Podcasts about nist

Measurement standards laboratory in the United States

  • 1,183PODCASTS
  • 3,099EPISODES
  • 38mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 27, 2026LATEST
nist

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about nist

Show all podcasts related to nist

Latest podcast episodes about nist

Paul's Security Weekly
Hacking All The Devices, with AI? - Rob Allen - PSW #941

Paul's Security Weekly

Play Episode Listen Later Aug 27, 2026 126:01


Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-941

Unleashing Intuition Secrets

Unleashing Intuition Secrets

Play Episode Listen Later Aug 26, 2026 57:07 Transcription Available


USAF combat veteran, entrepreneur and technology investor Rob Cunningham returns to Michael Jaco with a direct message for President Donald Trump: America can win the AI race—but first, we have to make sure the machines can never take authority they were never given. Cunningham, a former Air Force pilot who flew combat missions during Desert Storm, has publicly offered to serve in an unpaid advisory capacity in support of President Trump's goal of making America the world leader in artificial intelligence. And he says he isn't coming empty-handed. Rob lays out a patented information-physics protocol that he says could fundamentally change how America approaches AI security by separating the enormous computational capabilities of AI and quantum systems from the authority to make sovereign decisions. His principle is simple: Govern the machine. Never allow the machine to govern us. Rob warns that without a new approach, America could enter a perpetual AI-versus-AI arms race requiring ever-larger data centers, enormous amounts of energy, escalating cybersecurity infrastructure and increasingly sophisticated autonomous agents trying to defeat one another. The stakes extend far beyond ChatGPT or consumer technology. Michael and Rob discuss the potential impact of autonomous AI across defense, intelligence, banking, cryptocurrency, energy, communications, supply chains, air traffic control, critical infrastructure, robotics and national security. Rob argues that America should establish the rules of engagement underneath AI itself—creating a sovereignty layer where computational power can continue advancing while unauthorized agency remains off limits. And he's challenging the government to test it. Rob says NIST, DARPA, the FBI, MIT, Caltech or America's highest-level national security teams should independently validate the technology, red-team it and determine whether his claims stand up. If it works, Rob believes the implications could be enormous—not simply for cybersecurity, but for America's ability to become the AI, crypto, energy and manufacturing capital of the world. Michael asks Rob directly what he would say if President Trump invited him to Mar-a-Lago and gave him the opportunity to make his case. His answer sets up the heart of this episode: Test it. Try to break it. Validate it. Then decide whether America should make it the standard. The AI revolution isn't coming someday. It's already here—and Rob Cunningham believes America has an opportunity to define the architecture that governs it before someone else does. The country that establishes sovereignty in the AI era won't simply compete in the AI race. It could define the rules under which that race is run. Wakey Wakey America. Stay informed. Stay sovereign. Stay in the love vibrations. Connect with Michael Jaco Stay connected with Michael for the latest shows, intel, wellness resources, courses, events and more.

Unchained
One Type of Post-Quantum Cryptography Is Most Popular. Why Is Crypto Trying Out Three?

Unchained

Play Episode Listen Later Aug 25, 2026 62:57


Some crypto products work with multiple chains on different post-quantum paths. NEAR's Illia Polosukhin and Ledger's Charles Guillemet discuss how they manage that challenge. ======================================================== Thank you to our sponsor! ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Visit⁠⁠⁠ 1inch.com⁠⁠⁠ to swap tokenized securities, crypto and more. Simple. Secure. Self-custodial. Whatever asset you're buying - swap it at⁠⁠⁠ 1inch.com⁠⁠⁠ ======================================================== In March, a Google research team published a paper on breaking cryptographic keys with a quantum algorithm, so cautious about the finding that it released only a zero-knowledge proof the algorithm existed. Weeks later, an EigenLayer AI competition improved on that method in roughly 48 hours. Illia Polosukhin, co-founder of NEAR Protocol, and Charles Guillemet, CTO of Ledger, join Laura Shin for an update on the quantum threat whose deadline could be approaching fast. Both are creating products that deal with multiple chains that all have different post-quantum approaches.  They discuss why, of the three NIST-standardized, post-quantum algorithms, the crypto industry has splintered into different chains working with different ones, whereas most industries are converging on one, called lattice-based. They also debate what to do with Satoshi Nakamoto's bitcoins: do nothing, freeze them, or freeze and tail-emit new bitcoin, an option Guillemet favors even though Bitcoin's leaderless governance makes consensus hard to reach. Host: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Laura Shin⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, Host / Unchained Guests: ⁠Illia Polosukhin - Co-founder of NEAR Protocol ⁠Charles Guillemet - CTO of Ledger Timestamps

The New Quantum Era
Quantum Risk, Readiness, and the Enterprise Boardroom with Richard Entrup

The New Quantum Era

Play Episode Listen Later Aug 24, 2026 35:32


Richard Entrup is unusual in quantum circles: he's not a physicist, and he doesn't pretend to be. He spent decades as a CIO, CTO, CDO, and CISO at organizations including Verizon, Christie's, Disney/ABC, Time Warner, and Tiffany & Company before joining KPMG to lead its Emerging Solutions practice. That background — deep operational experience on the client side — shapes everything about how he thinks about quantum. He's not selling a hardware roadmap; he's thinking about what it actually takes to get a large, complex organization to change its cryptographic infrastructure before a threat materializes.The conversation matters now because the signals are accelerating. NIST has finalized its first post-quantum cryptography standards, executive orders in the US are pushing federal agencies toward PQC migration, and the algorithmic efficiency gains that reduce the qubit threshold for breaking RSA-2048 keep coming. Listeners who work in enterprise technology, cybersecurity, or quantum strategy — or who advise organizations that do — will find Entrup's practitioner perspective a useful counterweight to the more hardware-focused conversations that dominate the field.What We Get IntoWhy Q-Day's exact date is the wrong question — and why the more important issue is how long it will take enterprises to even inventory their cryptographic exposure, let alone remediate itThe scale of the cryptographic migration problem, including why a single laptop may contain hundreds of individual cryptographic components and why upstream/downstream API dependencies make this a supply-chain-wide challenge, not just an internal IT projectWhy "harvest now, decrypt later" creates urgency today, regardless of when fault-tolerant quantum computers arrive — and how compliance and regulatory timelines interact with that threat modelWhat crypto agility actually means in practice — moving from a "set it and forget it" cryptographic posture to a dynamic, continuously monitored framework, including the pressure SSL certificate renewal windows are already creatingHow KPMG built its PQC practice, incubated it within the firm, and handed it off to the cybersecurity advisory team as a core service offeringThe "good quantum" side of the ledger — how KPMG's emerging research function is approaching quantum computing as a source of competitive advantage, not just risk, and what sectors are furthest along in exploring itThe AI-quantum convergence, including Entrup's observation that AI is already being used to read and crack code — and what that means for the urgency of cryptographic modernizationWhy the enterprise quantum opportunity still has a long tail, and how the current moment compares to the early infrastructure phase of the internet — when everyone was talking about TCP/IP and DNS, not Uber or NetflixResources & LinksGuest & OrganizationRichard Entrup — Worth Magazine Profile — Career arc from CIO/CISO roles at major global brands to KPMG's Emerging Solutions practiceKPMG Quantum Dawn (2025) — KPMG's enterprise quantum readiness hub, introducing the Q-PREP framework and PQC implementation services, with Entrup as named leadReports & ResearchKPMG — "The Quantum Threat Is No Longer Theoretical" (2026) — The threat brief discussed in this episode, charting the rapid decline in qubits needed to crack RSA-2048 and urging immediate PQC migrationKPMG — "From Theory to Impact: Real-World Results in Quantum Machine Learning" (2026) — KPMG's joint report with IBM and Kipu Quantum on measurable quantum ML results on real hardwareKPMG — "Prepare Now for Quantum Cyber Risk" — Board Leadership Article (2026) — C-suite and board-level guidance on integrating quantum risk into enterprise oversightarXiv — "Quantum-enhanced satellite image classification" (2026) — The underlying research paper behind the KPMG/IBM/Kipu Quantum ML resultsEcosystem & EventsChicago Quantum Exchange — KPMG Joins CQE (October 2024) — Announcement of KPMG's formal CQE membership, referenced in the episode as part of the firm's ecosystem-building strategyKPMG 2026 Quantum Consortium — The inaugural KPMG Quantum Consortium event (March 2026, Orlando) discussed in the episodeIndependent CoverageQuantum Computing Report — KPMG joins Chicago Quantum Exchange (2024) — Independent coverage of KPMG's CQE partnership and enterprise quantum strategyQuantum Zeitgeist — Kipu Quantum satellite imagery coverage (Feb 2026) — Independent analysis of the KPMG/IBM/Kipu hybrid QML resultsKey Quotes & Insights> "It's not if but when. And it could be five years, could be three years, could be ten years. The fact is organizations are not gonna be ready. And that's the scary part." — Richard Entrup on Q-Day> "This is not just the CISO. This is gonna be the software engineering app dev guys. This is gonna be all your partners, upstream and downstream, who have to also be compliant — because if you change your crypto and they don't, that stuff's gonna break." — On why PQC migration is an enterprise-wide, supply-chain-wide problemInsight: Entrup draws a sharp distinction between the "bad quantum" (cryptographic risk requiring urgent defensive action) and the "good quantum" (competitive opportunity with a longer tail) — and argues that most organizations aren't adequately addressing either.Insight: The analogy to the early internet is deliberate: just as the 1990s were consumed with TCP/IP and DNS rather than the applications those protocols would eventually enable, the current quantum moment is still largely an infrastructure conversation — and that's normal, not a sign of failure.> "AI is expediting all of this. If AI is doing one thing, the use case is reading code and cracking it. That's pretty scary." — On the intersection of AI capability and cryptographic vulnerabilityRelated EpisodesEp. 81 — Quantum LDPC Error Correction with Larry Cohen and Paul Webster — Directly relevant: Cohen and Webster discuss how QLDPC error correction reduces the qubit overhead needed for RSA cryptanalysis, the technical underpinning of the threat timeline Entrup describesEp. 38 — Quantum Machine Learning with Jessic...

Paul's Security Weekly
Rejoice In The Nostalgia - PSW #940

Paul's Security Weekly

Play Episode Listen Later Aug 20, 2026 128:22


In the security news this week: Cursor opens your repo, the repo opens you If you want the good model I'm going to need to see your ID Flock's a Flocking mess Defender was supposed to be the chosen one Side stepping Secure boot - twice SonicWall: a LAMP stack in a fancy case Macs don't get viruses, part infinity Flipper One, but why not Nix? NetScaler is back in the room Borrowing phone's good reputation USB and how to make Windows download stuff A KVM with the expensive letters removed Five steps to stop the webcam creeps PlexTrac acquired NIST asks the internet to fix the NVD Poland's health software has a very bad week If Apple pings you about spyware, believe it A macOS stealer that drives your browser for you T-Mobile's incident response tool of choice may suprise you, or not... Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-940

Energy Talks
#133: Bridging the IT and OT Gap: Inside the OWASP OT Top 10 Project

Energy Talks

Play Episode Listen Later Aug 20, 2026 22:28 Transcription Available


In this episode, OMICRON's OT security expert Simon Rommer, along with security research experts Andreas Happe and Siegfried Hollerer, discuss their work and experience with the open-source OWASP OT Top 10 Project, which addresses critical industrial cybersecurity challenges affecting OT environments. Simon and his guests describe how critical cybersecurity risks are mapped directly to global frameworks like IEC 62443 and NIST, providing actionable countermeasures and a shared vocabulary for improved industrial resilience.

The Lawfare Podcast
Lawfare Daily: Vinh Nguyen, Elham Tabassi, and Kat Duffy on How to Design a Better AI Regulator

The Lawfare Podcast

Play Episode Listen Later Aug 18, 2026 41:01


Lawfare Senior Editor Kate Klonick is joined by three guests to discuss their recent article for the Council on Foreign Relations on the FINRA-style AI regulator reportedly under White House review: Vinh Nguyen, former chief AI officer at the National Security Agency and now CFR's Senior Fellow for Artificial Intelligence; Elham Tabassi, former chief AI advisor at NIST and now director of Brookings' AI and Emerging Technology Initiative; and Kat Duffy, CFR's Senior Fellow for Digital and Cyberspace Policy and director of LEAD AI.The conversation follows recent news of Demis Hassabis's July 14 framework calling for a U.S.-led Frontier AI Standards Body and a subsequent Bloomberg report that Treasury Secretary Bessent is involved in reviewing a version of the proposal. They discuss the problems but benefits with a FINRA-like model and what that means for public trust before the body even launches, especially for allies abroad who may be reluctant to treat an American, industry-funded body as an international standard-setter.To receive ad-free podcasts, become a Lawfare Material Supporter at www.patreon.com/lawfare. You can also support Lawfare by making a one-time donation at https://givebutter.com/lawfare-institute.Support this show http://supporter.acast.com/lawfare. Hosted on Acast. See acast.com/privacy for more information.

