Kelly Loeffler's post A useful LinkedIn post that breaks down a lot of what this really means (and doesn't) Weekly Enterprise News Finally, in the enterprise security news, will AI eliminate more cybersecurity jobs than it creates? Linus's law, amended the biggest patch Tuesday ever AI context bombs AI workflows are a security disaster people using AI in areas they don't understand ransomware crews are hitting legal firms hard lessons learned from CISA's recent github leak demystify your USB cables! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-468

Enterprise Security Weekly (Audio)
AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jul 20, 2026 102:29


Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions. In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution. Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting. Segment Resources: https://arcova.com/sectors/ https://arcova.com/category/blog/ For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova Topic: CMMC Pause creating chaos among federal contractors This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself. I think Howard Holton nails it here when he says: "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November." PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons. What this means: Phase II is paused Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work) NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required 60-day review aims to reform CMMC DoW opened an RFI for industry perspectives on what they should do CMMC characterized as a "compliance burden" and "red tape" False Claims Act and DOJ's cyber-fraud enforcement are still on the table More resources: CIO Davies' post on Twitter Administrator of the Small Business Administration, Kelly Loeffler's post A useful LinkedIn post that breaks down a lot of what this really means (and doesn't) Weekly Enterprise News Finally, in the enterprise security news, will AI eliminate more cybersecurity jobs than it creates? Linus's law, amended the biggest patch Tuesday ever AI context bombs AI workflows are a security disaster people using AI in areas they don't understand ransomware crews are hitting legal firms hard lessons learned from CISA's recent github leak demystify your USB cables! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-468

Paul's Security Weekly TV
AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

Paul's Security Weekly TV

Play Episode Listen Later Jul 20, 2026 102:29


Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions. In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution. Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting. Segment Resources: https://arcova.com/sectors/ https://arcova.com/category/blog/ For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova Topic: CMMC Pause creating chaos among federal contractors This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself. I think Howard Holton nails it here when he says: "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November." PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons. What this means: Phase II is paused Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work) NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required 60-day review aims to reform CMMC DoW opened an RFI for industry perspectives on what they should do CMMC characterized as a "compliance burden" and "red tape" False Claims Act and DOJ's cyber-fraud enforcement are still on the table More resources: CIO Davies' post on Twitter Administrator of the Small Business Administration, Kelly Loeffler's post A useful LinkedIn post that breaks down a lot of what this really means (and doesn't) Weekly Enterprise News Finally, in the enterprise security news, will AI eliminate more cybersecurity jobs than it creates? Linus's law, amended the biggest patch Tuesday ever AI context bombs AI workflows are a security disaster people using AI in areas they don't understand ransomware crews are hitting legal firms hard lessons learned from CISA's recent github leak demystify your USB cables! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-468

Enterprise Security Weekly (Video)
AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468

Enterprise Security Weekly (Video)

Play Episode Listen Later Jul 20, 2026 102:29


Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions. In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution. Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting. Segment Resources: https://arcova.com/sectors/ https://arcova.com/category/blog/ For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova Topic: CMMC Pause creating chaos among federal contractors This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself. I think Howard Holton nails it here when he says: "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November." PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons. What this means: Phase II is paused Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work) NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required 60-day review aims to reform CMMC DoW opened an RFI for industry perspectives on what they should do CMMC characterized as a "compliance burden" and "red tape" False Claims Act and DOJ's cyber-fraud enforcement are still on the table More resources: CIO Davies' post on Twitter Administrator of the Small Business Administration, Kelly Loeffler's post A useful LinkedIn post that breaks down a lot of what this really means (and doesn't) Weekly Enterprise News Finally, in the enterprise security news, will AI eliminate more cybersecurity jobs than it creates? Linus's law, amended the biggest patch Tuesday ever AI context bombs AI workflows are a security disaster people using AI in areas they don't understand ransomware crews are hitting legal firms hard lessons learned from CISA's recent github leak demystify your USB cables! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-468

Paul's Security Weekly
Fixing pentesting, Meta is destroying its engineering org, the weekly news - Adriel Desautels - ESW #465

Paul's Security Weekly

Play Episode Listen Later Jun 29, 2026 100:54


Interview with Adriel Desautels - the pentest is broken Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: https://hbr.org/2026/04/boards-are-falling-short-on-cybersecurity https://www.scworld.com/perspective/how-to-build-a-breach-ready-security-posture-without-the-enterprise-price-tag https://netragard.com/blog/what-is-penetration-testing/ Topic: Why Meta is destroying its engineering organization The titular essay: https://newsletter.pragmaticengineer.com/p/why-is-meta-destroying-its-engineering A very interesting analysis of what's going on inside big tech companies as they try to dogfood their own AI hype and tokenmaxx themselves into oblivion. There have been a LOT of stories on this, but this is the most comprehensive and enlightening. A few more are linked below. This is relevant to security, because heavier AI use appears to be linked to a much higher occurrence of availability and security issues. ‘Tell Him He's a Piece of Shit': Meta's New AI Unit Is a Total Mess The Newest Instagram "Exploit" is the Goofiest I've Seen Meta CTO Andrew Bosworth Admits the Company's AI Reorg Was ‘Atrocious' Meta's months-old AI unit is a soul-crushing gulag, say the engineers stuck inside it The Weekly Enterprise News Finally, in the enterprise security news, an AI vibe check An AI SOC vendor shuts down Cybersecurity vendor layoffs funding & acquisitions cascading breaches digital estate management criminals don't trust AI either some devs won't code without AI, even if you pay them to Midjourney is now a healthcare company? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-465

Enterprise Security Weekly (Audio)
Fixing pentesting, Meta is destroying its engineering org, the weekly news - Adriel Desautels - ESW #465

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jun 29, 2026 100:54


Interview with Adriel Desautels - the pentest is broken Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: https://hbr.org/2026/04/boards-are-falling-short-on-cybersecurity https://www.scworld.com/perspective/how-to-build-a-breach-ready-security-posture-without-the-enterprise-price-tag https://netragard.com/blog/what-is-penetration-testing/ Topic: Why Meta is destroying its engineering organization The titular essay: https://newsletter.pragmaticengineer.com/p/why-is-meta-destroying-its-engineering A very interesting analysis of what's going on inside big tech companies as they try to dogfood their own AI hype and tokenmaxx themselves into oblivion. There have been a LOT of stories on this, but this is the most comprehensive and enlightening. A few more are linked below. This is relevant to security, because heavier AI use appears to be linked to a much higher occurrence of availability and security issues. 'Tell Him He's a Piece of Shit': Meta's New AI Unit Is a Total Mess The Newest Instagram "Exploit" is the Goofiest I've Seen Meta CTO Andrew Bosworth Admits the Company's AI Reorg Was 'Atrocious' Meta's months-old AI unit is a soul-crushing gulag, say the engineers stuck inside it The Weekly Enterprise News Finally, in the enterprise security news, an AI vibe check An AI SOC vendor shuts down Cybersecurity vendor layoffs funding & acquisitions cascading breaches digital estate management criminals don't trust AI either some devs won't code without AI, even if you pay them to Midjourney is now a healthcare company? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-465

Paul's Security Weekly TV
Fixing pentesting, Meta is destroying its engineering org, the weekly news - Adriel Desautels - ESW #465