No Password Required
No Password Required Podcast Episode 76 - Dr. Aleksandr Yampolskiy

No Password Required

Play Episode Listen Later Aug 17, 2026 43:16


In this episode: How a virus-infected Prince of Persia floppy disk on a Commodore 64 sparked a lifelong obsession with cybersecurity (03:03 - 06:45) From NYU to Yale cryptography PhD to Goldman Sachs to Gilt Groupe, and the near-miss that changed everything (03:03 - 06:45) What SecurityScorecard actually does and why the pen and paper questionnaire era had to end (06:55 - 08:18) What it looked like in the early days, including an IKEA furniture test for business partnerships (08:26 - 12:01) Why SecurityScorecard now scores every company in the world, not just twelve million organizations (12:01 - 12:29) The Gilt Groupe credit card near-miss, what the first 24 hours looked like, and why fear was the first reaction (12:50 - 17:30) What it takes to create an entire market category from scratch and why the job to be done never changes (17:48 - 20:20) The difference between the CISO version and CEO version of Alex, and what Satya Nadella said about zooming out (20:49 - 22:36) Which version of Alex people would rather have a beer with and why any job besides CEO is more fun (22:43 - 23:45) How North Korea used a fake hedge fund to try to recruit SecurityScorecard developers (24:06 - 25:47) Why the world is not becoming safer and the critical difference between robustness and resilience (25:59 - 26:42) The True Confessions keynote: why openly admitting breaches makes the whole ecosystem stronger (27:13 - 29:22) The Jaguar Land Rover breach and what it took to double a UK company's security budget overnight (27:13 - 29:22) The single most dangerous thing a board member has ever said in a meeting about cybersecurity (29:45 - 31:09) What one thing a non-technical CEO could do this week to make their CISO's life better (31:25 - 32:12) The Lifestyle Polygraph: restaurant health scores, PowerPoint ban, The Inner Game of Tennis, chess, false advertising, and podcast advice (33:07 - 41:32)   Timestamp Highlights: (03:03) Prince of Persia, a floppy disk, and the origin of a cybersecurity career (06:07) The realization that changed everything: you can do everything right and still lose (08:26) The IKEA furniture test for business partnerships (12:50) The Gilt Groupe near-miss and what the first 24 hours looked like (17:48) What it takes to create a market category from scratch (20:49) CISO vs CEO: zooming in vs zooming out (22:43) Which version of Alex would you rather have a beer with? (24:06) North Korea's fake hedge fund operation (25:59) Robustness vs resilience: why the mindset has to change (29:45) The most dangerous thing a board member has ever said (31:25) One thing every non-technical CEO should do this week (36:48) The Inner Game of Tennis and the infinite game (40:00) Chess, false advertising, and meeting his future wife   Resources & Links: SecurityScorecard — securityscorecard.com The Perfect Scorecard by Aleksandr Yampolskiy ThreatLocker — Presenting sponsor of No Password Required DerScanner — Episode sponsor Cyber Florida — The Mother Ship

ITSPmagazine | Technology. Cybersecurity. Society
Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 13:45


Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose. RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project. Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again. Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react. That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue. The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Travis Howerton, Co-Founder and CEO at RegScale LinkedIn: https://www.linkedin.com/in/travishowerton/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas RegScale: https://regscale.com OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Python Bytes
#491 Feeling Judged

Python Bytes

Play Episode Listen Later Aug 12, 2026 42:14 Transcription Available


Topics covered in this episode: Claude Code /insights Post-quantum crypto lands in Python MCP goes stateless — and FastMCP gets renamed inshellisense - IDE style command line auto complete Extras Joke Watch on YouTube About the show Sponsored by Xweather Xweather combines enterprise-grade weather intelligence with agent-ready APIs, natural language capabilities, and an MCP server so your agents can adapt workflows, automate responses, and make better decisions based on real-world conditions. Michael will tell you more about them later in the show. Get started for free at pythonbytes.fm/xweather Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Michael #1: Claude Code /insights Michael's Insights: michael-kennedy-claude-code-insights-2026-08-09.html Be careful sharing these outputs, they include details references to your projects, errors, security findings, etc. ;) /insights reads your last 30 days of local session transcripts and hands back an interactive HTML report on how you actually work. One command, zero setup: type /insights in a session, or run claude -p "/insights" from the shell for a non-interactive version that just prints the path Reads what's already on disk: pulls session logs from ~/.claude/projects/, skipping agent sub-sessions and anything under 2 messages or 1 minute Project areas: clusters your sessions into themes like "CLI Tooling" or "Documentation" with session counts Friction analysis: categorizes where things went wrong by root cause - and quotes your own prompts back at you Interaction style: tells you whether you're a delegator or a micromanager, plus which workflows are worth doubling down on Actually actionable: suggests concrete CLAUDE.md additions and Claude Code features you're not using The catch: Haiku does the per-session classification, so the first run takes several minutes; results cache to ~/.claude/usage-data/facets/ and the report lands at ~/.claude/usage-data/report.html Calvin #2: Post-quantum crypto lands in Python pyca/cryptography 48 ships ML-KEM (key establishment) and ML-DSA (signatures) — NIST's post-quantum standards, now one pip install away. Big deal because it's the 11th most-downloaded package on PyPI (~1.2B downloads/month) and sits under Ansible, Certbot, Airflow, and paramiko. No PQ there, no PQ anywhere in Python. Trail of Bits did the work (Rust bindings, cross-backend API, tests, AWS-LC backend support), funded by the Sovereign Tech Agency. Timing tracks a June 22 White House order setting federal deadlines: PQ key establishment by end of 2030, PQ signatures by end of 2031. Not a drop-in swap — the wire sizes explode. ML-DSA-65 signatures are 3,309 bytes vs Ed25519's 64; ML-KEM-768 public keys are 1,184 bytes vs X25519's 32. Hardcoded field sizes and length prefixes will bite. API looks like the existing asymmetric primitives, except ML-KEM is encapsulate/decapsulate rather than a Diffie-Hellman exchange. SLH-DSA (the hash-based conservative backstop) is still in progress. The primitives are here, but protocols haven't caught up — so you won't be running post-quantum Certbot this week. Sponsor: Xweather You're using agents that can write code, summarize documents, and automate workflows. But they're missing one thing: awareness of the world around them. This is where today's sponsor, Xweather comes in. Xweather combines enterprise-grade weather intelligence with agent-ready APIs, natural language capabilities, and an MCP server built for tools like Claude, Codex, Copilot, and modern IDEs – so your agents can adapt workflows, automate responses, and make better decisions based on real-world conditions. Backed by Vaisala, whose instruments fly on NASA missions to Mars, Xweather delivers trusted data and unique insights that go beyond conditions to actual impact – from real-time lightning strikes to road surface forecasts. Start with 15,000 free API calls each month and pay only for what you use as you grow. Xweather is your full weather stack, for developers by developers. Start building for free today at pythonbytes.fm/xweather. The link is in your podcast player's show notes and on the episode page. Thanks so much to Xweather for supporting Python Bytes. Calvin #3: MCP goes stateless — and FastMCP gets renamed From Philipp Acsany over at Real Python The 2026-07-28 spec landed July 28 and the Python SDK shipped 2.0.0 the same day. Biggest rewrite since MCP launched, and it's breaking on purpose. Context for scale: the Tier 1 SDKs are pulling close to half a billion downloads a month, with TypeScript and Python each past a billion total. The headline is the stateless core. The initialize/initialized handshake and the Mcp-Session-Id header are both retired — protocol version, client identity, and capabilities now ride in _meta on every request, with an optional server/discover RPC if a client wants capabilities up front. Any request can land on any instance behind plain round-robin, no shared storage. Server-initiated calls are the hard part of the migration. Sampling, elicitation, and roots/list no longer call back to the client; instead the server returns resultType: "input_required" and the client retries with inputResponses attached. Multi Round-Trip Requests, MRTR. Also: Mcp-Method and Mcp-Name are now required headers so gateways route on headers instead of cracking JSON bodies, and missing-resource errors move to standard 32602. Deprecation sweep with an actual policy behind it — Roots, Sampling, Logging, and the legacy HTTP+SSE transport all deprecated with a twelve-month minimum offramp. Tasks graduated out of the experimental core into a real extension, which is what the formalized extensions framework was for. MCP Apps is now an official extension too, so a tool call can return sandboxed interactive HTML. Auth picked up RFC 9207 issuer validation, issuer-bound credentials, and a shift from DCR toward CIMD. Python SDK 2.0 is where it gets personal: FastMCP is now MCPServer, no alias, no shim. McpError → MCPError. Wire types went snake_case (is_error, input_schema) and moved to a standalone mcp_types package, with mcp.types kept as a permanent alias. One Client object replaces the old transport + ClientSession + initialize() stack. httpx became httpx2. Sync handlers run on worker threads now, so asyncio.get_running_loop() raises inside them. The good news: one MCPServer serves both protocol eras, so 2025-era clients keep working with nothing to configure, and a Resolve(fn) parameter lets one tool body cover MRTR and the old path. 1.x is maintenance-and-security-fixes only — pin mcp>=1.28,

Govcon Giants Podcast
337: Former GSA Acquisitions Chief: We Knew What Agencies Would Buy Before Anyone Bid | Tracy Marcinowski

Govcon Giants Podcast

Play Episode Listen Later Aug 12, 2026 36:57


Federal agencies signal upcoming contract dollars through the president's budget months before a solicitation ever posts, and the FY2027 budget was published just weeks ago. Tracy Marcinowski, a former Air Force contracting officer who rose to Assistant Commissioner for Acquisitions at GSA's Public Building Service, a $4 billion organization, walks through how a small business reads that budget to find where the money is going before competitors do. What you'll learn in this episode: Why a signed GSA schedule or OASIS Plus contract can carry zero obligated dollars, and what you still have to do after you win one How to read the president's budget to spot which agencies and programs will have money next year Where federal spending data went after SAM.gov absorbed FPDS and USASpending, and how to pull it now Which GSA vehicle actually fits your business, and why the schedules are often the wrong first move The right people to reach inside an agency, program managers and requirements owners, not the CEO Chapters: 0:00 - Tracy Marcinowski's path from Air Force to GSA 3:00 - Why the government does not buy everything 9:00 - The vendor who pitched the wrong buyer six times 11:30 - Who inside an agency actually shapes requirements 15:30 - Choosing a contract vehicle that fits what you sell 17:30 - Starting research with the president's budget 23:30 - Why GSA is the easiest agency to break into 25:00 - CMMC, NIST, and Department of War requirements 32:30 - Action steps for a first-time small business Mindy gives you the federal opportunities, agency signals, recompete intel, and pursuit briefs that tell you not just what contracts exist, but which ones to chase and how to win them. Sign up for free Daily Alerts and get opportunities delivered to your inbox before the day starts.

Quantum Tech Pod
IQT The Quantum Dragon Podcast Episode 88 – It’s already blinking red.

Quantum Tech Pod

Play Episode Listen Later Aug 12, 2026 20:19


I spoke with Rebecca Krauthamer, CEO and Co-Founder of QuSecure, about the implications of the post-quantum cryptography (PQC) market splitting between early movers and laggards on the laggards, the bestowing of US military standards for QuSecure's civilian customers, the difference between NIST standards and US military standards, the benefits of AWS Qualified Software Certification, why Forbes keeps recognizing QuSecure as one of America's Best Startup Employers, and more. Rebecca Krauthamer (LinkedIn) QuSecure (website) QuProtect R3 QuSecure Careers QuSecure (LinkedIn) #303 America's Best Startup Employers (Forbes) Rebecca Krauthamer will be a speaker at PQC+IQT, which is coming to New York City on October 26, 2026. Dragon Castle by Makai Symphony | https://soundcloud.com/makai-symphony Music promoted by https://www.chosic.com/free-music/all/ Creative Commons CC BY-SA 3.0 https://creativecommons.org/licenses/by-sa/3.0/ Dungeons And Dragons by Alexander Nakarada | https://creatorchords.com Music promoted by https://www.chosic.com/free-music/all/ Creative Commons CC BY 4.0 https://creativecommons.org/licenses/by/4.0/

Be Real Show
#467 - Scott Alldridge gets REAL about Cybersecurity in an AI World

Be Real Show

Play Episode Listen Later Aug 10, 2026 29:32


"We cannot solve our problems with the same thinking we used when we created them." – Albert Einstein Scott Alldridge is a tech-forward C-Suite Executive, Board Director, Amazon Best Seller Author and exceptional Problem Solver with deep experience in AI, cybersecurity, data governance and risk management spanning a broad array of industries. He is a transformational leader adept at driving organizational change, mitigating financial and reputation risk and formulating high-impact tech strategies that lead to significant value creation. ______ CYBERSECURITY SME. Scott's work is grounded in Zero Trust – a cyber-tech operations discipline for highly regulated environments. He has led and advised organizations operating under NIST CSF, NIST 800-53, NIST 800-171, CMMC and ISO 27001. Scott's experience also includes HIPAA, PCI DSS, SOX, GLBA, SOC 2, state privacy laws and cyber insurance requirements. In each engagement, Scott's primary goal is to support organizations by strengthening security, ensuring compliance and improving performance – without compromising business efficiency. ENGAGED BOARD MEMBER. Scott helps companies build future-ready infrastructures and leverage technology to strengthen organizational agility and drive profitable growth. He brings a unique blend of business acumen and technical proficiency to his roles as CEO, Advisor and Independent Board Director. Scott's board-level advisory experience includes strategic guidance on a variety of topics including digital transformation, cybersecurity governance, business strategy, portfolio growth and AI. PRAGMATIC LEADER. Scott builds accountable, cross-functional teams that deliver spot-on, data-driven results for their organization, clients and stakeholders. Guided by a shared set of "Mission, Vision and Values", Scott mentors emerging leaders to execute assignments with clarity and autonomy. As testament to his effective leadership style, Scott's core team has remained with him for more than 15 years. https://ipservices.com/ ______ EXPERIENCE and EXPERTISE Small Cap · Mid-cap · SMB · Startups · PE · Digital Transformation • Change Management · AI · IT Roadmaps · Cybersecurity · Continuous Improvement · Agile Methodology · SaaS · ERP Systems Cloud Services · IT Infrastructures · Growth Strategies · Risk Mitigation Business Development M&A Due Diligence • Acquisition Integration • Vendor Negotiations Audit Compliance • NIST • CMMC • GLP • SOX • Gramm-Leach-Bliley Act

AFSO21's Weekend Wrap-up Podcast
NFA: Academic Theory vs. Fireground Reality

AFSO21's Weekend Wrap-up Podcast

Play Episode Listen Later Aug 10, 2026 21:40 Transcription Available


Send us Fan MailThe National Fire Academy has a name that still stops conversations cold, but a lot of firefighters are asking a blunt question: why doesn't the “Mecca” feel like the place you go to become deadly competent on the fireground? We dig into that disconnect without cheap shots, and we get honest about what the NFA is great at, namely executive leadership, grants, budgets, community risk reduction, and the administrative work that shapes an entire department.We also unpack why crews in the apparatus bay often lose faith in federalized training: it can feel too far from the nozzle, too focused on liability-driven risk avoidance, too slow to keep up with lightweight construction and new hazards, and too gated by prerequisites and affiliation rules. I share a personal gut-punch story about being accepted to the Executive Fire Officer Program and learning I could not continue after retirement due to the affiliation policy, even with experience and a platform to support the fire service.Then we get practical about where the best operational firefighting training really comes from: company-level repetition, the kitchen table, regional and state academies with burn towers and real props, hands-on conferences like FDIC, and the modern blend of fire science research from UL FSRI and NIST with street-tested engine and truck tactics. If you care about fire service training, fireground tactics, and building better firefighters, hit play, share this with your crew, and subscribe and leave a review so more people can find the conversation. The Energy DrinkFounded by Firefighters. Fuel for EveryoneDisclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the showContact AFSO21's Weekend Wrap-up Podcast - Email us at podcast@afso21.comAs always, keep supporting your local fire and emergency services, stay safe, and keep on listening!

Federal Drive with Tom Temin
Remote connections that help operators monitor critical systems create opportunities for cyber attackers

Federal Drive with Tom Temin

Play Episode Listen Later Aug 7, 2026 9:08


Keeping water systems running requires remote access for monitoring, maintenance, and vendor support. Securing those connections has become a growing priority for utilities that rely on operational technology every day. A new NIST guide offers practical approaches for doing that. Here to discuss it is CheeYee Tang, an electronic engineer at NIST.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Jon Myer Podcast
Partner Spotlight: Ep#8 Compliance Without the Theater Cloud Advisory for Regulated Industries

Jon Myer Podcast

Play Episode Listen Later Aug 5, 2026 15:13


Eric Evans and Charlie Clayton from Hanabyte join Ingram Micro's AWS Partner Spotlight to discuss how regulated organizations can move fast in the cloud without sacrificing security or compliance. They break down Hanabyte's "cradle to grave" approach — from mock audits and knowledge transfer to blurring the line between compliance and engineering — and how their Ingram Micro partnership helps clients navigate NIST, CMMC, FedRAMP, and HIPAA requirements.Key Takeaways

Jon Myer Podcast
Partner Spotlight: Ep#8 Compliance Without the Theater Cloud Advisory for Regulated Industries

Jon Myer Podcast

Play Episode Listen Later Aug 5, 2026 15:13


Eric Evans and Charlie Clayton from Hanabyte join Ingram Micro's AWS Partner Spotlight to discuss how regulated organizations can move fast in the cloud without sacrificing security or compliance. They break down Hanabyte's "cradle to grave" approach — from mock audits and knowledge transfer to blurring the line between compliance and engineering — and how their Ingram Micro partnership helps clients navigate NIST, CMMC, FedRAMP, and HIPAA requirements.Key Takeaways

CISSP Cyber Training Podcast - CISSP Training Program
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 3, 2026 46:08 Transcription Available


Send us Fan MailA breach can hit your headlines even when your own systems never get touched, and that's exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputation problem that security teams have to own.From there, we zoom out to the bigger pattern behind modern supply chain security: attackers increasingly go after dependencies, CI/CD pipelines, shared developer tools, and widely used vendors because one compromise can cascade across hundreds of customers. We talk about how to reduce that exposure with a stronger TPRM program, including vendor risk tiering, continuous monitoring, SBOM thinking, and practical contractual controls like breach notification timelines, right to audit language, and clear subcontractor disclosure with flow-down requirements to address fourth-party risk.We also shift into CISSP Domain 1 rapid review mode: what the exam really wants when it asks about due diligence, evidence, and proportional risk decisions. You'll hear clean explanations of SOC 2 Type 1 vs SOC 2 Type 2, where ISO 27001 fits, why questionnaires like SIG are not proof, and which frameworks matter for third-party and supply chain risk management including NIST 800-161, ISO 27036, and NIST CSF 2.0. We close with practice scenarios that mirror common CISSP traps so you can spot them fast.Subscribe for more CISSP training, share this with a study partner, and leave a review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Federal Drive with Tom Temin
NIST's Cyber AI Profile is designed to move agencies from abstract frameworks to real operational choices

Federal Drive with Tom Temin

Play Episode Listen Later Jul 31, 2026 12:32


Federal agencies often struggle to turn high‑level guidance on AI and cybersecurity into everyday decisions about procurement, deployment and risk. NIST's new Cyber AI Profile is meant to help close that gap by showing how AI risk management can work in practice. We'll talk about how it's intended to be used and what not to do with it, with Kat Megas, the program manager for cybersecurity, privacy and AI at the U.S. National Institute of Standards and Technology.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Federal Drive with Tom Temin
The Federal Drive with Terry Gerton - - Friday, July 31, 2026

Federal Drive with Tom Temin

Play Episode Listen Later Jul 31, 2026 48:45


Today on the Federal Drive with Terry Gerton . . . NIST's Cyber AI Profile is designed to move agencies from abstract frameworks to real operational choices Artificial intelligence is only as reliable as the information behind it. Many organizations are discovering they haven't paid enough attention to that part When an organization hires someone, it assumes it knows who's doing the work. In some cases, that's becoming a risky assumptionSee Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

artificial nist federal drive
Everything with Everett
Synchronized: The US Atomic Timekeepers

Everything with Everett

Play Episode Listen Later Jul 29, 2026 95:01


If you've ever tuned a shortwave radio, you've likely heard it: a hypnotic, unending rhythm of ticks, tones, and disembodied voices cutting through the static. For over a century, NIST radio stations WWV in Colorado and WWVH in Hawaii have acted as the mechanical heartbeat of the United States, blanketing the globe with atomic-precision time.But who is actually listening to these mysterious broadcasts in the age of GPS and smartphones?In this episode, we dive into the fascinating world of the world's oldest continuously operating radio stations. We'll explore the towering antennas of Fort Collins and Kauai, the iconic male and female voices that guide ships through storms, and the incredibly precise atomic clocks that make it all possible. Join us as we uncover how these legacy analog signals synchronized the modern world, survived the digital revolution, and why scientists, doomsday preppers, and amateur radio operators argue we still desperately need them today.Synchronize your watches. It's time to tune in.Send us Fan Mail

Space Cafe Radio
Space Cafe Radio - Cyber Threats in Space: Why the Ground Segment Is the Real Target with Roger Patrick

Space Cafe Radio

Play Episode Listen Later Jul 23, 2026 18:03


"If someone ever claims they've finished implementing all the cyber, it's nonsense - it's a continually evolving problem." That clear-eyed honesty runs through this entire conversation, recorded live at SmallSat Europe in Amsterdam, where Torsten Kriening sits down with Roger Patrick, Director of Sales and Business Development at TERMA.TERMA sits right at the core of the operational chain - building satellite control and test systems that integrate with manufacturers and operators - which makes Patrick the ideal person to puncture a dangerous assumption: that the satellite is the prize and the ground is just plumbing. As he puts it, the plumbing is exactly what gets you access to the satellite. People talk about jamming and signal spoofing, but the real soft target is the terrestrial infrastructure: polluted software supply chains, abused user access rights, and all the familiar weaknesses of any IT system. A system is only as strong as its weakest link - and that link is usually on the ground.From there, the conversation ranges across the questions that rarely make the slides: how to retrofit secure-by-design, DevSecOps and zero trust into existing systems without breaking them or the budget; what NIS2, Germany's space security strategy and the coming EU Space Act mean for operators built on assumptions regulators may be about to retire; and the unglamorous reality that certification is fragmented across countries and standards. Patrick is candid on scaling security across thousands of satellites - layered architecture, automated key management, and resilience that lets you cut a compromised ground station loose and keep operating - and on why zero trust has moved from recommendation to near-mandate, even if "100% zero trust" remains a utopian ideal.He also tackles AI on both sides of the fight (penetration testing and productivity versus smarter attacks), the post-quantum threat and the NIST algorithms built to withstand it, and why none of this is a military-only problem: every asset in orbit is mission critical and worth protecting. His one ask for Monday morning? Think about security from day one — never as a bolt-on afterthought.Sharp, practical, and refreshingly free of hype. Press play.This Space Cafe Radio is supported by TERMA.Space Café Radio brings you talks, interviews, and reports from the team of SpaceWatchers while out on the road. Each episode has a specific topic, unique content, and a personal touch. Enjoy the show, and let us know your thoughts at radio@spacewatch.globalWe love to hear from you. Send us your thought, comments, suggestions, love lettersSupport the showYou can find us on: Spotify and Apple Podcast!Please visit us at SpaceWatch.Global, subscribe to our newsletters. Follow us on LinkedIn and X!

Fire Science Show
261 - The story of the Cone Calorimeter with Vyto Babrauskas

Fire Science Show

Play Episode Listen Later Jul 22, 2026 93:44 Transcription Available


The cone calorimeter sits in thousands of labs, shaping what we know about flammability, smoke production, and heat release rate. This essential piece of equipment comes with quite a story of how it was engineered or why its “obvious” design choices were anything but obvious. We wanted that history from the source, so we invited Professor Vyto Babrauskas to walk us through the decisions, constraints, and small breakthroughs that turned an idea into the most practical bench-scale fire test in common use today.We dig into the 1970s research environment at NIST (then NBS), including the plastics-focused push that created funding, talent density, and the freedom to build new measurement tools. Vyto explains how the field moved from qualitative “widget tests” toward combustion-science thinking, and why oxygen consumption calorimetry was the turning point. We also talk about terminology and standardization, including how “heat release rate” became the key engineering variable for “how big is the fire,” and why that framing still guides modern fire modeling and performance-based design.Then we get concrete: why the specimen is 100 by 100 mm, how the cone heater geometry was modified to keep combustion products flowing where they should, why adding feedback control was so important, and how ignition and smoke measurement evolved into the robust setup many of us take for granted under ASTM E1354 and ISO 5660. We also cover heat flux selection for realism, horizontal versus vertical orientation, and why some promising variants like controlled-atmosphere attachments never became widespread. The closing brings it back to today, including Vyto's critique of fire research (mainly in Li-ON batteries) that stops at plotting heat release rate curves without answering the deeper engineering and forensic questions.If you would like to read more about the cone, I got  you covered:https://www.nist.gov/nist-museum/cone-calorimeter-most-important-tool-fire-safety-science from the NIST Museumhttps://www.nist.gov/news-events/news/2022/03/happy-retirement-cone-calorimeter - a NIST note on the history of the conehttps://www.jstage.jst.go.jp/article/fst/41/1/41_21/_article paper by Vyto Babrauskas on the early history of the cone.Cover image credit: NIST, from the https://www.nist.gov/news-events/news/2022/03/happy-retirement-cone-calorimeter----The Fire Science Show is produced by the Fire Science Media in collaboration with OFR Consultants. Thank you to the podcast sponsor for their continuous support towards our mission.

Hybrid Identity Protection Podcast
Why AI Makes Your Legacy Systems the Biggest Target with Andre Priebe, CTO at iC Consult Group

Hybrid Identity Protection Podcast

Play Episode Listen Later Jul 21, 2026 46:54


This episode features Andre Priebe, Chief Technology Officer at iC Consult Group, the world's largest independent provider of identity security services.Andre has spent more than two decades leading IAM projects for large-scale enterprises across workforce, customer, and device identity domains. As CTO, he steers iC Consult's Centers of Excellence, service portfolio, and vendor strategy, and advises strategic customers on shaping their identity programs.In this episode, Andre explains why the gap between identity security awareness and actual maturity is growing every day, and how AI is making it faster and easier for attackers to find the weaknesses organizations already know they have. He breaks down why recovery is the most underestimated phase of the NIST cybersecurity framework and what it really costs when organizations haven't prepared for it.This episode is a candid look at the state of identity security from someone who sees it across hundreds of organizations every year.Guest Bio Andre Priebe serves as the Chief Technology Officer at iC Consult Group, a vendor-independent system integrator specializing in Identity & Access Management and Identity Security with a global team of over 850 employees. Boasting more than two decades of experience managing IAM projects focused on workforce, customer, and device identities within large-scale enterprises, Andre steers the Centers of Excellence, the service portfolio, and vendor strategy at iC Consult.Andre's role involves a deep focus on emerging approaches, trends, and technologies within the IAM sector, assessing their business value for iC Consult's clientele. He is an innovator with a patent in DevOps-related IAM methodologies, and he holds a B.Sc. and an MBA.Guest Quote  “Threat actors, for them, it's easier than ever before, faster, more efficient to identify that kind of technical debt, the weaknesses. They are not going for your latest Entra ID, conditional access, configuration with all the fancy stuff in place to really make sure that nobody else accessing that resource. No. They're going for the old systems, for old protocols, for areas that might be out of control, out of visibility. Third parties, contractors, unmanaged devices.”Time stamps 0:40 Meet Andre Priebe: Veteran IAM Expert 2:43 The State of Identity Security Awareness 4:51 The Reality of Technical Debt 6:16 How AI Is Changing the Attack Landscape 10:37 Zero Trust Is Mandatory but Almost Nobody Has Achieved It 15:06 What Customers Are Actually Asking About Now 19:19 Planning for Identity Recovery 26:08 The Most Underestimated Part of Recovery 29:56 Return to Trustworthiness vs Return to Operations 39:42 AI Agents and Non-Human Identities 44:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Andre on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

Cyber Security Today
AI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026

Cyber Security Today

Play Episode Listen Later Jul 18, 2026 33:56


Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks. In this episode of Cybersecurity Today On The Weekend, host David Shipley speaks with Lionel Liddy, Chief Information Security Officer at Menlo Security, about why today's security strategies must evolve as AI reshapes the threat landscape. The conversation explores how AI is speeding up vulnerability discovery, why browser security has become a critical layer of defence, the emerging risks of AI agents operating inside browsers, and why recent NIST research suggests perfect AI guardrails may be mathematically impossible. Lionel also explains why organizations should prepare for future attacks that could spread even faster than Log4j. In this episode: How AI is accelerating cyberattacks Why browser isolation can reduce risk The security challenges created by AI agents Prompt injection and browser extension threats Why AI guardrails have fundamental limits Lessons from Log4j and preparing for the next major exploit Practical advice for CISOs and security leaders Chapters 00:00 Sponsor – NordLayer 00:39 Weekend Show Intro 01:48 Lionel Liddy Background 04:44 What Menlo Security Does 06:43 AI Speeds Up Exploits 10:09 CISO Whiplash With AI 12:01 Agents And Browser Risks 15:59 Guardrails And NIST Proof 19:40 Mythos Hype And New Normal 23:19 Hazmat Suit For Servers 27:22 Log4j Times Four Scenario 31:44 Wrap Up And Links 32:54 Sponsor – NordLayer Outro Subscribe for weekly cybersecurity news, expert interviews, and practical insights for CISOs, IT professionals, and security leaders.