Paul's Security Weekly TV

Play Episode Listen Later Jun 29, 2026 100:54


Interview with Adriel Desautels - the pentest is broken Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: https://hbr.org/2026/04/boards-are-falling-short-on-cybersecurity https://www.scworld.com/perspective/how-to-build-a-breach-ready-security-posture-without-the-enterprise-price-tag https://netragard.com/blog/what-is-penetration-testing/ Topic: Why Meta is destroying its engineering organization The titular essay: https://newsletter.pragmaticengineer.com/p/why-is-meta-destroying-its-engineering A very interesting analysis of what's going on inside big tech companies as they try to dogfood their own AI hype and tokenmaxx themselves into oblivion. There have been a LOT of stories on this, but this is the most comprehensive and enlightening. A few more are linked below. This is relevant to security, because heavier AI use appears to be linked to a much higher occurrence of availability and security issues. 'Tell Him He's a Piece of Shit': Meta's New AI Unit Is a Total Mess The Newest Instagram "Exploit" is the Goofiest I've Seen Meta CTO Andrew Bosworth Admits the Company's AI Reorg Was 'Atrocious' Meta's months-old AI unit is a soul-crushing gulag, say the engineers stuck inside it The Weekly Enterprise News Finally, in the enterprise security news, an AI vibe check An AI SOC vendor shuts down Cybersecurity vendor layoffs funding & acquisitions cascading breaches digital estate management criminals don't trust AI either some devs won't code without AI, even if you pay them to Midjourney is now a healthcare company? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-465

Paul's Security Weekly
Navigating Shadow AI in the Enterprise, Verizon's SECOND 2026 report, and the news - Ankita Gupta - ESW #464

Paul's Security Weekly

Play Episode Listen Later Jun 22, 2026 97:53


Interview with Ankita Gupta, CEO of Akto How to Navigate Shadow AI Risk in the enterprise This week, we discuss AI governance in the enterprise, starting with the nuts and bolts of how to discover and understand shadow AI. Following that, we dive into what security and tech leaders should do next with this information: apply guardrails? Limit vendor options? Ankita has a wealth of experience and anecdotes to share here, from years of working with customers and seeing all the unexpected things that happen with AI in today's workplace. Segment Resources: Website: https://www.akto.io Book a Free Demo: https://www.akto.io/agentic-security-demo LinkedIn: https://www.linkedin.com/company/akto-io YouTube: https://www.youtube.com/@aktodotio This segment is sponsored by Akto. Visit https://securityweekly.com/akto to secure your AI agents before attackers do. Topic Segment: Verizon's Breach Impact Study The same team that delivers the DBIR every year gave us a bonus, based on over 70,000 insurance claims! Some of my favorite insights: Cost of breaches, broken out by SMB, mid-sized enterprise, and large The claim amount as a percentage of the company's revenue Losses broken down by loss TYPE This data validates something I think everyone in cyber needs to understand: cyber events are rarely business-ending events. Every cybersecurity professional and vendor, frustrated by companies "not taking security seriously enough" now have data explaining why: breaches don't hurt as much as you thought they did. Maybe you think they should hurt more? Push for regulation/fines/etc. With that said, the report also shows breach costs increasing significantly over the past 6 years and the quantity of incidents shooting up. Specifically, the median impact has almost doubled. Security failures aren't getting any cheaper. Weekly Enterprise News Finally, in the enterprise security news, A $100M seed round! Accenture acquires 3 security vendors Some thoughts on the government takedown of Fable and Mythos One of the craziest security mistakes I've ever seen, in the software FIFA uses to manage World Cup streams! A Critical Copilot vulnerability 75,000 Fortinet Firewalls get compromised Remediation is broken Using guardrails to evade detection All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-464

Enterprise Security Weekly (Audio)
Navigating Shadow AI in the Enterprise, Verizon's SECOND 2026 report, and the news - Ankita Gupta - ESW #464