Hashtag Trending
Special Interview With Lionel Liddy, CISO at Menlo Security

Hashtag Trending

Play Episode Listen Later Jul 18, 2026 33:43


Browser Security in the Age of Agentic AI: Containment, Isolation, and the New CISO Reality Host Jim Love introduces a #TrendingOnTheWeekend episode featuring David Shipley (Cyber Security Today, Beauceron Security) interviewing Lionel Liddy, CISO at Menlo Security, about AI-driven vulnerability discovery and why reactive security is failing as exploitation accelerates. Liddy shares his path from a University of Toronto PhD researching virtual machines to building Menlo's browser-security approach: an isolated remote "cloud browser" that prevents active web content from executing on endpoints and can also shield servers by forcing interactions through a controlled browser. They discuss CISOs struggling to keep up with rapid shifts, agentic AI risks in browsers and extensions, limits of LLM guardrails (including NIST's proof-like framing), and the compounding impact of pervasive bugs and technical debt. The episode closes with where to learn more at Menlo Security. 00:00 OpenClaw Policy Panic 00:19 Weekend Show Setup 00:57 Interview Preview 02:06 Lionel Origin Story 05:02 Menlo Browser Isolation 06:58 AI Speeds Up Exploits 10:33 CISO Whiplash Era 12:18 Agents In The Browser 16:17 Guardrails Limits Proof 19:58 Mythos And New Normal 23:36 Hazmat Suit For Servers 28:24 Collision Weekend Scenario 32:02 Wrap Up And Links 33:11 Show Closing Notes

Cyber Security Today
Scattered Spiders sentenced, OpenAI builds an AI that breaks AIs, and Iran leans on ChatGPT

Cyber Security Today

Play Episode Listen Later Jul 17, 2026 12:02


Two leading Scattered Spider members, Thaila Jubar and Owen Flowers, were sentenced to five years and six months for the 2024 Transport for London hack that knocked 148 systems offline, forced 27,000 password resets, stole customer data, and cost TfL £29 million, with wider losses estimated far higher; U.S. charges against Dubar remain unproven. Investigators also believe Russian hackers were behind last year's crippling Jaguar Land Rover attack that halted production for months and contributed to a £1.5 billion bailout, with Microsoft and multiple agencies assisting.  OpenAI unveiled GPT-Red, an automated red-teaming AI for prompt injection, alongside a NIST-backed argument that finite guardrails can't be universally robust. The episode also covers ClickLock, a macOS stealer that kills apps until a password is entered, and Recorded Future's report on Iran-linked groups using ChatGPT for malware, phishing, and reconnaissance. 00:00 Headlines Kickoff 01:08 Scattered Spider Sentencing 02:57 US Charges Loom 03:29 Jaguar Land Rover Hack 04:35 GPT-Red AI Red Team 05:40 Why Guardrails Fail 06:36 ClickLock Mac Stealer 06:53 How ClickLock Spreads 07:59 Defense and Cleanup Tips 08:37 Iran Uses AI for Ops 10:30 Wrap Up and Next Show

DailyCyber The Truth About Cyber Security with Brandon Krieger
AI, Compliance Automation & The Future of Cyber Governance | DailyCyber with Justin Beals

DailyCyber The Truth About Cyber Security with Brandon Krieger

Play Episode Listen Later Jul 12, 2026 70:42


AI, Compliance Automation & The Future of Cyber Governance | DailyCyber with Justin Beals   As regulatory requirements continue to expand, organizations are looking for ways to simplify compliance while strengthening cybersecurity outcomes. AI and automation are increasingly becoming critical components of modern governance, risk, and compliance programs.   In this live episode of DailyCyber, Brandon Krieger speaks with Justin Beals, Founder & CEO of Strike Graph, about how organizations can modernize compliance operations, reduce audit fatigue, and build sustainable cybersecurity programs.   Justin is an entrepreneur, former CTO, AI researcher, and inventor whose work spans enterprise software, semantic mapping, and educational NLP systems serving millions of users. His research into knowledge classification and framework alignment directly influenced the architecture behind Strike Graph's approach to compliance automation across standards such as SOC 2, ISO 27001, NIST, HIPAA, and CMMC.   Topics covered: • Why major compliance frameworks overlap more than organizations think • Using AI to automate cybersecurity compliance activities • Common misconceptions surrounding compliance and security maturity • Foundational security gaps organizations should address before adopting AI • Governance and risk challenges created by emerging AI technologies • Strategies for building scalable and audit-ready security programs   Guest: Justin Beals — Founder & CEO, Strike Graph https://www.linkedin.com/in/jubeals/ https://www.strikegraph.com/   Host: Brandon Krieger — CEO & vCISO Advisor https://www.linkedin.com/in/brandonkrieger https://www.DailyCyber.ca  

Empathy to Impact
ENCORE: Leadership Through Community Engagement At NIST

Empathy to Impact

Play Episode Listen Later Jul 10, 2026 38:06


A throwback to the old intro… Happy Summer (northern hemisphere) from Inspire Citizens. We hope you enjoy this encore episode from our archives featuring some amazing student leaders at NIST. New episodes coming soon.If you have enjoyed the podcast please take a moment to subscribe, and also please leave a review on your favorite podcast platform. The way the algorithm works, this helps our podcast reach more listeners. Thanks from IC for your support. New from Inspire Citizens: Inspired Coaching & Inspired Experiences Learn more about how Inspire Citizens co-designs whole-school service learning programsYou can book a discovery call with Inspire Citizens at this linkShare on social media using #EmpathytoImpactEpisode Summary On this episode, I connect with service learning leaders Pooja, Maya, Minnie, & Poj. These young global citizens share an interest in service through the lens of unity, collaboration and humanitarianism. Listen to our conversation to hear about the multitude of options for students at NIST to engage in meaningful, impactful, and sustainable service through collaboration with diverse community partners in Thailand. We talk about the current projects and aspirations of the service clubs that they are personally involved with, as well as how they have developed as leaders through their work with their clubs and ServiceCo, a student-led organization within the school, who, among their many responsibilities, coordinate and offer leadership and oversight to the many initiatives happening across the school. How might we work together to create a culture of service within our own schools and empower students to take action for a more just equitable, joyful, and sustainable future?  Listen and be inspired.Discover a transformative podcast on education and learning from a student perspective and student voice, exploring media, media literacy, and media production to inspire citizens in schools through a media lab focused on 21st-century learning, empathy to impact, Global citizenship, collaboration, systems thinking, service learning, PBL, CAS, MYP, PYP, DP, Service as Action, futures thinking, project-based learning, sustainability, well-being, harmony with nature, community engagement, experiential learning, and the role of teachers and teaching in fostering well-being and a better future.

Federal Drive with Tom Temin
NIST's National Vulnerability Database has largely been a helpful resource, but needs some help to continue that

Federal Drive with Tom Temin

Play Episode Listen Later Jul 8, 2026 10:16


A list of potential cyber vulnerabilities, rightfully called the National Vulnerability Database, is one of the many ways the National Institute of Standards and Technology aims to help industry and government cyber officials keep track of possible weaknesses in IT systems. However, a recent review of the NVD by the Commerce Department's Inspector General, found that a backlog has developed over the years, and NIST officials are in need of more resources to cut it down. For an explanation of what it will take, I had the chance to speak with Chuck Mitchell from the IG's office.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Federal Newscast
There's a new leader at NIST

Federal Newscast

Play Episode Listen Later Jul 7, 2026 8:06


The National Institute of Standards and Technology has a new leader. Arvind Raman was sworn is as the fifth undersecretary of commerce for standards and technology on June 30th. He was confirmed by the Senate in May. Raman was previously the dean of engineering at Purdue University. His background is in atomic force microscopy, human biomechanics and electronics manufacturing. As the head of NIST, he'll be charged with overseeing an array of high-profile work in areas like artificial intelligence, quantum science, and biotechnology.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Security. Cryptography. Whatever.
Trump's Golden Post-Quantum EO(s)

Security. Cryptography. Whatever.

Play Episode Listen Later Jul 2, 2026 56:37 Transcription Available


The dear leader has actually bleated out some not-dumb executive orders (EOs) to accelerate adoption of post-quantum crypto for the US government! This looks to be in response to a flurry of advancements in quantum computing and quantum attack algorithms a few months ago. We cram legalize into our eyeballs— plus, ECDSA.fail!Watch on YouTube: https://www.youtube.com/watch?v=7ZwQpN_F6P8Transcript: https://securitycryptographywhatever.com/2026/07/02/trumps-golden-post-quantum-eosLinks:- The EO https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/- CNSA2 https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF- https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF- https://www.ecdsa.fail/- https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/- https://blog.cloudflare.com/post-quantum-roadmap/- https://blog.google/innovation-and-ai/technology/research/neutral-atom-quantum-computers/- https://en.wikipedia.org/wiki/FedRAMP- https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/- https://blog.trailofbits.com/2026/04/17/we-beat-googles-zero-knowledge-proof-of-quantum-cryptanalysis/- https://scottaaronson.blog/?p=9861"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

Insider
Amerika nezapomene na české vojáky v Afghánistánu, říká generál Nicholson

Insider

Play Episode Listen Later Jul 1, 2026 20:34


Generál John Nicholson Jr. sloužil třem americkým prezidentům a patří mezi nejvýraznější osobnosti světové bezpečnostní komunity. Jak se změnil pohled na válku po zkušenostech z Ukrajiny? Jak nahlížet na nástup firem jako Palantir, Anduril nebo Shield AI v americkém obranném průmyslu? Má Evropa šanci dohnat technologický náskok Spojených států? Je NATO pořád pevnou aliancí? Co máme očekávat od summitu v Ankaře?Partnerem podcastu je advokátní kancelář ROWAN LEGAL a mezinárodní poradenská společnost RSM.

HTML All The Things - Web Development, Web Design, Small Business
AI Safety: From Narrow AI to Superintelligence

HTML All The Things - Web Development, Web Design, Small Business

Play Episode Listen Later Jun 30, 2026 63:40


Artificial Intelligence is advancing faster than ever, but can it actually be made safe? In this episode, we explore the evolution of AI from today's Narrow AI systems to the theoretical future of Artificial General Intelligence (AGI) and Superintelligence. Along the way, we discuss AI alignment, control, bias, security, transparency, and the growing challenges researchers face as AI capabilities continue to accelerate. We also examine concerns raised by AI safety researcher Dr. Roman Yampolskiy and compare them with current safety approaches from organizations like Google DeepMind and NIST. Whether you're a developer, tech enthusiast, or simply curious about the future of AI, this episode provides a practical introduction to one of the most important conversations in technology. Show Notes: https://www.htmlallthethings.com/podcast/ai-safety-from-narrow-ai-to-superintelligence Use our Scrimba affiliate link (https://scrimba.com/?via=htmlallthethings) for a 20% discount!! Full details in show notes.

Govcon Giants Podcast
What every small business needs to know about CMMC compliance before working with DOD

Govcon Giants Podcast

Play Episode Listen Later Jun 29, 2026 8:18


If you're trying to win Department of Defense contracts, understanding PIEE, CMMC, and your SPRS score isn't optional, it's the baseline. In this episode, Randie Ward breaks down exactly how to register inside PIEE, why CMMC compliance levels matter more than ever, and why a negative SPRS score doesn't mean you're disqualified. This is the practical, no-fluff walkthrough every small business needs before bidding on DOD work. How to register inside PIEE and navigate the training tiles for SBIRS, SPRS, and WAWF Why CMMC compliance levels are now mandatory for any business working with the Department of Defense What the SPRS score actually measures and how the 110-question NIST self-assessment works Why having a negative SPRS score is normal at the start and doesn't disqualify you from an award A real story about a tribal-owned business navigating its first CMMC assessment with Army Corps of Engineers EPISODE CHAPTERS: 0:00 - Introduction to the Federal Help Center podcast 0:49 - Overview of PIEE and what it manages 1:14 - How RFPs RFIs and payments flow through PIEE 1:50 - Registering for PIEE and finding training resources 2:33 - Introduction to SBIRS and required payment systems 3:09 - What CMMC is and why it is here to stay 4:06 - Understanding CMMC security levels and requirements 4:30 - How SPRS scores work and the NIST self-assessment 5:21 - Why your CMMC level depends on the type of work 6:11 - Real story of a negative SPRS score with Army Corps 7:55 - Closing thoughts and community call to action Mindy gives you the federal opportunities, agency signals, recompete intel, and pursuit briefs that tell you not just what contracts exist, but which ones to chase and how to win them. Sign up for free Daily Alerts and get opportunities delivered to your inbox before the day starts.

IP Fridays - your intellectual property podcast about trademarks, patents, designs and much more
Creator Economy Law: What Every Creator Needs to Know About AI, Platforms, and Their Rights – Interview with Franklin Graves of Linkedin – IP Fridays Podcast – Episode 176

IP Fridays - your intellectual property podcast about trademarks, patents, designs and much more

Play Episode Listen Later Jun 26, 2026 36:31


My co-host Ken Suzan and I are welcoming you the episode 176 of the IP Fridays Podcast. Today's interview guest is returning guest Franklin Graves, who is a senior counsel at Linkedin and teaching IP law at Emerson College. With my co-host Ken Suzan he is discussing how the law for creators has dramatically changed in the past years. Franklin Graves is expressing his personal views and not the views of Linkedin or Microsoft. He is talking about the paper “Upload Complete” before he joined Linkedin. Bio: https://www.linkedin.com/in/franklingraves/ Paper: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5271442 Website: https://creatoreconomylaw.com/ But before we jump into this interview, I have news for you! Richard Meade, a judge on the UK High Court and one of the most prominent figures in European patent law, was appointed Lord Justice of Appeal at the British Court of Appeal on June 12, 2026. Meade played a key role in numerous landmark British patent decisions, particularly in the area of standard-essential patents (SEPs) and FRAND licenses. In Insulet Corp. v. EOFlow Co., No. 2025-1807, the U.S. Court of Appeals for the Federal Circuit completely overturned the original $452 million judgment (which had already been reduced by the District Court to $59.4 million) in favor of Insulet. In its decision of June 2, 2026, in the case of Fujifilm v. Kodak, the UPC Board of Appeal provided comprehensive clarifications regarding so-called “long-arm jurisdiction”—that is, the question of whether the UPC can also rule on national patent claims outside the UPC territory (such as in the United Kingdom). In 14 guiding principles, the judges established specific procedural rules for various categories of cases. There is no automatic UPC jurisdiction over national patent claims outside the UPC territory. The Munich Regional Court has issued an arrest warrant against the managing director of Polytech Health & Aesthetics GmbH because he is alleged to have continued to exploit the Brazilian company Silimed's patent for breast implants despite a preliminary injunction. A number of IT and automotive industry associations—which are among the most frequent users of Inter Partes Reviews (IPR) at the U.S. Patent and Trademark Office—have filed an amicus brief with the Supreme Court, urging the Court to grant Google's certiorari petition. An attorney for a Las Vegas performer has asked a California federal judge to temporarily prohibit Taylor Swift from using “The Life of a Showgirl” as a trademark while the trademark lawsuit is pending. Swift's attorney called the lawsuit baseless. And now let's hear Ken discuss creator law with Franklin! AI, Platform Law, and the Creator Economy: What Businesses Need to Know Now Franklin Graves has spent his entire career watching digital content move through systems that most people never see. He started in marketing at a major music label right out of law school, then represented individual creators on YouTube in a pro bono capacity, then moved to the platform side at Eventbrite, and today works as Senior Product Counsel at LinkedIn, where he focuses on AI, data, and the regulatory questions that come with both. His recently published law review article, Upload Complete: An Introduction to Creator Economy Law, is the first academic paper to address the creator economy as a distinct legal field. In a recent episode of the IP Fridays podcast, he spoke with host Kenneth Suzan about responsible AI development, platform regulation, and what it actually means to own your audience in a world where the rules keep changing overnight. From Content Creator to Platform Lawyer The through-line in Graves’ career is a genuine understanding of how content moves from an idea in someone’s head to an audience on a screen. That experience, he argues, is precisely what in-house counsel needs right now. Lawyers working on AI and product development cannot afford to sit at a distance from the technology they are advising on. They need to use the tools, experience them as a creator or end user would, and understand the nuances of how a product actually operates before it reaches the public. Understanding the product first is the precondition for everything else. That philosophy translates directly into how he approaches responsible AI implementation. The landscape of AI standards is crowded: NIST frameworks, the EU AI Act, sector-specific guidance, and a growing body of industry-adopted best practices. The challenge for in-house counsel is not knowing that these standards exist. It is making them actionable for the engineering and product teams they support. Abstract principles need to become concrete controls and workflows. Graves offers one practical shortcut: most companies already have open source software review processes that involve the right stakeholders, the right sign-off levels, and the right security checks. Layering the specifics of generative AI or large language models onto those existing processes is far more efficient than building something new from scratch. A Fragmented Regulatory World The geopolitical dimension of AI regulation is something Graves thinks about constantly in his role at LinkedIn. The EU AI Act, shifting US executive orders, and country-specific approaches to data privacy have created a regulatory environment that can change the rules of the game without warning. His analogy is instructive: creators have long understood what it means to build a community on a platform they do not own. An algorithm change, a policy update, or a government ban can wipe out years of audience-building overnight. Businesses deploying AI tools globally now face a structurally similar problem. The response, for creators and for platforms alike, is to build resilience rather than rely on stability that may not last. TikTok is the clearest recent example. When the platform faced the prospect of being shut down in the United States on national security grounds, it triggered a broader conversation about platform dependence that had been building for years. Creators who had invested their entire business in one platform suddenly confronted the possibility that their audience could simply disappear. The lesson is not that platforms are bad. It is that concentration of any kind, whether it is your audience, your data pipeline, or your regulatory compliance strategy, creates fragility. What Is a Creator, Legally Speaking? One of the central contributions of Graves’ law review article is definitional. The terminology matters more than it might seem. When courts and regulators talk about creators without a shared understanding of what that word means, the resulting legal analysis tends to miss the mark. Graves draws a distinction between users who post content, creators who post with the intent to build an audience and eventually monetize it, and influencers, a subset of creators who are actively running a small business through their content. The difference is intent. A parent posting family photos on Facebook is a user. Someone building a subscription community around their professional expertise is running a business, and the legal framework that applies to them should reflect that. That distinction matters practically when it comes to liability. As more creators build their own platforms, whether through custom membership sites, open source tools like Ghost, or federated social networks, they take on obligations that previously fell to large platforms: content moderation policies, privacy notices, terms of service, and compliance with data regulations across multiple jurisdictions. A creator in Tennessee running a membership platform with subscribers in Germany is operating a global business, whether they think of themselves that way or not. Protecting Children Online: A Question Without a Clean Answer The tension between age verification and privacy is one of the more difficult problems in platform law right now. Australia, several European countries, and a growing number of US states have introduced or passed minimum age requirements for social media accounts. The technical challenge is real: verifying age online requires collecting identifying information, and collecting identifying information creates privacy risk, particularly for the young people the laws are designed to protect. Who should bear the responsibility for that verification is also unresolved. Is it the platform? The app store? The mobile operating system? Graves does not pretend there is a clean answer, but he points to the mobile layer as an underexplored option. The Apple App Store and Google Play Store already have significant leverage over which apps reach users on their devices. Whether that leverage should extend to age verification is a question that deserves more attention than it currently receives. The Right of Publicity in the Age of AI Voice cloning, digital replicas, and AI-generated synthetic media have pushed the right of publicity into territory that traditional IP law was not designed to cover. Trademark law, copyright law, and existing publicity rights each capture part of the problem but none of them covers it completely. The result, as Graves describes it, is a period of experimentation: lawyers filing trademarks on vocal sounds and phrases, states updating their publicity statutes to explicitly mention artificial intelligence, and entertainment unions negotiating over who controls a performance and any AI-generated iterations of it. Tennessee’s Elvis Act is a concrete example of the legislative response: the state updated its right of publicity law to include voice and to reference AI directly. Similar efforts are underway elsewhere. The underlying challenge is calibrating protection so that it gives creators and performers meaningful control over their likeness and voice without foreclosing the development of generative AI systems that depend on broad rights to process and learn from content. Somewhere between those two interests, a workable legal framework needs to emerge. The brand deal context may be where the issue becomes most immediately practical. When a brand partners with an influencer and the campaign involves generative AI in any form, the contract needs to address control explicitly. Who has final approval over how the influencer’s likeness or voice is used in AI-generated deliverables? What happens to those assets after the campaign ends? These are not hypothetical questions. They are contract drafting problems that any brand counsel or creator attorney should be addressing today. What Comes Next Graves is cautious about predictions, but his sense of direction is clear. The regulatory environment will continue to fragment before it converges. The right of publicity will be updated, imperfectly, in more jurisdictions. Creators will continue to move toward owning more of their infrastructure. And the lawyers who do this work best will be the ones who understand the technology well enough to translate it into practical, defensible decisions for the people they advise. Full Transcript: Ken Suzan: Thank you, Rolf. Our returning guest today is Franklin Graves. Franklin is the founder and editor of Creator Economy Law, a website and newsletter that educates creator economy professionals on the intersection of law and policy with the world of creators, brands, and platforms. Franklin also published the first law review article focused on the creator economy, Upload Complete, an introduction to creator economy law. He regularly appears across news and media outlets as a commentator and contributor with a focus on educating creators and raising awareness of all legal aspects of the creator economy. Franklin is based in Nashville, Tennessee. Ken Suzan: Franklin was invited to participate as one of the creators and creator economy professionals in the first ever White House creator economy conference. Franklin works full time as a product counsel at LinkedIn Corporation. As a member of the product and data team, he focuses on emerging issues in AI and data. Franklin previously held roles on the technology law group at HCA Healthcare, the commercial legal team at Eventbrite, and the business and legal affairs team at Naxos Music Group. Welcome back Franklin to the IP Fridays podcast. Franklin Graves: Thank you so much for having me. It is exciting to be back and reflecting over the last decade since I last joined and also the paper that I wrote that dives into this in more detail. So I really appreciate it. And yes, full disclosure, I currently work for LinkedIn, which is a subsidiary of Microsoft. I’m here in my personal capacity to talk about this, the paper I wrote before joining LinkedIn and all of that. So thank you so much for having me back. Ken Suzan: Excellent. So Franklin, since your last appearance on IP Fridays in 2017, your career has evolved significantly. You are now senior product counsel at LinkedIn focusing on AI and data. How has working inside a major tech platform changed your perspective on the legal frameworks governing digital content compared to when you were viewing it purely from the creator side? Franklin Graves: I appreciate that question because when I wrote the article, I did not work for LinkedIn. And I had been coming from a history in my career where I, right out of law school, worked for a record label like we talked about almost 10 years ago. And I was on the content creation side. I’ve represented a major distributor of classical music digitally at the time. And that was my first exposure to understanding how content was taken from the initial inception stage from creators and routed through all the various digital platforms that were at the time still evolving and even arguably still today continue to evolve. The early days of YouTube Music launching and then Apple Music launching, and then going through all the phases of high-res audio and everything that came after that. So that was an interesting perspective to start my career with. And then I went to Eventbrite, which is a ticketing platform, but was also focused on elevating event creators. They kind of took on that moniker of “Hey, we are event creators that we support.” And that was arguably my first exposure to the platform side, the tech platform side of it, because Eventbrite is a platform. And so then I evolved from there in my personal capacity, in a pro bono capacity representing individual creators across the YouTube space. And that’s what we talked about a little bit back when I first came on the podcast. Franklin Graves: Over the last decade, it’s been a chance to grow my own understanding of the creator economy. The terminology “creator economy” came around. And then now on the other side of it, having written the article and all that, and now being fully in-house at LinkedIn, I truly am experiencing a social media platform. LinkedIn is of course arguably way more than just the platform itself. There are so many different avenues to it, but it is a chance for me to understand what it is like working for a company that is operating the platform that people are distributing content on. There’s a user journey to content and all of that. So it’s definitely enhanced and given me a different perspective from a major tech platform side. And part of my role at LinkedIn is really heavily focused on understanding regulation and how that from an AI and data perspective impacts the company. And so I’ve been really leveling up my game over the last year and a half that I’ve been here, understanding mostly EU regulations, but also US regulations that are still in their infancy when it comes to AI. But really when it comes to privacy and data, those are pretty well established across the board. It’s been kind of a combination of what I learned at Eventbrite, because I went to Eventbrite when GDPR was going into effect. And so that was an eyes-wide-open moment of getting in the weeds with negotiating data processing agreements, understanding data transfers and cross-border data transfers and the like. So it’s been kind of an evolution as the laws and regulations have evolved. So has my career, so has my own understanding, so have the platforms’ responses to those laws and regulations. And I’m sure that probably resonates with a lot of your listeners who have also been growing their practice and their understanding as the laws and regulations in this realm have been evolving too. Ken Suzan: Yes, indeed. Now let’s switch gears and talk about AI. You advise on AI and data daily. As platforms integrate generative AI tools into their tech stacks, what are the most critical best practices in-house counsel should be adopting right now to embed responsible AI principles into product development? Franklin Graves: So as an attorney, one of my key roles is to understand the technology. Even representing creators and working for creator platforms, that’s something I’m constantly trying to do: put myself in the shoes of being a creator. And I think I talked about this last time I was on, but I come from a background where I was working for a major label doing marketing, video editing, social media work. And I was creating content. I understood the whole life cycle from the inception point of an idea to execution and then to the final delivery and distribution of that content to an audience within a major music label. And so part of that is the same thing that I think attorneys, especially in-house, should be doing: using the tools that the product and engineering teams are either developing in-house or partnering with third parties to develop, or a combination of the two. Using them, understanding them, using them as a creator would, using them as an end user or a client or customer would. And making sure that if you understand the product and understand the nuances of how it operates, and being a part of the iterations of that internally before it fully ramps, that really gives you a chance to understand: okay, we have a lot of responsible AI principles and standards and protocols that are in existence right now, whether it’s NIST, whether it’s based on the EU AI Act or anything and everything in between. It’s understanding how to apply those and bring those into a product and an engineering environment in a way that is practical and actionable for the people that you’re supporting, the stakeholders you’re supporting. So I think one of the critical best practices is, number one, understand the product or features that you’re supporting. Franklin Graves: And then understand how you as an attorney can use your expertise and understanding of responsible AI practices, whether it’s a regulatory standard or an industry-adopted standard or a hybrid of the two, to leverage those and implement those, break those down and make them into actionable controls and processes and flows that work within your existing infrastructure. That’s a lot of high-level talk, but that’s the general idea. One concrete example we talk about frequently is with open source AI. If you’re working with a product team or an engineering team that is taking an off-the-shelf open source model and bringing that in-house, a lot of times companies have pre-existing open source processes that cover the use of open source software or code. Piggyback on that. That’s the easiest quick win for attorneys: leveraging your existing open source processes to just build on top of that the AI flavor and layering. It’s not very much that you have to do, but the underlying process of the key stakeholders that need to be involved in the review, whether it’s security, whether it’s executive sign-off if it gets to that point, even export control considerations should already be part of your existing open source software process. So layering in on those existing processes the specifics of generative AI or large language models that you’re trying to bring in is a great way to put this into practice. Ken Suzan: Now looking at the geopolitical landscape that we currently have, we have the EU AI Act setting strict standards and shifting US executive orders. How should platforms and brands prepare for this fragmented regulatory environment when deploying AI tools to a global user base? Franklin Graves: It’s a great question. It’s something that is still evolving, I think is fair to say. I would equate it, as I do in the paper that I wrote, to how creators and arguably brands don’t own the platforms that they’re building their communities on. That spawned this concept of de-platforming or going into building your own platform, a decentralized platform of sorts, and owning your community. That gives you that control and takes away the level of instability that can come for creators trying to build a business on a platform they don’t own, they don’t control when certain updates happen, when algorithms change, when tools and functionalities either become available or go away completely. So it’s very similar to what we’ve been experiencing in a regulatory environment where we have geopolitical complexities, for lack of a better term, that can overnight seemingly disrupt the way in which a platform or even a multinational brand is able to connect and reach an audience or continue to leverage the user base that they’ve built. I think TikTok is a great example of that, where it became a national security concern and suddenly it was facing an executive order that required it to be effectively disabled in the US or completely owned and operated by a US entity. All the mechanics and technicalities of whether it’s actually possible and still have a global platform with a global user base is a whole different discussion. But that’s an example of very similar considerations that are now not just a discussion point at the creator level or the individual brand level, but also in a much broader context at a platform level as well. Ken Suzan: Franklin, let’s now shift gears and talk about your article. In your recently published journal article, Upload Complete, which we will have linked in our show notes, you advocate for a shift in terminology from internet creator law, a term used during our first podcast almost a decade ago, to creator economy law. Why is this distinction important and how does it change the way legal practitioners should view the ecosystem of creators, brands, and platforms? Franklin Graves: Oh yes, this is part of the reason why I wanted to write the article: to lay this foundation of understanding. Because at the time I’d written the article, the term creator economy and creator had really not appeared but for maybe once in an actual court decision. And it was kind of focused on influencers and this concept, and it was just not getting it right. And so it was also, as you mentioned, when we first spoke I was even using the term internet creators. And I think that was something that was common at the time. The “internet” portion as a qualifier has since dropped off. And now for purposes of the creator economy, the term creators refers to individuals, it can be small businesses, which is what we’ve seen from a regulatory standpoint, how these small businesses are being impacted by regulations. But essentially creators in the article I pin in the context of intent. What is the intent behind the person or the small business that is posting content, trying to build a community and form a community in a virtual environment? And then that can even spill over into real physical world environments. And so the intent is kind of what I look at. Franklin Graves: And I have a chart in the article that has a diagram showcasing the overlap of what I refer to as “users generating content.” It’s a play on the concept of user-generated content, UGC. Users generating content is that large bucket of anyone posting on a platform of some kind. And within that large bucket, that large circle, are smaller subsets. You have creators, you have brands. Those are really the two buckets you can put people into. Otherwise it’s like your grandmother or your parents posting content on Facebook or Instagram, and those are everyday users of a platform. The distinction to get into that subcategory of being a creator more so has been analyzing the intent behind the posting. Are you posting content to build an audience, to build a community, to eventually have a chance to monetize the following that you’re bringing in or sell services or something like that? Brands are posting for that reason. Creators are maybe posting for that same reason. But even within the creator category, there’s a subcategory of influencers that are trying to sell something, that are trying to build more than just an awareness of who they are, their influence. They are trying to do brand deals, partnership deals, upsells and all that, and start an actual small business aside from just the content itself that they’re creating. So that’s kind of the distinctions that I make in the paper. And that’s why it’s important to understand and lay that foundation, that anyone can post content online, but the intent, the why behind their posting that content, really does ultimately matter, especially when you’re looking at it from a court case or from a regulatory standpoint. Ken Suzan: Now, Franklin, we’re seeing unprecedented geopolitical activity around platform ownership. For example, the US legislation targeting TikTok and Brazil’s recent temporary ban of X. How do these macro-level battles impact the day-to-day livelihood of creators? And how can they legally and operationally protect themselves? Franklin Graves: So the shift that we’re seeing, and I alluded to this earlier in our conversation, is this concept of Web 3. And that term may or may not be really popular anymore, but that’s essentially what we’re looking at: a shift into a federated, decentralized operation of a platform. So instead of one owner, one company, one entity owning and operating the platform, it’s decentralized. Anyone can start up a server, and it’s interoperable, meaning anyone can plug and play and connect to that larger network. And it creates this unified social network experience. Within each operating node of that network, there can be your own decisions around content moderation, your own decisions around the hosting providers you use, where you’re operating out of, the terms and conditions that apply to that. But the flip side is that instead of creators posting and sharing in a closed environment run and controlled by a singular entity, you’re now experiencing a peer-to-peer type operation where your experience can change based on which server, which node, which user you’re engaging with. You might have content that’s acceptable in one area but not acceptable in another, and maybe it just doesn’t even show up in that other area. Franklin Graves: But from a liability standpoint, as creators start to build their own networks and communities, even outside of a concept like the fediverse, it’s even down to creators building their own communities through online courses, subscription membership-based platforms that they run on their own website. There’s open source software out there, even something called Ghost, where you have memberships. And that is a creator or a small business in the creator economy that is now taking on the obligations that would typically fall upon a platform. They need to take into consideration terms and conditions, privacy policies, legal aspects, and regulatory considerations for running a platform, especially in a global world. So it’s a lot of liability that then shifts over to those small businesses and even brands sometimes that are doing the same thing. Whether it is something as simple or complex as content moderation or all the way up to monetizing an audience, this new world where creators can spin up and run a platform all dovetails back to the concept of creators not feeling like they have control in reaching the audience and the community that they’re building on an individual platform. And so this really became more mainstream conversation with TikTok and the issues around it potentially being shut down in the US. That was kind of the mindset shift and eyes opening for many creators, especially within the influencer subset, of realizing: we need to make sure that we have a way to reach the audience we’ve built if the individual platform that we’ve committed to over the last year or three years or so is no longer available. We need a way to continue that relationship outside of that one platform controlling it. Ken Suzan: Franklin, we have a few minutes left and a number of topics. So I’m going to switch gears and talk about a few issues. First, a major emerging topic in your paper is the evolution of protecting kids online. With state-level age-gating laws like the CAADCA and the recent FTC updates to COPPA, how should platforms navigate the significant tension between strict age verification mandates and the privacy and First Amendment rights of their users? Franklin Graves: Man, that is a whole discussion to unravel. It is a consideration that we’re seeing happen again, going back to the geopolitical nature of everything. Countries like Australia and certain countries in Europe and now even individual states in the US are trying to look at ways, and some of them have already put into place minimum age requirements before you can even sign up for an account with a social media platform. One of the things I’d just highlight quickly here is that one of the tensions is around how you verify someone’s age online and still maintain the ability to be at least pseudonymous. How do you still have a level of privacy, autonomy, and protection when it comes to having to provide something like a driver’s license or have parental consent tied and connected to an account managed by a parent in a situation where maybe it’s not appropriate or not beneficial to the child in that manner? But then maybe there are counterbalancing factors that outweigh that. All of that comes down to the technicalities of how it’s actually implemented and maintaining the sense of openness and freedom that we’ve had on the internet to date. And then the other element there is, since a lot of the internet that we think of today is more so through mobile applications, is it something that the mobile operating system providers and app store providers should be thinking about? So whether that’s the Google Play Store or the Apple App Store, where does that initial age verification need to fall? Is it at the platform level? Is it the app store or mobile device management level or something else? Yeah, there’s a lot to discuss there. And a lot of the issues we’re seeing with how the internet is changing in terms of being able to browse a website without disclosing personal information that might not have been required before is largely stemming from a focus on protecting children online. Ken Suzan: It sounds like, Franklin, we could have another episode covering lots of issues connected with that one topic alone. Franklin Graves: I would absolutely agree with that. There’s a lot going on there. And again, it’s different across the world. And so I know you all have a global listener base. And so there’s a lot of nuances to that whole discussion too, that are worth exploring. Ken Suzan: Last question for today’s episode is regarding the right of publicity. With the explosion of AI-generated synthetic media, digital replicas, and voice cloning, the right of publicity is taking center stage. What are the biggest legal risks for brands partnering with influencers right now? And how can creators protect their most valuable asset, their likeness? Franklin Graves: That’s a great question. I think we’re seeing kind of a throwing-spaghetti-against-the-wall-to-see-what-sticks approach right now by a lot of different parties, whether it’s trademark attorneys, whether it’s general entertainment attorneys or whoever. For example, we’ve seen Taylor Swift filing trademarks to protect certain sounds of her voice and phrasing that she uses. It’s a difficult area because in the realm of generative AI with deep fakes and virtual avatars, that is where it gets tricky, because traditional IP laws are just not able to fully cover that spectrum. It’s a piecemeal approach, but even then it doesn’t fully cover it. So for example, I’m based in Tennessee and a couple of years ago we had the Elvis Act that updated our right of publicity law to add voice and to explicitly reference artificial intelligence. And so that’s the kind of effort we’re probably going to continue to see: efforts to develop some framework around protecting what is essentially a privacy right, in a manner that doesn’t restrict generative AI systems from continuing to develop and operate the way they’re operating now, while layering in those protections so that in the US at least a First Amendment right doesn’t necessarily get squashed, and those traditional well-recognized efforts to not overregulate a technology in its early stages are respected. Franklin Graves: And so I think a lot of what we’re seeing is just a need to update laws. The SAG-AFTRA debate and the strikes that happened around maintaining control of your performance and any iterations of that, or building upon that by a media company that might come later, it’s all on the table right now and still being discussed, still being worked out. I think in the short run, a lot of times if it’s in a brand deal, the key question is: if you are using generative AI to enhance in some way the final deliverable for the campaign, who has control over that? Who has final say and sign-off on how that likeness or that digital replica or that person’s voice is represented? And even outside of the brand space, we’ve seen actors like James Earl Jones signing over certain aspects like their voice and allowing it to continue to be used in these manners powered by generative AI as Darth Vader. And I think I saw something that Boy George was even starting up an AI company that allows musicians, the original recording artist, to rerecord new versions of their masters so that they don’t miss out on that revenue. It’s powered by generative AI, by taking their voice now, which is significantly different than it was back in the 80s, and using generative AI to make it sound closer to the original, but all based on their current performance. So I think it’s still an evolving area. And what’s interesting too is on the platform side, we’re seeing the early stages of platforms like Google starting to acknowledge and rely on the license grant contained in their terms of service for YouTube, which grants them broad rights to use the content to run their platform. So all that to be said, it’s still early stages. I’m very interested to see where we go from here in the future, especially from a global perspective as well. Ken Suzan: Franklin, I could spend hours talking to you about this. You’re such a knowledgeable person on these topics. Maybe in a few years, will we connect again and talk further on AI and all the things that are yet to be developed? Franklin Graves: Thank you. Yeah, it doesn’t have to be another decade. Maybe we can cut it to half a decade, given the pace at which technology is going now. Ken Suzan: Sounds good, Franklin. Thanks again for being on the IP Fridays podcast.