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jun 22, 2026 97:53


Interview with Ankita Gupta, CEO of Akto How to Navigate Shadow AI Risk in the enterprise This week, we discuss AI governance in the enterprise, starting with the nuts and bolts of how to discover and understand shadow AI. Following that, we dive into what security and tech leaders should do next with this information: apply guardrails? Limit vendor options? Ankita has a wealth of experience and anecdotes to share here, from years of working with customers and seeing all the unexpected things that happen with AI in today's workplace. Segment Resources: Website: https://www.akto.io Book a Free Demo: https://www.akto.io/agentic-security-demo LinkedIn: https://www.linkedin.com/company/akto-io YouTube: https://www.youtube.com/@aktodotio This segment is sponsored by Akto. Visit https://securityweekly.com/akto to secure your AI agents before attackers do. Topic Segment: Verizon's Breach Impact Study The same team that delivers the DBIR every year gave us a bonus, based on over 70,000 insurance claims! Some of my favorite insights: Cost of breaches, broken out by SMB, mid-sized enterprise, and large The claim amount as a percentage of the company's revenue Losses broken down by loss TYPE This data validates something I think everyone in cyber needs to understand: cyber events are rarely business-ending events. Every cybersecurity professional and vendor, frustrated by companies "not taking security seriously enough" now have data explaining why: breaches don't hurt as much as you thought they did. Maybe you think they should hurt more? Push for regulation/fines/etc. With that said, the report also shows breach costs increasing significantly over the past 6 years and the quantity of incidents shooting up. Specifically, the median impact has almost doubled. Security failures aren't getting any cheaper. Weekly Enterprise News Finally, in the enterprise security news, A $100M seed round! Accenture acquires 3 security vendors Some thoughts on the government takedown of Fable and Mythos One of the craziest security mistakes I've ever seen, in the software FIFA uses to manage World Cup streams! A Critical Copilot vulnerability 75,000 Fortinet Firewalls get compromised Remediation is broken Using guardrails to evade detection All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-464

Paul's Security Weekly TV
Navigating Shadow AI in the Enterprise, Verizon's SECOND 2026 report, and the news - Ankita Gupta - ESW #464

Paul's Security Weekly TV

Play Episode Listen Later Jun 22, 2026 97:53


Interview with Ankita Gupta, CEO of Akto How to Navigate Shadow AI Risk in the enterprise This week, we discuss AI governance in the enterprise, starting with the nuts and bolts of how to discover and understand shadow AI. Following that, we dive into what security and tech leaders should do next with this information: apply guardrails? Limit vendor options? Ankita has a wealth of experience and anecdotes to share here, from years of working with customers and seeing all the unexpected things that happen with AI in today's workplace. Segment Resources: Website: https://www.akto.io Book a Free Demo: https://www.akto.io/agentic-security-demo LinkedIn: https://www.linkedin.com/company/akto-io YouTube: https://www.youtube.com/@aktodotio This segment is sponsored by Akto. Visit https://securityweekly.com/akto to secure your AI agents before attackers do. Topic Segment: Verizon's Breach Impact Study The same team that delivers the DBIR every year gave us a bonus, based on over 70,000 insurance claims! Some of my favorite insights: Cost of breaches, broken out by SMB, mid-sized enterprise, and large The claim amount as a percentage of the company's revenue Losses broken down by loss TYPE This data validates something I think everyone in cyber needs to understand: cyber events are rarely business-ending events. Every cybersecurity professional and vendor, frustrated by companies "not taking security seriously enough" now have data explaining why: breaches don't hurt as much as you thought they did. Maybe you think they should hurt more? Push for regulation/fines/etc. With that said, the report also shows breach costs increasing significantly over the past 6 years and the quantity of incidents shooting up. Specifically, the median impact has almost doubled. Security failures aren't getting any cheaper. Weekly Enterprise News Finally, in the enterprise security news, A $100M seed round! Accenture acquires 3 security vendors Some thoughts on the government takedown of Fable and Mythos One of the craziest security mistakes I've ever seen, in the software FIFA uses to manage World Cup streams! A Critical Copilot vulnerability 75,000 Fortinet Firewalls get compromised Remediation is broken Using guardrails to evade detection All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-464

Paul's Security Weekly
Safe AI at scale, what happens after initial access, and the weekly enterprise news - Albert Estevez Polo, Shiva Pillay - ESW #463