The CyberWire
All eyes on AI.

The CyberWire

Play Episode Listen Later Jun 23, 2026 24:47


Five Eyes warns AI could supercharge cyberattacks within months. Tata Electronics confirms breach as stolen data allegedly includes Apple and Tesla documents. Researchers publish new analysis of FortiBleed. Gizmodo breach exposes readers to ClickFix malware campaign. BootROM exploit can bypass Apple's SecureROM. Scattered Spider members plead guilty in the UK. Attackers exploit Gravity SMTP flaw to harvest secrets From WordPress sites. Executive Order accelerates federal shift to post-quantum cryptography. Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts. Keeping tabs on the tab-keepers. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today Dave Bittner sits down with Ellen Boehm, the Senior Vice President of IoT Strategy & Operations at Keyfactor, to discuss NIST's progress in its PQC efforts and where more effort needs to be made to get the U.S. and its critical infrastructure quantum-ready. Selected Reading 'Five Eyes' intelligence alliance warns that new AI models pose urgent cyber risk (Reuters) Intel agencies: Frontier AI models will reshape cybersecurity faster than expected (CyberScoop) Anthropic's Mythos AI broke into almost all NSA classified systems in hours (SecurityAffairs)  Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach (TechCrunch) FortiBleed campaign used custom FortiGate sniffer to steal credentials (BleepingComputer) Gizmodo readers hit with ClickFix malware prompts after account compromise (The Register) New Exploit Bypasses Apple's Boot Defenses, Affects Millions of iPhones (SecurityWeek) TFL Hackers Admit Carrying Out Cyberattack That Cost £39M (Law360) Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin (Wordfence)  Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration (Security Week) Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

This Week in XR Podcast
Special From CES 2026: AI Strategy, Tariffs, and the Future of Consumer Tech ft. Gary Shapiro, CEO

This Week in XR Podcast

Play Episode Listen Later Jun 19, 2026 58:57


Gary Shapiro has spent decades at the center of the global consumer technology industry, leading the Consumer Technology Association (CTA) and building CES into one of the most important stages for innovation, policy, and deal-making on the planet.In this first episode of 2026, Gary joins Charlie, Rony, and Ted to preview CES, unpack the explosion of AI across every category, and deliver unusually blunt takes on tariffs, China, manufacturing, and U.S. innovation policy. He explains how CES has evolved from a TV-and-gadgets show into a global platform where boards meet, standards are set, and policymakers, chip designers, robotics firms, and health-tech startups all collide.In the News: Before Gary joins, the hosts break down Nvidia's $20 billion “not-a-deal” with Singapore's Groq, the stake in Intel, and what that combo might signal about the edge of the GPU bubble and the shift toward inference compute, x86, and U.S. industrial policy. They also dig into Netflix's acquisition of Ready Player Me and what it suggests about a Netflix metaverse and location-based entertainment strategy, plus Starlink's rapid growth and an onslaught of “AI everything” products ahead of CES.Gary walks through new features at this year's show: CES Foundry at the Fontainebleau for AI and quantum, expanded tracks on manufacturing, wearables, women's health, and accessibility, plus an AI-powered show app already fielding thousands of questions (top query: where to pick up badges).He also talks candidly about his biggest concern—that fragmented state-level AI regulation (1,200+ state bills in 2025) will crush startups while big players shrug—and why he believes federal standards via NIST are the only realistic path. The discussion ranges from AI-driven healthcare and precision agriculture to robotics, demographics, labor culture, global supply chains, and what CES might look like in 2056.5 Key Takeaways from Gary:AI is now the spine of CES. CES 2026 centers on AI as infrastructure: CES Foundry at the Fontainebleau for AI + quantum, AI training tracks for strategy, implementation, agentic AI, and AI-driven marketing, and an AI-powered app helping attendees navigate the show.Fragmented state AI laws are an existential risk for startups. Over 1,200 state AI bills in 2025—including proposals to criminalize agentic AI counseling—could create a compliance maze only large incumbents can survive, which is why Gary argues for federal standards via NIST.Wearables are becoming systems, not gadgets. Oura rings, wrist devices, body sensors, and subdermal glucose monitors are starting to be designed as interoperable families of devices, with partnerships emerging to combine data into unified health services.Robotics is breaking out of the industrial niche. CES will showcase the largest robotics presence yet, moving beyond factory arms and drones to humanoids, logistics, social companions, and applied AI systems across sectors.Tariffs, alliances, and AI will reshape manufacturing. Gary is skeptical of “Fortress USA” strategies that try to onshore everything, pointing instead to allied reshoring (Latin America, Europe, Japan, South Korea) and the long-term role of AI-powered robotics in changing labor economics and global supply chains.This episode is brought to you by Zappar, creators of Mattercraft—the leading visual development environment for building immersive 3D web experiences for mobile headsets and desktop. Mattercraft combines the power of a game engine with the flexibility of the web, and now features an AI assistant that helps you design, code, and debug in real time, right in your browser. Whether you're a developer, designer, or just getting started, start building smarter at mattercraft.io. Hosted on Acast. See acast.com/privacy for more information.

The Thoughtful Entrepreneur
2443 - What Every Accountant Needs to Know About Cybersecurity Compliance in the Age of AI with CardinalsByte's Michele Novack

The Thoughtful Entrepreneur

Play Episode Listen Later Jun 17, 2026 19:16


The AI-Driven Threat Matrix: Architectural Cybersecurity and Compliance for Small Firms with Michele NovackIn a recent episode of The Thoughtful Entrepreneur Podcast, host Josh Elledge sat down with Michele Novack, the host and founder of Cardinalsbyte, to break down the rapidly evolving cyber vulnerabilities that threaten the financial solvency of small businesses. As a veteran risk strategist specializing in the financial services sector, Michele highlights how CPAs, accountants, and tax professionals have become prime targets for sophisticated, automated digital attacks. This conversation delivers an intentional operational roadmap for mid-market founders and executive teams looking to navigate tightening federal mandates, identify hidden security gaps within their existing infrastructure, and defend their enterprise value against highly advanced, AI-powered corporate fraud.The Anatomy of Digital Defense: Mitigating Algorithmic Vulnerabilities through Zero-Trust ProtocolsThe rapid proliferation of consumer-facing artificial intelligence has weaponized the digital threat landscape, enabling bad actors to execute automated, hyper-personalized social engineering campaigns at an unprecedented scale. Michele Novack cautions that small businesses can no longer rely on traditional, passive firewall defenses as cybercriminals increasingly deploy sophisticated voice cloning, automated phishing sequences, and deepfake video streams to bypass conventional security guardrails. A single compromised corporate email account can result in catastrophic financial loss, as demonstrated by emerging corporate wire fraud schemes where payroll managers are manipulated by synthetic, AI-generated replicas of their CEO during live video conferences. To counter this automated disruption, executive leadership must enforce rigid, non-negotiable zero-trust verification protocols—requiring multi-channel, manual confirmation for all financial movements and high-stakes data extractions completely independent of digital messaging networks.Insulating a firm against regulatory penalties and liability requires a disciplined commitment to formalizing internal data compliance programs rather than treating security as an ad-hoc IT checklist. Tightening federal mandates, such as the revised FTC Safeguards Rule and IRS security guidelines, now legally obligate financial services providers to maintain comprehensive, written documentation detailing their operational defenses. Many business owners operate under the dangerous assumption that their external Managed Service Provider (MSP) inherently handles regulatory compliance, leaving the enterprise exposed to massive liability gaps due to a complete lack of formal Written Information Security Programs (WISPs) and documented Incident Response Plans (IRPs). True enterprise resilience is achieved when leadership takes proactive ownership of corporate compliance, closing security gaps by performing routine endpoint audits, implementing geographical IP blocking, and maximizing the advanced, built-in security features native to enterprise cloud suites like Microsoft 365 or Google Workspace.Transforming an organization's digital posture ultimately relies on establishing a transparent, security-first corporate culture that bridges the gap between complex technical tools and human operational habits. Because human manipulation remains the primary vector for enterprise data breaches, continuous, jargon-free employee training is a vital piece of operational infrastructure. Rather than deploying clinical, one-and-done IT lectures that fail to change day-to-day employee behavior, founders must implement continuous, interactive education loops and safe phishing simulations that sharpen frontline skepticism. When clear behavioral habits, automated endpoint monitoring, and verified compliance documentation are synthesized under a unified governance architecture, a business successfully limits its operational risk. This proactive stance converts cybersecurity from a costly technical burden into a powerful, high-valuation corporate asset that fiercely protects the organization's market authority.About Michele NovackMichele Novack is the host, founder, and chief risk strategist of Cardinalsbyte, and a premier authority on small business data security and financial compliance management. Drawing from decades of specialized experience within the financial services and accounting sectors, Michele focuses on demystifying complex technical architecture to make regulatory frameworks accessible for corporate executives. She is a dedicated educator and advisor who specializes in constructing high-accountability cyber defense models designed to protect small-to-mid-sized enterprises from advanced electronic corporate theft.About CardinalsbyteCardinalsbyte is an elite risk management and cybersecurity compliance consultancy that provides custom data-protection solutions, vulnerability assessments, and regulatory mapping for professional services firms. The company specializes in translating complex federal guidelines, such as NIST frameworks and IRS mandates, into actionable corporate playbooks including Written Information Security Programs (WISPs). Through proactive technical testing, executive risk summaries, and white-glove incident response coordination, Cardinalsbyte enables mid-market organizations to eliminate administrative security debt and shield their bottom lines from systemic digital threats.Links Mentioned in This EpisodeCardinalsbyte Compliance Partner Page: cardinalsbytes.com/compliance-partnerMichele Novack on LinkedIn: linkedin.com/in/cardinalsbyte-mnovackKey Episode HighlightsThe AI Weaponization Trap: Analyzing how deepfakes, automated voice cloning, and synthetic media bypass traditional corporate communication filters to enable catastrophic wire fraud.The MSP Compliance Gap: Understanding why standard IT vendors fail to provide mandatory regulatory documentation, and how to self-correct using structured WISPs.Maximizing Built-In Cloud Security: Leveraging and configuring the advanced, pre-existing anti-phishing dashboards embedded within Microsoft 365 and Google Workspace.The Multi-Channel Verification Mandate: Implementing mandatory human-in-the-loop protocols that require dual physical authorization for high-volume financial movements.Building a Skeptical Corporate Culture: Shifting internal security training from a static annual checklist into continuous, interactive education that reduces human error on the frontline.ConclusionThe conversation with Michele Novack underscores that true cybersecurity resilience is an ongoing exercise in structural governance and human vigilance rather than an expensive software purchase. By standardizing internal corporate compliance, executing rigorous endpoint audits, and building an inclusive culture of behavioral accountability, business leaders can transform a vulnerable digital setup into a highly secure, enterprise-grade corporate asset.More from The Thoughtful Entrepreneur

KMJ's Afternoon Drive
America's Time Capsule Contents Revealed Ahead of July 4 Burial

KMJ's Afternoon Drive

Play Episode Listen Later Jun 16, 2026 26:54


America’s Time Capsule was developed in collaboration with scientists at NIST, preservation experts at the Library of Congress, and in coordination with the National Park Service. It was built at NIST’s technology fabrication shop in Gaithersburg, Md. Please Like, Comment and Follow 'Philip Teresi on KMJ' on all platforms: --- Philip Teresi on KMJ is available on the KMJNOW app, Apple Podcasts, Spotify, YouTube or wherever else you listen to podcasts. -- Philip Teresi on KMJ Weekdays 2-6 PM Pacific on News/Talk 580 AM & 105.9 FM KMJ | Website | Facebook | Instagram | X | Podcast | Amazon | - Everything KMJ KMJNOW App | Podcasts | Facebook | X | Instagram See omnystudio.com/listener for privacy information.

ITSPmagazine | Technology. Cybersecurity. Society
A Crime Against Time | An Interview with Rik Ferguson | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 15, 2026 14:54


PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli Adversaries are stealing encrypted data today that they cannot read yet, and storing it until a quantum computer can. Sean Martin sat down with Forescout's Rik Ferguson to talk about “harvest now, decrypt later,” why Q-Day is closer than the comfortable timelines suggest, and what the decisions you make this year have to do with secrets you thought were safe forever.

Resilient Cyber
AI Industrialized the Vuln Lifecycle and Broke the System of Record

Resilient Cyber

Play Episode Listen Later Jun 15, 2026 40:43


VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck.DescriptionVulnerability management spent years as the chore everyone dreaded, and now it is one of the hottest topics in security because attackers made exploitation the number one way in. Patrick Garrity of VulnCheck rejoins the show to separate what is real from what is marketing. We get into the honest state of the NIST National Vulnerability Database after CISA pulled its funding, the new AI executive order that wants a clearinghouse for AI-discovered vulnerabilities, the first measurable wave of AI-assisted disclosures, and Patrick's audit of Anthropic's Glasswing ledger. We also dig into why cheap AI discovery makes the remediation bottleneck worse, how AI is raising the security poverty line, and whether the 90-day disclosure model still holds.Key takeawaysVulnerability management is hot again because attackers made it the top way in. As Patrick puts it, attention flows to wherever the attacker goes, and right now that is exploitation.The NIST NVD breakdown was worse than a backlog. A recent report confirmed CISA had stopped funding the NVD and NIST lost about half its funding, with no real plan to clear the backlog, which quietly hurts every defender who relies on enriched CVE data.A new AI executive order wants a clearinghouse for AI-discovered vulnerabilities, reportedly under Treasury. Patrick's reaction is that we already have a vulnerability database, the program is optional, and it may turn into a marketing race more than a coordination win.The first measurable AI disclosure wave is real. CVE volumes are up 563 percent for Chrome and GitHub advisories up 470 percent year to date, and Patrick separated genuine AI-assisted discovery from AI slop and from bugs that merely live in AI software by correlating researchers, domains, and email addresses across multiple advisory sources.Patrick audited Anthropic's Glasswing ledger and found the transparency lacking. He had around 80 vulnerabilities in his own database while the public ledger listed 27, several items had blown past their own 90-day disclosure window, and the ledger had not been updated in two weeks.Finding vulnerabilities is not the bottleneck, remediation is. AI makes discovery cheap, but the coordinated disclosure and fix process takes enormous human effort, and the median time to remediate even known exploited bugs is still measured in weeks.Exploitation looks like it is sustaining rather than surging. CISA KEV and VulnCheck KEV are tracking similar year-over-year volumes, partly because attackers already have more than enough to target and partly because you can only count the exploitation you can actually detect.AI is raising the security poverty line, at least for now. Token costs and access-restricted tools concentrate the most powerful discovery capabilities among well-funded teams, while smaller organizations lack the expertise to turn open-weight models into working vulnerability harnesses.The economics are circular. AI drives the surge in findings and attacker velocity, and AI is then sold as the fix, so teams pay to surface the problem and pay again to remediate it, all on consumption-based pricing against finite budgets.The 90-day disclosure norm mostly holds, though it may tighten. VulnCheck runs a strict 120-day policy with no exceptions and averages 45 to 48 days to fix and disclose, and for open source the fixing commit often makes the flaw public anyway.

HPE Tech Talk
Are we ready for the quantum age of computing?

HPE Tech Talk

Play Episode Listen Later Jun 11, 2026 19:17


Are we prepared for the deployment of a functional quantum computer? This week, Technology Now is returning to the topic of post quantum cryptography. We ask why the deadline for migrating to PQC enabled systems has been moved up, we discover what a quantum computer actually needs to be cryptographically relevant, and we pose the question: when it comes to migrating your systems to quantum resistant forms of encryption, could it already be too late for some people to start?This is Technology Now, a weekly show from Hewlett Packard Enterprise. Every week, hosts Michael Bird and Sam Jarrell look at a story that's been making headlines, take a look at the technology behind it, and explain why it matters to organizations.