Paul's Security Weekly

Play Episode Listen Later Jun 15, 2026 91:17


Interview with Shiva Pillay from Veeam Safe AI at Scale AI investment is exploding, yet nearly 90% of enterprise initiatives fail because the data powering AI cannot be trusted. That's the uncomfortable truth the industry is facing right now. Safe AI at scale requires more than just great models—it demands trusted, governed, and recoverable data. This segment is sponsored by Veeam. Visit https://securityweekly.com/veeam to learn more about them! Segment resources: Veeam Launches New Data and AI Trust Maturity Model to Help Organizations Benchmark AI Readiness Topic: Sure, we know how initial access works, but what about lateral movement? A special topic segment where we're joined by Albert Estevez Polo, field CTO for Zero Networks (a community guest, not a podcast sponsor). Zero Networks just released some very interesting data on what attackers are doing after they gain access to victim's environments and how they're doing it. Segment Resources: Link to report page Weekly Enterprise Security News Finally, in the enterprise security news, Funding and acquisitions Good news, Mythos isn't dangerous anymore! An excellent breach analysis Cyber insurance rates are dropping, but there's a catch CISA updates vulnerability remediation guidance Zoom calls are worse than you think, and maybe not for the reasons you think Remember when it was illegal to rip DVDs? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-463

Enterprise Security Weekly (Audio)
Safe AI at scale, what happens after initial access, and the weekly enterprise news - Albert Estevez Polo, Shiva Pillay - ESW #463

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jun 15, 2026 91:17


Interview with Shiva Pillay from Veeam Safe AI at Scale AI investment is exploding, yet nearly 90% of enterprise initiatives fail because the data powering AI cannot be trusted. That's the uncomfortable truth the industry is facing right now. Safe AI at scale requires more than just great models—it demands trusted, governed, and recoverable data. This segment is sponsored by Veeam. Visit https://securityweekly.com/veeam to learn more about them! Segment resources: Veeam Launches New Data and AI Trust Maturity Model to Help Organizations Benchmark AI Readiness Topic: Sure, we know how initial access works, but what about lateral movement? A special topic segment where we're joined by Albert Estevez Polo, field CTO for Zero Networks (a community guest, not a podcast sponsor). Zero Networks just released some very interesting data on what attackers are doing after they gain access to victim's environments and how they're doing it. Segment Resources: Link to report page Weekly Enterprise Security News Finally, in the enterprise security news, Funding and acquisitions Good news, Mythos isn't dangerous anymore! An excellent breach analysis Cyber insurance rates are dropping, but there's a catch CISA updates vulnerability remediation guidance Zoom calls are worse than you think, and maybe not for the reasons you think Remember when it was illegal to rip DVDs? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-463

Paul's Security Weekly TV
Safe AI at scale, what happens after initial access, and the weekly enterprise news - Albert Estevez Polo, Shiva Pillay - ESW #463

Paul's Security Weekly TV

Play Episode Listen Later Jun 15, 2026 91:17


Interview with Shiva Pillay from Veeam Safe AI at Scale AI investment is exploding, yet nearly 90% of enterprise initiatives fail because the data powering AI cannot be trusted. That's the uncomfortable truth the industry is facing right now. Safe AI at scale requires more than just great models—it demands trusted, governed, and recoverable data. This segment is sponsored by Veeam. Visit https://securityweekly.com/veeam to learn more about them! Segment resources: Veeam Launches New Data and AI Trust Maturity Model to Help Organizations Benchmark AI Readiness Topic: Sure, we know how initial access works, but what about lateral movement? A special topic segment where we're joined by Albert Estevez Polo, field CTO for Zero Networks (a community guest, not a podcast sponsor). Zero Networks just released some very interesting data on what attackers are doing after they gain access to victim's environments and how they're doing it. Segment Resources: Link to report page Weekly Enterprise Security News Finally, in the enterprise security news, Funding and acquisitions Good news, Mythos isn't dangerous anymore! An excellent breach analysis Cyber insurance rates are dropping, but there's a catch CISA updates vulnerability remediation guidance Zoom calls are worse than you think, and maybe not for the reasons you think Remember when it was illegal to rip DVDs? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-463

Paul's Security Weekly
The State of AI in SecOps, the Unintended Consequences of Vulnmaxxing, and the News - Filip Stojkovski - ESW #462

Paul's Security Weekly

Play Episode Listen Later Jun 8, 2026 97:51


Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked project. We also discuss how most of the market has traditionally been focused on the "middle" of the process, which is effectively alert management. Where the conversation really gets interesting is shifting left to discuss building better quality detections. Segment Resources: Be sure to check out SecOps Unpacked - it has more than just vendor information: there are articles, frameworks, podcast episodes, research, and articles/thought leadership Topic: The Unintended Consequences of Vulnmaxxing We discuss my latest blog post where I share a theory that perhaps Project Glasswing is a clever exclusive freemium tier, where Anthropic is hoping to ensnare the world's largest producers of software into using its most expensive model to fix their code for the foreseeable future, creating a much needed new revenue stream for the AI giant with a Trillion dollar valuation. There are some potential unintended consequences that come along with an expensive vulnerability discovery/remediation process that threatens to raise the security poverty line and leave less wealthy companies behind. The Weekly Enterprise News Finally, in the enterprise security news, If you were starting a cybersecurity company today, which category would you pick? layoffs funding the White House AI executive order OpenAI's frontier governance framework Anthropic's Zero Trust for AI agents guide IBM's vulnmaxxing efforts RICO as a service for job seekers Instagram had possibly the most embarrassing hack ever All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-462

Enterprise Security Weekly (Audio)
The State of AI in SecOps, the Unintended Consequences of Vulnmaxxing, and the News - Filip Stojkovski - ESW #462

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jun 8, 2026 97:51


Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked project. We also discuss how most of the market has traditionally been focused on the "middle" of the process, which is effectively alert management. Where the conversation really gets interesting is shifting left to discuss building better quality detections. Segment Resources: Be sure to check out SecOps Unpacked - it has more than just vendor information: there are articles, frameworks, podcast episodes, research, and articles/thought leadership Topic: The Unintended Consequences of Vulnmaxxing We discuss my latest blog post where I share a theory that perhaps Project Glasswing is a clever exclusive freemium tier, where Anthropic is hoping to ensnare the world's largest producers of software into using its most expensive model to fix their code for the foreseeable future, creating a much needed new revenue stream for the AI giant with a Trillion dollar valuation. There are some potential unintended consequences that come along with an expensive vulnerability discovery/remediation process that threatens to raise the security poverty line and leave less wealthy companies behind. The Weekly Enterprise News Finally, in the enterprise security news, If you were starting a cybersecurity company today, which category would you pick? layoffs funding the White House AI executive order OpenAI's frontier governance framework Anthropic's Zero Trust for AI agents guide IBM's vulnmaxxing efforts RICO as a service for job seekers Instagram had possibly the most embarrassing hack ever All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-462

Paul's Security Weekly TV
The State of AI in SecOps, the Unintended Consequences of Vulnmaxxing, and the News - Filip Stojkovski - ESW #462

Paul's Security Weekly TV

Play Episode Listen Later Jun 8, 2026 97:51


Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked project. We also discuss how most of the market has traditionally been focused on the "middle" of the process, which is effectively alert management. Where the conversation really gets interesting is shifting left to discuss building better quality detections. Segment Resources: Be sure to check out SecOps Unpacked - it has more than just vendor information: there are articles, frameworks, podcast episodes, research, and articles/thought leadership Topic: The Unintended Consequences of Vulnmaxxing We discuss my latest blog post where I share a theory that perhaps Project Glasswing is a clever exclusive freemium tier, where Anthropic is hoping to ensnare the world's largest producers of software into using its most expensive model to fix their code for the foreseeable future, creating a much needed new revenue stream for the AI giant with a Trillion dollar valuation. There are some potential unintended consequences that come along with an expensive vulnerability discovery/remediation process that threatens to raise the security poverty line and leave less wealthy companies behind. The Weekly Enterprise News Finally, in the enterprise security news, If you were starting a cybersecurity company today, which category would you pick? layoffs funding the White House AI executive order OpenAI's frontier governance framework Anthropic's Zero Trust for AI agents guide IBM's vulnmaxxing efforts RICO as a service for job seekers Instagram had possibly the most embarrassing hack ever All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-462

Paul's Security Weekly
Helping defense's use of AI catch up with offense, cost of the vulnpocalypse, news - Evan Powell - ESW #461

Paul's Security Weekly

Play Episode Listen Later Jun 1, 2026 97:35


Interview with Evan Powell - Generative and agentic AI are improving cyberattacks faster than they're improving cyber defenses. Offensive folks have been having the most luck with AI so far, which is further eroding any advantage defenders might have had. Evan Powell joins us to share some ideas on how defenders can get some benefits from AI as well, and why open source is important with this approach. Topic For this week's topic segment, we've got two very interesting data sources. The first is Anthropic's first update on Project Glasswing, where they're absolutely tearing through codebases with ultra premium Mythos tokens, but then hitting a human-shaped bottleneck as they attempt to validate all the findings. The second is the first report from Root Evidence, the latest startup from Jeremiah Grossman and Robert Hansen (aka RSnake), which aims to help organizations filter out all the vulnerabilities that don't matter. Where these two reports meet in the middle is my concern that the use of AI to scour every last bug out of code is going to be the most Sisyphean task the cybersecurity industry has ever come up with (and we have some deep experience here). The Weekly Enterprise News Finally, in the enterprise security news, Less funding, more acquisition the AI SOC startup space is CROWDED your CEO is suffering from AI psychosis Some CISOs are done with the job, IT can have it detecting and removing dangerous secrets from dev workstations 230,000 security advisories roll up to 6 attacker behaviors The FBI's 2025 IC3 report is out When tech billionaires make predictions, they're actually sales pitches All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-461

Enterprise Security Weekly (Audio)
Helping defense's use of AI catch up with offense, cost of the vulnpocalypse, news - Evan Powell - ESW #461

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jun 1, 2026 97:35


Interview with Evan Powell - Generative and agentic AI are improving cyberattacks faster than they're improving cyber defenses. Offensive folks have been having the most luck with AI so far, which is further eroding any advantage defenders might have had. Evan Powell joins us to share some ideas on how defenders can get some benefits from AI as well, and why open source is important with this approach. Topic For this week's topic segment, we've got two very interesting data sources. The first is Anthropic's first update on Project Glasswing, where they're absolutely tearing through codebases with ultra premium Mythos tokens, but then hitting a human-shaped bottleneck as they attempt to validate all the findings. The second is the first report from Root Evidence, the latest startup from Jeremiah Grossman and Robert Hansen (aka RSnake), which aims to help organizations filter out all the vulnerabilities that don't matter. Where these two reports meet in the middle is my concern that the use of AI to scour every last bug out of code is going to be the most Sisyphean task the cybersecurity industry has ever come up with (and we have some deep experience here). The Weekly Enterprise News Finally, in the enterprise security news, Less funding, more acquisition the AI SOC startup space is CROWDED your CEO is suffering from AI psychosis Some CISOs are done with the job, IT can have it detecting and removing dangerous secrets from dev workstations 230,000 security advisories roll up to 6 attacker behaviors The FBI's 2025 IC3 report is out When tech billionaires make predictions, they're actually sales pitches All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-461

Paul's Security Weekly TV
Helping defense's use of AI catch up with offense, cost of the vulnpocalypse, news - Evan Powell - ESW #461

Paul's Security Weekly TV

Play Episode Listen Later Jun 1, 2026 97:35


Interview with Evan Powell - Generative and agentic AI are improving cyberattacks faster than they're improving cyber defenses. Offensive folks have been having the most luck with AI so far, which is further eroding any advantage defenders might have had. Evan Powell joins us to share some ideas on how defenders can get some benefits from AI as well, and why open source is important with this approach. Topic For this week's topic segment, we've got two very interesting data sources. The first is Anthropic's first update on Project Glasswing, where they're absolutely tearing through codebases with ultra premium Mythos tokens, but then hitting a human-shaped bottleneck as they attempt to validate all the findings. The second is the first report from Root Evidence, the latest startup from Jeremiah Grossman and Robert Hansen (aka RSnake), which aims to help organizations filter out all the vulnerabilities that don't matter. Where these two reports meet in the middle is my concern that the use of AI to scour every last bug out of code is going to be the most Sisyphean task the cybersecurity industry has ever come up with (and we have some deep experience here). The Weekly Enterprise News Finally, in the enterprise security news, Less funding, more acquisition the AI SOC startup space is CROWDED your CEO is suffering from AI psychosis Some CISOs are done with the job, IT can have it detecting and removing dangerous secrets from dev workstations 230,000 security advisories roll up to 6 attacker behaviors The FBI's 2025 IC3 report is out When tech billionaires make predictions, they're actually sales pitches All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-461

Paul's Security Weekly
What Security Leaders Should Expect from RSAC - Joseph Blankenship - BSW #449

Paul's Security Weekly

Play Episode Listen Later May 27, 2026 43:05


RSA Conference (RSAC) 2026, the 35th annual flagship event for cybersecurity, drew over 43,500 attendees, featuring more than 600 exhibitors, 570+ sessions, and 700+ speakers from 104 countries. It generated 370 million social media impressions. With this size and reach, what should security leaders expect when they attend? Joseph Blankenship, Vice President, Research Director at Forrester Research, and Adrian Sanabria, host of Enterprise Security Weekly, join Business Security Weekly for a special recording from RSAC 2026. This pre-recorded session was filmed live from the conference on March 24, 2026. We discuss what security leaders will see, what they should expect from attending, and a few predictions for the future. If you didn't attend the conference, don't worry, this is a great way to get an inside view. And maybe it helps you decide to attend next year. Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-449

vice president research director blankenship forrester research rsac security leaders adrian sanabria enterprise security weekly business security weekly
Paul's Security Weekly
Visibility with EDR/MDR is still important, 'the basics' are impossible, and the news - Rob Allen - ESW #460

Paul's Security Weekly

Play Episode Listen Later May 25, 2026 104:54


Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460

Paul's Security Weekly
AI Has a data problem, cascading breaches, and the weekly news - Dimitri Sirota - ESW #459

Paul's Security Weekly

Play Episode Listen Later May 18, 2026 96:29


Interview with Dimitri Sirota from BigID Most organizations think AI risk lives in the model – or the identity. It doesn't. It lives in the data. In this episode, BigID's CEO reframes the conversation: why legacy access controls are breaking down, why visibility into sensitive data is the missing foundation, and what it takes to govern humans and machines under a single, accountable framework. Segment Resources: BigID's Agent Access Management Guide BigID's podcast, CTRL + ALT + AI This Week's Topic: Cascading Breaches We're seeing more and more 3rd and 4th party attacks that chain through multiple layers of compromised tools and services. In this topic segment, we discuss the two main aspects of this trend: How we can stop the chain of breaches from a third party library, vendor, or service provider How this might get handled at the legal, contractual, and organizational levels We discuss two big recent examples: Sonicwall's 2025 breach of their cloud firewall configuration backup service The compromise of Aqua Security's widely used Trivy open source tool The Weekly Enterprise News Finally, in the enterprise security news, Funding and M&A courtesy of the Security, Funded newsletter We have evidence that attackers are leveraging AI now (this sounds like old news, but there was little to no evidence before, when people were claiming this) The Angry admin problem emerges again Vulnerability information is getting crazy to keep up with Breach information is getting crazy to keep up with You can give your Agents an allowance now - don't spend it all in one place Are vulnerabilities sparse or dense? Mythos, as a model, isn't all that special Deploy your own deception sensors! Japan made something weird. Again. All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-459