La Martingale
#321 - IA et quantique : la nouvelle menace sur votre argent - Charles Guillemet

La Martingale

Play Episode Listen Later Jun 11, 2026 58:08


Le sujet :À l'ère de l'IA, la sécurité n'est plus une option. Les coûts et les délais pour exploiter les failles d'un système sont en train de disparaître. Mais le pire pourrait être à venir. La cryptographie actuelle est menacée par l'informatique quantique, remettant en question de nombreux protocoles. Cette nouvelle donne force une migration de tous les systèmes critiques vers le post-quantique d'ici 2030, une échéance fixée par le NIST. Dans ce contexte, la sécurité de nos actifs numériques, de nos cryptos à nos mots de passe, n'a jamais été aussi précaire.L'invité du jour :Charles Guillemet est le CTO de Ledger. Au micro de Matthieu Stefani, il alerte sur la catastrophe de sécurité imminente due à l'IA et au quantique, et détaille les stratégies de défense, du wallet physique au "25e mot".Au programme :00:00:00 : La mission de Ledger : sécuriser les systèmes00:01:54 : Où sont vraiment "stockés" vos Bitcoins00:04:49 : Comment sécuriser ses cryptos (sans risquer de tout perdre)00:08:30 : Pourquoi l'IA menace la sécurité de vos portefeuilles : l'asymétrie défense/attaque00:17:47 : Les banques tradi sont-elles à l'abri ?00:20:30 : Le quantique : quels sont les vrais cas d'usage00:24:49 : Le QDay : le monde devra changer00:30:51 : Ton téléphone est ta pire vulnérabilité00:36:27 : Les pires mots de passe à utiliser00:38:07 : La preuve d'identité : l'IA et les deep fake00:41:39 : La France et le manque de sécurité : comment se protégerAvantages :Bonne nouvelle ! Nous avons négocié pour vous un avantage exclusif : obtenez 10$ en Bitcoin pour l'achat d'un Ledger, pour en profiter, rendez-vous sur : https://www.ledger.com/lamartingale Merci à notre partenaire eToro de soutenir la Martingale.Allez sur etoro.com et prenez le contrôle de vos investissements. E-T-O-R-O point com.eToro est une plateforme d'investissement multi-actifs. La valeur de vos placements peut augmenter ou diminuer. Votre capital est assujetti à un risque.La libre antenne de votre podcast préféré, Allo La Martingale, a désormais son propre flux ! Abonnez-vous sur Spotify, Apple Podcasts ou votre plafeforme audio favorite pour ne manquer aucun nouvel épisode. Pour s'abonner à la newsletter, c'est ici : https://lamartingale.io/ La Martingale, c'est aussi un assistant IA qui vous apporte des réponses éclairées issues des interventions des experts passés au micro du podcast. Pour tester, direction https://beta.lamartingale.ioLa Martingale est un média d'Orso Media. Vous souhaitez entrer en contact avec a rédaction ? Ou nous soumettre une collaboration ? Ecrivez-nous ici : https://orsomedia.io/contactHébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

The Post-Quantum World
The Race to Save Bitcoin – with Chris Tam of BTQ

The Post-Quantum World

Play Episode Listen Later Jun 10, 2026 36:54


Is the ultimate cryptocurrency ticking toward a sudden, quantum-powered collapse? In this episode, Chris Tam, President and Head of Innovation at BTQ, joins host Konstantinos Karagiannis to shatter the comforting illusions many Bitcoiners still hold about the quantum computing threat. While many assume that a Q-Day attack would only disrupt future mining, Tam exposes the true, terrifying reality: Quantum computers utilizing Shor's algorithm are on an exponential trajectory to cracking the elliptic curve cryptography that safeguards individual wallets. Even worse, recent upgrades like Taproot have inadvertently introduced more vulnerable public keys into the ecosystem, making a network upgrade more complex than ever.The real crisis isn't just finding a cryptographic fix: it's time. Experts warn that migrating the entire decentralized Bitcoin network to a post-quantum standard could take upwards of seven years, but the network simply lacks the block space to move everyone before quantum adversaries are predicted to break the encryption. To bypass the political gridlock of Bitcoin core development, Tam details how BTQ surgically built a working, post-quantum Bitcoin Quantum testnet to experiment with solutions like BIP 360 in the real world. From the catastrophic ripple effects a Bitcoin hack would have on traditional financial markets to BTQ's pioneering work on day-one quantum-resistant stablecoins in South Korea, this episode is an urgent, eye-opening wake-up call for anyone holding digital assets.For more information on BTQ, visit www.btq.com/. Visit Protiviti at www.protiviti.com/US-en/technology-consulting/quantum-computing-services to learn more about how Protiviti is helping organizations get post-quantum ready.  Follow host Konstantinos Karagiannis on all socials: @KonstantHacker             Questions and comments are welcome!  Theme song by David Schwartz, copyright 2021.  The views expressed by the participants of this program are their own and do not represent the views of, nor are they endorsed by, Protiviti Inc., The Post-Quantum World, or their respective officers, directors, employees, agents, representatives, shareholders, or subsidiaries.  None of the content should be considered investment advice, as an offer or solicitation of an offer to buy or sell, or as an endorsement of any company, security, fund, or other securities or non-securities offering. Thanks for listening to this podcast. Protiviti Inc. is an equal opportunity employer, including minorities, females, people with disabilities, and veterans.  

Business of Tech
Consumption-Based AI Billing Increases Financial Risk for Unprepared MSPs

Business of Tech

Play Episode Listen Later Jun 5, 2026 13:46


The current structural shift centers on the transfer of accountability for AI risk from vendors and regulators to managed service providers (MSPs). Vendors such as Anthropic and Microsoft are expanding their enterprise-focused AI channel programs and services tracks, while regulators pull back from enforcement, leaving MSPs as the de facto accountable parties for AI deployments. Reports and data indicate that vendor-driven channel expansion and regulatory laxity are converging to make service providers the liable layer in AI delivery. Anthropic is broadening its CLAUDE partner network from around 100 to several thousand partners, organized in tiers with outcome-based incentives and a dedicated services track targeting MSPs and system integrators. Microsoft, responding to low Copilot adoption rates (reported at 3.3% of eligible users), is allowing full removal of Copilot from systems. An IDC/Expereo survey of 800 companies found 70% are budgeting for AI, but investment is driven more by competitive anxiety than proven results. Additionally, a concentrated group—top 5% of users—accounts for the bulk of enterprise AI-related risk, according to a separate analysis. Supporting developments include the emergence of Lemhi, an early-stage platform aimed at enabling MSPs to package and sell AI transformation as a recurring service, and warnings from lawmakers about cuts to CISA that undermine federal cyber defense capacity. The episode also highlights a consistent theme: government agencies such as the White House and NIST are shifting toward voluntary measures and measurement frameworks, declining to create enforceable accountability standards for AI in production environments. For MSPs and IT leaders, these developments translate to increased contract and operational risk. Without renegotiated agreements specifying usage ceilings, approval workflows, and liability terms, providers may inherit unpredictable financial exposure and compliance gaps. The absence of effective governance requirements from both vendors and authorities places the operational burden on MSPs to define, monitor, and enforce safe use of AI, including recurring governance services such as data boundary enforcement and audit evidence. Failure to address these issues may result in MSPs acting as uninsured support for unmanaged AI deployments they cannot fully control or price. 00:00 MSP AI Play  04:24 AI's Accountability Gap 06:50 MSP Risk Transfer 09:49 Why Do We Care?  Supported by:  ScalePad Moovila 

Unchained
The Chopping Block: Ethereum's Inflection Point w/ Joe Lubin on DATs, CROPS, AI-Driven Exploits, Quantum Threats, and CFTC's Perps

Unchained

Play Episode Listen Later Jun 4, 2026 62:24


Joe Lubin makes the bull case for Ethereum amid a sea of bearishness. The panel dissects Saylor selling Bitcoin for the first time in four years, the meaning behind 9 senior EF departures, Justin Drake's Q-Day call (50% by 2032), Manuel Araoz declaring all of DeFi unsafe, the ThorChain hack fallout, the Zama/Overnight Finance USDC freeze saga, and the CFTC greenlighting the first US perpetual futures product. Welcome to The Chopping Block — where crypto insiders Haseeb Qureshi, Tom Schmidt, Tarun Chitra, and Robert Leshner chop it up about the latest in crypto. This week Joe Lubin is stepping in to make the bull case for ETH on what he admits is a tough day to be bullish. We open on Strategy's first Bitcoin sale in four years and whether the STRC preferred stock structure is "an algorithmic stablecoin with too many steps," as Tarun puts it. Joe pivots to pitching Ether DATs, then we get into the Ethereum Foundation's brain drain -- nine researchers gone, CROPS as the new mandate, and a mysterious new developer organization taking shape behind the scenes. The episode's meatiest block covers DeFi security: Justin Drake warns Q-Day is 50% likely by 2032, Manuel Araoz says all of DeFi is unsafe, ThorChain's been offline for two weeks post-hack, and the panel debates whether we're entering a rough 12-24 months where attackers outrun defenders. We close on Hyperliquid's all-time highs and the CFTC opening the door to US perps.  Listen to the episode on Apple Podcasts, Spotify, Pods, Fountain, Podcast Addict, Pocket Casts, Amazon Music, or on your favorite podcast platform. Show highlights

Defense in Depth
Has Cybersecurity Become a Cult?

Defense in Depth

Play Episode Listen Later Jun 4, 2026 33:57


All links and images can be found on CISO Series We think of cybersecurity as a discipline. But when do ideas like best practices and NIST frameworks change into a system of belief? Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Davi Ottenheimer, principal, Flying Penguin. Joining is Joshua Copeland, director of security, Crescendo. In this episode: Tools, not religion The case for structured discipline The management problem underneath Fix the damn holes A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

tools cult cybersecurity fix ciso crescendo nist threatlocker david spark zero trust network access davi ottenheimer ciso series
Risky Business
Risky Business #840 -- Microsoft walks back researcher threats

Risky Business

Play Episode Listen Later Jun 3, 2026 66:03


On this week's show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week's cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution. They cover: Adversaries are tracking US troop locations with commercially available location data A new Signal phishing campaign is going after message backups 404 Media is suing ICE to get its spyware contract with REDLattice (lol) Microsoft's tone-deaf response to ‘never justifiable' zero-day disclosures Mini Shai-Hulud pops up again just as Glassworm gets shattered Much, much more This week's episode is sponsored by Authentik, an open source identity platform that you can host yourself. In this week's sponsor interview Authentik's CEO Fletcher Heisler joins Patrick Gray to talk about how they're keeping up with the bugpocalypse, and also the work they're doing to support identities for AI agents. This episode is also available on YouTube. Show notes The Pentagon Knew Enemies Could Track Troops' Phones for Years. Now They Are | wired.com U.S. says troops were targeted with location data, as senator warns ad industry is a ‘national security threat' | TechCrunch Security DOD location data attachment (Wyden) | Risky Business #830 -- LiteLLM and security scanner supply chains compromised | Risky Business Media US has seized nearly $1 billion in crypto from Iran, Bessent says | Russia claims foreign spy agencies hacked officials' phones | therecord.media Hackers are trying to steal Signal users' backups in new wave of phishing attacks | TechCrunch Security We Sued ICE to Get Its Spyware Contract. The Agency Is Redacting Essentially Everything | Social Signals Microsoft calls zero-day releases ‘never justifiable' as researcher threatens to drop more | therecord.media A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure | Social Signals Microsoft says it will not pursue security researchers after zero-day backlash | therecord.media IBM's new $5B initiative will help enterprises rapidly patch open-source vulnerabilities | Social Signals Federal audit reveals NIST's NVD is plagued by poor planning and duplication | cyberscoop.com Hackers Used Meta's AI Support Bot to Seize Instagram Accounts | krebsonsecurity.com Critical Windows Netlogon RCE flaw now exploited in attacks | BleepingComputer CISA adds exploited Palo Alto Networks GlobalProtect flaw to KEV | Cybersecurity Dive Password manager Dashlane says hackers stole some customers' password vaults | TechCrunch Security CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain | cyberscoop.com Botnet of more than 17 million devices dismantled | arstechnica.com Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans | therecord.media ACCC investigating Olympics ticket scam | ABC Dozens of Red Hat packages backdoored through its offical NPM channel | arstechnica.com Solo podcast: A deep dive on TeamPCP - Risky Business Media | Trump administration releases scaled-back AI executive order | cyberscoop.com Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket | cyberscoop.com

The CyberWire
The bugs are piling up faster than the fixes.

The CyberWire

Play Episode Listen Later Jun 2, 2026 30:23


A federal watchdog questions NIST over its vulnerability database backlog. Google patches an Android zero-day. Citizen Lab exposes a powerful location-tracking platform. Malware hides commands in Steam comments. Researchers spot AI-assisted malware development. Attackers compromise Red Hat's npm namespace. DriveSurge spreads malware through ClickFix and fake updates. FreePBX patches a critical flaw. And Dashlane responds to a brute-force attack. Our guest is ⁠Laure Lydon⁠, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on digital health platforms. Meta's AI support bot proves a bit too eager to help. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Maria Varmazis speaks with ⁠Laure Lydon⁠, Opening Chair for Infosecurity Europe and VP of Security and Infrastructure, Flo Health, sharing her expertise on privacy, security, and trust in digital health platforms, especially in sensitive areas like women's health. This interview is part of our partnership with Infosecurity Europe. Selected Reading Inspector general finds NIST mistakes have made vulnerability database ineffective (The Record) Google fixes one actively exploited Android zero-day, 124 flaws (Bleeping Computer) Uncovering Webloc: An Analysis of Penlink's Ad-based Geolocation Surveillance Tech (The Citizen Lab) GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure (Security Affairs) Threat Actor Uses AI to Build EDR Evasion Tools (Infosecurity Magazine) Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets (Infosecurity Magazine) Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks (Bleeping Computer) Critical Hard-Coded Credentials Vulnerability in FreePBX User Control Panel (Beyond Machines) Dashlane password manager users locked out by brute force attacks (Bleeping Computer) Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices