Podcasts about OAuth

Open standard for authorization

  • 355PODCASTS
  • 722EPISODES
  • 43mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 25, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about OAuth

Show all podcasts related to oauth

Latest podcast episodes about OAuth

Hacker Valley Studio
The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

Hacker Valley Studio

Play Episode Listen Later Aug 25, 2026 35:51


A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and Richard Penshorn, a senior security engineer at a top financial services company, to talk about the AI already living inside your business. Ron, Russell, and Richard dig into why shadow AI doesn't behave like shadow IT, how one forgotten grant became the door into a real world breach, and whether AI agents should ever get access to a corporate inbox. Underneath all of it is the one thing Russell and Richard keep coming back to: ownership. Give an AI agent access with no owner attached and it becomes invisible. Give every employee an approved, low-friction path to use AI and they stop wandering off it. Find out how you can  get ahead of the AI already running inside your walls. Impactful Moments 00:00 - Introduction 02:00 - Busting the "shadow AI is just shadow IT" myth 03:45 - Meet Russell Spitler and Richard Penshorn 05:50 - The surprising long tail of AI tool usage 07:00 - Entertainment vs. finance: build vs. buy culture 08:50 - How 30 OAuth grants became 88 in 2026 10:25 - Why manual OAuth audits became untenable 11:30 - The Canva example: what "click to connect" really grants 15:20 - Benign vs. malicious: how a stolen OAuth grant gets exploited 17:00 - Shadow IT vs. Shadow AI: what's actually different now 21:00 - Hot take: should AI agents ever touch corporate email? 25:10 - The three buckets of AI agent discovery 27:55 - Russell's best practices for locking down agents 31:00 - Fundamentals for the next 18 months: visibility and easy paths Links Connect with Russell Spitler on LinkedIn: https://www.linkedin.com/in/russell-spitler/  Connect with Richard Penshorn on LinkedIn: https://www.linkedin.com/in/richardpenshorn/  Learn more about Nudge Security: https://www.nudgesecurity.com/  –  Check out our upcoming events: https://www.hackervalley.com/livestreams   Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com   Become a sponsor of the show: https://hackervalley.com/work-with-us/

Security Conversations
Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure

Security Conversations

Play Episode Listen Later Aug 21, 2026 131:08


(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 110: We dig into Computer Weekly's scoop on the EncroChat hack and news that the French law enforcement implant was cobbled together from GitHub. Plus, Irregular, the $450M startup running sandboxes for OpenAI, Anthropic and Meta, drones over Romania's gas platforms, OpenAI's two-week training pause, and T-Mobile taking scissors to a cable during Salt Typhoon incident response. Stick around for a UFO segment that somehow involves Dr. Phil. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter; LabsCon speakers announced 9:06 A naval drone reaches the Neptun Deep gas platform 17:38 OpenAI pauses RL training: what "slowing the pace of scaling" costs 24:34 Guardrails vs refusals vs alignment. 33:54 Irregular, formerly Pattern Labs: $80M, $450M valuation, one job 46:11 JAGS on why security needs a new batch of startups right now 1:06:52 EncroChat revealed: a GitHub-sourced implant, IOCs 1:15:12 Law enforcement malware vs intelligence malware 1:21:07 T-Mobile, Salt Typhoon, and cutting the cable with a pair of scissors 1:32:06 Captive Crunch: hotel Wi-Fi, OAuth token theft, and the MSP supply chain 1:47:00 ICE RELIC, UNC6293, and the trouble with subcluster naming 2:00:39 UFO corner: David Grusch, Dr. Phil, and the Skywatcher Project 2:05:44 Shout outs, the Costin Challenge

ChannelBuzz.ca
Logging in, not breaking in: Blackpoint Cyber’s Wil Santiago on the 2026 threat landscape

ChannelBuzz.ca

Play Episode Listen Later Aug 13, 2026 30:07


Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

The Ravit Show
Why the Way You're Giving AI Agents Data Access Is Probably Wrong

The Ravit Show

Play Episode Listen Later Aug 10, 2026 10:41


Data + AI Summit by Databricks is in full swing!!!! Just finished talking with Steven Touw, CTO at Immuta, on The Ravit Show, about one of the problems nobody is talking about yet but everybody will be talking about in six months. The problem: an AI agent needs access to data inside your Databricks lakehouse. What do most enterprises do right now? They plug in the agent with a user's OAuth token. The agent inherits everything that user can access. Simple. Done.Here is what actually happens next: the agent now has a user's full permissions. If the agent gets compromised, your data does too. If the agent runs a query you did not intend, it looks like that user ran it. If you need to revoke access, you have to revoke the whole user. The audit trail tells you a person did the work when a machine did it.Steve calls this the authentication-authorization gap for agents. Everyone is solving for “can the agent prove who it is” and ignoring “can we control what it actually does.”The alternative is what he calls “on behalf of” access. The agent can act on behalf of a user but does not inherit their full permissions. It gets a scoped token. It can only touch the specific tables and columns it needs. It can only do the operations it was designed to do. If it breaks, the damage is bounded. The audit log is honest. Revocation is surgical.This is not an Immuta problem. This is a security architecture problem that every company building production agents needs to solve right now.Watch the full conversation in the video below. This is the kind of problem that separates the companies shipping agents safely from the ones that are going to have a very bad incident next year.#data #ai #access #security #databricks #api #immuta #theravitshow

Reimagining Cyber
CaptiveCrunch - The Evolution of Public WiFi Attacks - #213

Reimagining Cyber

Play Episode Listen Later Aug 5, 2026 21:59


Hotel Wi-Fi has long been considered a cybersecurity risk—but what if you're connected to the correct network? In this episode of Reimagining Cyber, Tyler Moffitt examines CaptiveCrunch, a sophisticated campaign that compromises legitimate hotel and conference Wi-Fi infrastructure to intercept users before they ever reach the internet.Discover how attackers manipulate DNS traffic, abuse device code authentication, bypass traditional phishing defenses, and deploy malware such as Cornflake and CocoShell to steal credentials, OAuth tokens, and corporate access. Tyler explains why familiar security signals—including genuine Wi-Fi networks, legitimate Microsoft login pages, and even multi-factor authentication—may no longer be enough to protect travellers.Whether you're a business traveller, security leader, or IT professional, this episode offers practical guidance on reducing risk, securing remote connections, and adapting to a new generation of identity-based attacks.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

The top AI news from the past week, every ThursdAI
This Week in AI: Open Weights, Frontier Models, Sandbox Escapes, Voice & AI Detection

The top AI news from the past week, every ThursdAI

Play Episode Listen Later Jul 31, 2026 108:17


Hey, it's Alex (yeah, I'm finally back from my vacation!) What a freaking week to come back to! Just after our last episode was published, Anthropic releases Opus 5, Jensen joins X and drops the “Open Weights & AI Leadership” open letter, Kimi K3 is released the following Monday beating expectations, and then the AI hack (OpenAI model breaking sandbox and infiltrating HuggingFace) is on everyone's mind, another Open Letter, this time from over 1K employees inside the frontier AI companies all talk about pacing the pace of frontier AI development. We played with Opus 5 and Kimi K3, and had the great pleasure to chat with friends of the pod Elie Bakouch (Prime Intellect) and Philip Kiely (BaseTen) about this important open weights release, then covered our general thoughts on Opus 5, and made order of all the different open letters that came out this week. Finally we chatted with Max from Pangram about the next version of AI writing detection (their biggest yet) and finished with Zuckerbergs (also on X! what's going on with everyone joining X) op-ed on the vision of personal superintelligence for everyone. Let's dive into this (as always, all the links and sources at the end, please don't forget to sub to our podcast on your favorite podcast app!) Open Weights AIKimi K3 the king of open weights - 2.8T chonker MoE near frontier model (X, HF, Blog, Tech report)This has got to be the biggest news of this week, and maybe the open weights AI news since GLM 5.2. MoonShot came back with Kimi K3, and we haven't seen any models quite this large in the open. Even Grok 4.5 is around 1.5T, this model is nearly 2x the size. Coming in at close to 3T parameters (and 2.5terabytes of weights at MXFP4 format), this model comes in very close to frontier! This was such an important release that I invited 2 friends of the pod, Elie Bakouch (prev HuggingFace, now Prime Intellect) and Philip Kiely (Author of Inference Engineering book, BaseTen) to dive deep into what makes this special! Elie's take, from reading the tech report, there's no single secret sauce, it's a combination of already available in the open techniques. Like KDA (Kimi Delta Attention) that has been out for a while, attention residuals, NVIDIA's latent MoEs. The highlight for Elie was the scaling work they did that reported a 2.5x scaling efficiency over Kimi K2.5 (2.5 performance at the same compute)! They also skipped RoPE entirely in favor of NoPE (the report calls it No Positional Encoding) for long context.Serving 1.4TB on eight GB300s (Baseten blog)Philip's team at Baseten was a day-zero provider (we're still working on bringing this model to CW Inference, stay tuned!) so I invited him to tell us behind the scenes of hosting this beast. Philip said that just loading the weights takes about 1.5TB!! of VRAM, and that's before the KV cache allocation + 1M token windows, so they're serving it on 8 GB300s where NVL72 . Baseten worked with the vLLM and SGLang teams on kernels and he also said they contributed patches back upstream! The model was trained with MXFP4, which, unlike Nvidia's own NVFP4 is a more standard format per Philip. I enjoyed his deep dive analysis into the differences, but because of this and because they trained the model with quantization awareness, it's “only” 1.5TB vs the would-be 5-6 TB if that this model in FP16 would demand. One of the more favorite nerd snipes moments, Philip pointed out that his colleague discovered that with over 99% of the usage being cached (think harnesses that send millions of the same cached tokens back and forth), tokenization actually starts to become a bottleneck. So they released a custom “basetenkenizer” that reduces the latency to serve the first token significantly! Great job!The harness in question is very importantOne important callout with 2 evidence pieces - the way you inference this model really matters. Kimi trained K3 with preserving thinking history, so when your harness uses it, it must send back the full thinking and tool use into the API to get the best next response. If your harness strips that out, you're not getting the most intelligence out of Kimi (shoutout to Niels from HF team for pointing this out). Additionally, the Composio folks, tested K3 on 3 harnesses, Kimi Code, Hermes and Claude Code. The difference in outcome was negligible, but the different in cost and number of tokens is definitely surprising! Claude Code (as a harness only) took 9x more Kimi tokens to get the same responses! This is also why Kimi Vendor Verified exists, their own held back benchmark of how well model providers serve Kimi across different quantization, tokenizer and KV cache settings. Benchmarks and the license! Ok let's start with the ugly... this isn't MIT, not remotely. This model is suspiciously served by all providers with exactly the same price (check OpenRouter) and requires inference companies to sign a contract with Kimi (I've no internal knowledge of this except that CW folks are working on it). Not something I particularly like, but hey... we're still advancing the frontier here! Speaking of frontier, this model approaches the frontier very closely. On DeepSWE, K3 sits just behind Fable 5 and GPT-5.6 Sol at 67%, beating GPT-5.5 & Opus 4.8. On Terminal-Bench 2.1 it takes second place behind GPT 5.6 Sol! It's 4th overall on Agentic Arena, with frontend design being genuinely good across the board - 1st on Design Arena

Definitely, Maybe Agile
Why AI Agents Need Room to Fail Before They Learn

Definitely, Maybe Agile

Play Episode Listen Later Jul 30, 2026 17:16 Transcription Available


Giving an AI agent real autonomy means accepting it will fail early and often before it gets good, the same curve organizations hit during any real change.Peter Maddison brings a stuck OAuth problem to the table: an AI agent that kept going in circles and couldn't find its way through. That leads into a conversation from Dave Sharrock's local AI meetup about an AlphaGo-style approach to AI agent autonomy: instead of specifying every step, you define hard constraints and let the model work out its own strategy inside them. Peter and Dave connect this to the Virginia Satir change curve, the same dip in performance that shows up when an organization tries a new way of working, and to the difference between using AI to optimize what you already do versus using it to rethink the business itself. They also get into how experiments like Andon Labs' AI-run cafes and vending machines use small dollar constraints to let a model learn from failure without real financial risk.This week's takeaways:- A well-articulated objective with clear guardrails lets an AI agent find its own path to a solution, even one you didn't expect or fully understand.- Real learning, whether it's an AI agent or an organization adopting a new way of working, comes with an unavoidable dip in performance that can't be planned away.- The bigger opportunity with AI isn't squeezing more efficiency out of an existing process, it's using AI to test entirely different ways a business could operate.Listen to the full episode at definitelymaybeagile.comSubscribe so you never miss an episode.Have a question or topic you'd like us to cover? Reach out at feedback@definitelymaybeagile.com

Identity At The Center
#437 - Identiverse 2026 - Pam Dingle

Identity At The Center

Play Episode Listen Later Jul 27, 2026 55:31


Live from the IDAC booth at Identiverse 2026, Jeff and Jim sit down with Pam Dingle, Director of Identity Standards at Microsoft, to unpack agentic identity. Pam breaks down assistive versus autonomous agents, walks through where standards like SPIFFE and OAuth hold up, and explains the difference between delegation, impersonation, and partition. The conversation also covers credential discovery risk, shared signals and revocation, what enterprises should prioritize now, and the value of hallway conversations at Identiverse.Connect with Pam: https://www.linkedin.com/in/pameladingle/OAuth Actor Profile for Delegation: https://www.ietf.org/archive/id/draft-mcguinness-oauth-actor-profile-00.htmlConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps:00:00 Intro and Identiverse 2026 vibes04:01 Defining agentic identity07:06 Has the earth really shifted11:38 An old problem thats been bejeweled15:13 From Nulli Secundus to Microsoft16:00 How standards are holding up19:27 Client ID metadata and just in time trust21:41 Shared signals and the revocation problem24:43 Deploying agentic identity at scale28:11 Registries at scale29:04 Delegation authorization and attenuation32:33 Delegation vs impersonation vs partition36:03 The one thing you can fix right now37:56 Favorite hallway conversation42:29 The solar system of hallway conversations45:51 Remembering Kim Cameron48:00 New voices to watch52:08 Wrap up and thank youKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Pam Dingle, Pamela Dingle, Microsoft, Identiverse 2026, agentic identity, agentic AI, non-human identity, delegation, impersonation, SPIFFE, OAuth, identity standards, IAM, digital identity, workload identity

Cyber Security Today
Hotel Wi-Fi Hijack, Six Years For A Snapchat Predator, Chicken on the hacking menu globally

Cyber Security Today

Play Episode Listen Later Jul 27, 2026 11:53


Hotel Wi‑Fi steals Microsoft 365 logins, ShinyHunters sextortion spam, and Chick‑fil‑A stuffed again Hotel and conference Wi‑Fi networks are being hijacked to harvest Microsoft 365 credentials by compromising captive portals and DNS, redirecting travelers to convincing lookalike logins and even abusing Microsoft's device code flow to obtain OAuth tokens in ways MFA may not stop. Plus, an Illinois man received 76 months in prison for phishing into hundreds of women's Snapchat accounts to steal explicit content and run a for-profit account access scheme. Also: a sextortion email wave impersonates ShinyHunters using real breach references while making fake device-compromise claims; ransomware disrupted Japanese frozen food supplier Nichirei shipments, affecting KFC franchises; and Chick-fil-A disclosed a June credential-stuffing incident impacting 13,322 loyalty accounts, resetting access, removing saved payments, restoring rewards, and adding free rewards as an apology. 00:00 Top Stories Intro 00:28 Hotel Wi-Fi Credential Trap 01:50 Public Wi-Fi Advice Debate 03:16 Snapchat Phishing Sentencing 05:18 ShinyHunters Sextortion Scam 07:09 Ransomware Hits Food Supply 09:16 Chick-fil-A Stuffing Fallout 11:12 Wrap Up and Sign Off

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 14, 2026 7:16


Someone Is Scanning for Your MCP Servers and AI Assistant Credentials https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150 Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a OAuth Client ID Spoofing https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 https://www.veeam.com/kb4869 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

GREY Journal Daily News Podcast
How Should SaaS Leaders Respond to OAuth Abuse?

GREY Journal Daily News Podcast

Play Episode Listen Later Jul 14, 2026 1:15


Microsoft warned that the hacking group ShinyHunters abused OAuth in SaaS environments to gain persistent access through malicious applications. The company described attacks that rely on user or administrator consent to grant high value permissions, allowing access to email, files, calendars, and directories without using passwords. Microsoft advised limiting who can register applications, requiring administrator approval for risky scopes, preferring publisher verified apps, and applying Conditional Access to consent flows. Detection steps include auditing Enterprise Applications, reviewing OAuth consent logs and token usage, and removing malicious service principals while revoking tokens. Founders should inventory third party integrations, enforce least privilege scopes through centralized approvals, and require security commitments from vendors. Training employees on consent prompts and running incident exercises help strengthen response and reduce business risk.Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.

The Identity Jedi Show
Why AI Agents Need a New Security Blueprint

The Identity Jedi Show

Play Episode Listen Later Jul 14, 2026 17:21


Your AI agents are doing things you didn't ask them to do. The question is: did you give them permission?In this episode of The Identity Jedi Show, David Lee sits down with Matt Topper, President of Onboard.ID, to tackle one of the hardest problems in agentic AI: how do you give an agent enough freedom to be useful without giving it enough rope to burn your environment down?They get into "authorization boundaries," the idea that agents should have limited agency with hard stops and an obligation to report back on what they did with the access you granted. Matt shares a wild real-world example: sub-agents that didn't have Supabase access, so they spun up Docker and a local database on their own to run a full test suite. Impressive? Absolutely. Terrifying without boundaries and audit trails? Also yes.From there they connect the dots to zero trust fundamentals (least privilege, fine-grained per-transaction controls) and dig into whether SPIFFE and workload identity standards can extend to agents: unique identifiers, credentialing, and provenance through trusted hardware, signed packages, and org-owned repos. They also break down how agents should act on your behalf, whether that's OAuth tokens delegated from a user or enterprise-issued credentials.Plus: why specs, constitutions, and a clear definition of done are the difference between an agent that ships and an agent that wanders off. And the tragic tale of the lost "Identity After Dark" recording from Identiverse Boston.In this episode:How authorization boundaries give agents agency without chaos | Why obligations and reporting are the missing piece of agent access | Mapping SPIFFE and workload identity to AI agents | OAuth, delegation, and enterprise tokens for agents | Spec-driven development: constitutions, scope, and definition of done | The real cost of agent tooling and where guardrails pay for themselvesChapters:00:00 Season Four Intro00:29 Authorization Boundaries02:14 Docker Surprise Demo04:13 Obligations and Zero Trust05:01 SPIFFE for Agents07:54 OAuth and Credentialing10:15 AI Native Building Specs11:22 Agent Constitution and Scope13:36 Tooling Costs and Guardrails14:51 Identity After Dark Story17:00 Wrap Up and FarewellConnect with Matt Topper:LinkedIn: https://www.linkedin.com/in/matttopper/Onboard.ID: https://onboard.id/Join the Identity Jedi community:Newsletter: www.theidentityjedi.com#IdentityJedi #AgenticAI #NonHumanIdentity #SPIFFE #ZeroTrust #IAM #AISecurity #Cybersecurity #WorkloadIdentity

Paul's Security Weekly
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467

Paul's Security Weekly

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-467

Enterprise Security Weekly (Audio)
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-467

Paul's Security Weekly TV
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - François Proulx, John Pritchard, Cassie Christensen, Jaime Lewis-Gross, Kim Brown - ESW #467

Paul's Security Weekly TV

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Show Notes: https://securityweekly.com/esw-467

Enterprise Security Weekly (Video)
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - François Proulx, John Pritchard, Cassie Christensen, Jaime Lewis-Gross, Kim Brown - ESW #467

Enterprise Security Weekly (Video)

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Show Notes: https://securityweekly.com/esw-467

Identity At The Center
#433 - Sponsor Spotlight - FusionAuth

Identity At The Center

Play Episode Listen Later Jul 8, 2026 55:50


Jim McDonald sits down with Dan Moore, Senior Director of CIAM Strategy and Identity Standards at FusionAuth, for an in-depth conversation on customer identity and access management. Dan explains how FusionAuth views authentication as the front door to any application and why control, deployment flexibility, and developer ownership are central to their approach. The discussion covers progressive registration, friction vs. usability, customization options, identity standards, the build vs. buy debate, risk-based MFA, and how AI agents will shape the future of customer identity. This episode and others is made possible with support from FusionAuth. Learn more at fusionauth.io/idac.Connect with Dan: https://www.linkedin.com/in/mooreds/Learn more about FusionAuth: https://fusionauth.io/idacBlog article mentioned: https://bobdahacker.com/blog/fifa-hackConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00:00 Introduction00:01:18 What is FusionAuth?00:03:15 Dan's identity origin story00:04:19 Developer focus and ethos00:06:54 Authentication as the front door00:10:00 Balancing friction and usability00:15:24 Customization in CIAM00:18:10 What sets FusionAuth apart00:20:33 FusionAuth's customer sweet spot00:25:48 Deployment flexibility and the control spectrum00:30:19 Common challenges in CIAM00:33:06 Build vs. buy for authentication00:36:00 Omni-channel authentication00:40:27 Why identity standards matter00:42:07 Risk-based MFA and intelligent challenges00:45:00 AI agents and the future of CIAM00:49:23 Closing thoughts00:51:35 Vacation roundupKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Moore, FusionAuth, CIAM, customer identity, authentication, access management, IAM, identity standards, MFA, risk-based authentication, progressive registration, OAuth, OIDC, SAML, AI agents, deployment flexibility, build vs buy, Sponsor Spotlight

Silicon Valley Tech And AI With Gary Fowler
The Org Chart Is the Runtime: AI Shifts to Multi-Agent Workflows with Ege Celik

Silicon Valley Tech And AI With Gary Fowler

Play Episode Listen Later Jul 8, 2026 27:44


Join Ege Celik, Co-Founder and CEO of Atlantic AI Inc., for an unvarnished examination of why the current enterprise fascination with text-based chatbots is fundamentally hitting a wall. While the initial wave of corporate AI focused on superficial text summaries and basic Q&A interfaces, it completely ignored the execution bottleneck: work doesn't get done by talking to a blank prompt; it gets done by executing multi-step workflows across an organization's tools, permissions, and reporting hierarchies. Drawing from an exceptional trajectory that spans launching a multi-city digital marketing agency at age 16, serving as an EdTech CMO at 17, and co-developing EEG-guided neurotechnology protocols, Ege is treating the company organization chart not as a static visual graphic, but as the active software runtime layer for enterprise AI. In this episode—following Atlantic AI's recent $5M seed valuation—we explore how the team is shifting the paradigm from generalized copilots to dedicated, role-specific autonomous agents that execute workflows end-to-end.

Cloud Security Podcast
Who Governs Your AI Agents? Identity, Offboarding & Open Standards

Cloud Security Podcast

Play Episode Listen Later Jul 2, 2026 34:42


Are overprivileged AI agents the biggest emerging threat in cybersecurity? In a recent high-profile attack, a vibe-coding company had its entire source code stolen because an attacker exploited a long-lived, overprivileged token tied to a third-party AI agent.In this episode, Ashish sits down with Ely Kahn, CPO at Okta, to unpack the challenge of managing Non-Human Identities (NHI) in the AI era. Ely explains why traditional, static human permissions completely break down when applied to autonomous agents. To solve this, Okta has spearheaded Cross-App Access (XAA), an extension of OAuth that uses an Identity Assertion Grant (ID JAG). This open protocol, backed by 25+ partners, including Anthropic, XAA securely passes the baton between apps without annoying consent pop-ups or dangerous static API keys.We also explore the four maturity levels of agent authorization, ranging from broad API keys to the ultimate "North Star" of intent-based security. Learn the difference between SPIFFE (for internal cryptographic identity) and XAA (for downstream resource authorization), how the Linux Foundation is building an Agent Domain System, and why every CISO needs an immediate "kill switch" for rogue AI agents.Guest Socials -⁠⁠ ⁠⁠⁠⁠⁠Ely's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Security, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Security Podcast⁠Questions asked:(00:00) Introduction(02:50) Ely Kahn's Background: From DHS to Okta CPO(04:00) Why AI Agent Identity is Different from Human IAM(06:30) The Danger of Overprivileged Tokens: A Source Code Breach Case Study(08:30) Introducing Cross-App Access (XAA) and ID JAG(11:00) Agent Identities: Acting on Behalf of a User vs. Autonomous Scopes(13:00) SPIFFE vs. XAA: Workload Identity vs. Resource Authorization(14:30) The Linux Foundation's Agent Domain System for Cross-Company Passports(18:00) Assuming Breach: Why Prompt Injection Makes Identity the Highest ROI Security Action(19:30) The 4 Maturity Levels of AI Agent Authorization(21:00) Intent-Based Security and Zero Standing Privilege(23:00) How to Offboard AI Agents and Manage Identity Governance (IGA)(27:00) The 3 Governance Questions Every CISO Must Answer(28:50) Implementing a Universal Kill Switch for Rogue AgentsResources spoken about during the episode:Learn more about how Okta and XAA are setting the new security standard for the AI era

Reimagining Cyber
What Defenders Are Still Getting Wrong About Identity - #208

Reimagining Cyber

Play Episode Listen Later Jul 1, 2026 15:26


For years, cybersecurity assumed attackers had to break into organizations.Today, they increasingly just log in.Valid credentials, stolen browser sessions, OAuth tokens, help desk social engineering,and underground marketplaces have fundamentally changed how attacks unfold.So why are organizations still thinking about identity the same way they did five years ago?In this episode, Tyler Moffitt discusses the biggest misconceptions around identitysecurity, why trust has become a commodity, and why cyber resilience requires more than prevention alone.Relevant links:'What defenders are still getting wrong' webcast series with Tyler Moffitthttps://www.brighttalk.com/webcast/8241/646699?utm_source=LinkedIn&utm_medium=brighttalk&utm_campaign=646699As featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

Security Conversations
US Gov Takes the Wheel: Who Gets to Use the Best AI?

Security Conversations

Play Episode Listen Later Jun 29, 2026 113:54


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 103: We dive into the U.S. government's takeover of frontier-model rollouts (Mythos, Fable, and OpenAI's Sol/Terra/Luna) and what it means when intelligence gets commoditized but access gets rationed. Plus, Costin's all-Chinese open-weight stack, the economics of burning tokens, a fresh Salesforce OAuth breach, and jellyfish UFOs over Iran. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 — Introductory banter, Thinkst Canary sponsorship 2:55 — Why threat intel analysts are built for the AI moment 11:09 — Government takes the wheel: Mythos, Fable & the frontier labs 16:15 — Did the government go too far/not far enough? 25:42 — Anthropic's "best PR campaign in history" 31:52 — Alibaba, distillation & the model-router cartel 40:58 — Costin's stack: Chinese open-weight models & token economics 46:12 — Dumping, evals & the real work of AI engineering 1:04:32 — Soft power: how the world gets pushed toward China 1:14:43 — "The bullshit": over-refusal & the Opus 4.8 regression 1:32:03 — The trillion-dollar IPO endgame 1:35:49 — The Klue OAuth breach and secure-by-default 1:45:32 — Shout-outs: UAP jellyfish, LABScon 2026

CISSP Cyber Training Podcast - CISSP Training Program
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 29, 2026 43:08 Transcription Available


Send us Fan MailA vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That's the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident.We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it's not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician.Then we go deeper on two concepts that keep showing up in both real breaches and exam questions. First, SBOM (Software Bill of Materials), the “nutrition label” that tells you exactly what's inside your software so you can respond fast when a new CVE hits. Second, OAuth token governance, where long-lived or overly broad tokens can become silent master keys if you do not scope, expire, inventory, revoke, and monitor them properly. We finish with three practice questions and the reasoning behind the best answers and the common distractors.If this helps, subscribe so you do not miss the next training, share the episode with a CISSP study partner, and leave a review to help more security pros find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

MLOps.community
The Dark Side of MCP Servers

MLOps.community

Play Episode Listen Later Jun 23, 2026 69:59


Sam Partee (CTO & co-founder of Arcade.dev) and Nate Barbettini (Founding Engineer at Arcade.dev) sit down at the MCP Dev Summit to unpack what nobody wants to admit about the Model Context Protocol: the security model is still full of sharp edges. From tool poisoning and prompt injection to why OAuth got bolted onto the spec, this is a builder 's-eye view of where MCP breaks — and how to ship agents safely anyway.What we get into:

Cyber Security Today
Stolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake Cyberstalking

Cyber Security Today

Play Episode Listen Later Jun 22, 2026 10:03


A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration credential involved, and engaged CrowdStrike as Icarus threatens extortion, echoing earlier Salesforce token-theft campaigns affecting nearly 1,000 companies.  Researchers also detail AriStinger, a new botnet infecting 4,000+ end-of-life D-Link routers to scan, proxy, tunnel, execute commands, and hijack DNS, with many infections in South Korea and China. The episode covers federal cyberstalking charges against Anthony Belford for allegedly using fake accounts and AI-generated nude images, and ESET's report that the "Gentleman" ransomware crew is developing modular EDR-killing tools to disable endpoint defenses. 00:00 Top Stories Teaser 00:29 Clue OAuth Token Breach 02:32 Salesforce Token Attack Trend 04:14 AryStinger Router Botnet 05:33 AI Deepfake Cyberstalking Case 07:50 Gentleman EDR Killer Arsenal 09:37 Wrap Up And Sign Off

Cyber Security Headlines
Police clean WordPress sites, Klue OAuth breach, Warner's CISA warnings

Cyber Security Headlines

Play Episode Listen Later Jun 19, 2026 9:28


Police clean ups SocGholish-infected sites tied to Evil Corp Klue OAuth breach linked to Icarus Salesforce data theft attacks Warner warns of CISA cuts, staffing gaps in letter to acting chief  Get the show notes here: https://cisoseries.com/cybersecurity-news-police-clean-wordpress-sites-klue-oauth-breach-warners-cisa-warnings/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.  

Talking Drupal
Talking Drupal #557 - Test-Driven Drupal eBook

Talking Drupal

Play Episode Listen Later Jun 15, 2026 54:57


Today we are talking about Test Driven Development, ebooks, and Drupal with guest Oliver Davies. We'll also cover Juicer Social Feed as our module of the week. For show notes visit: https://www.talkingDrupal.com/557 Topics What Is Test Driven Drupal Why Automated Tests Matter How TDD Works AI and Test Quality Balancing Test Coverage When to Write Tests Why Write the Book Why Write an Ebook From Email Course to Ebook Ebook vs Print Tradeoffs Who the Book Helps What You Will Learn Keeping Content Updated Publishing Tools Workflow Lessons and Drupal Changes Podcast and Future Books Mob Programming Explained Free Ebook and Wrap Up Resources Juicer io Drupal 11: The Upgrade Experience I've Been Waiting For codethatships Test-Driven Drupal Sculpin Guests Oliver Davies - oliverdavies.uk opdavies Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Scott Falconer - managing-ai.com scott-falconer MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted to embed social feeds into your Drupal website? There's a module for that. Module name/project name: Juicer Social Feed Brief history How old: created in Mar 2026 by Denis Omerović (drupalchille) Versions available: 1.0.2, that works with Drupal 10.3 or 11 Maintainership Actively maintained (version released today!) No open issues Usage stats: 4 sites Module features and usage This module embeds an aggregated social media feed from Juicer.io directly into Drupal as a configurable block. It natively supports content from Instagram, LinkedIn, Facebook, X (Twitter), TikTok, Bluesky, YouTube, and more. Traditionally, displaying feeds from platforms like Facebook, X, or Instagram requires creating developer accounts, managing rotating OAuth tokens, and keeping up with constantly shifting API restrictions. Juicer handles all API authentication on its platform, shielding your website from sudden breaking changes by individual social networks. To use this module, you will need an active account on Juicer.io. They offer both free and paid tiers depending on how many sources you want to aggregate and how frequently you need the feed to sync. The module is created and maintained by the official Juicer.io team. That should ensure that the module is closely aligned with the product's features and any potential API changes over time. The embedded feed is made available as a Drupal block, to make it easy to control where it should appear on your site. When placing the Juicer block, the UI exposes several user-friendly settings: Feed Slug: Just paste your unique Juicer feed ID to establish the connection. Post Limit: Control exactly how many items populate initially. Source Filtering: If your Juicer account aggregates five networks, but you only want to show LinkedIn posts on a specific page, you can filter down to a single network right inside the block settings. SEO/Semantic Control: You can set titles/subtitles and choose the exact heading level hierarchy ( through ) to ensure your pages remain semantically correct and accessible. I did get a chance to test out the module and the service today, and I can tell you from experience, it's a huge improvement on having to create and pull in feeds directly. I did notice that the block didn't show up in the Drupal Canvas component library, but I was able to determine that two lines of code to declare the block as FullyValidatable were all that was needed. So I opened a Feature Request to add that, and it was merged in and a new release cut in less than an hour. So it's now Drupal Canvas compatible too! It's worth pointing out that the standard Juicer's embed script loads HTMX, which conflicts with the version of HTMX included in Drupal 11 core. As a result, the module fetches feed HTML directly from the Juicer API and includes a minimal HTMX shim to prevent errors. John, you nominated this module, why don't you start us off by telling us about how you got started using it?

Hybrid Identity Protection Podcast
Agentic AI and the Authorization Gap No One Closed with Geoffrey Mattson, CEO of SecureAuth

Hybrid Identity Protection Podcast

Play Episode Listen Later Jun 9, 2026 34:43


This episode features Geoffrey Mattson, CEO of SecureAuth, joined by co-host Sarah Cicchetti, Director of Product Management at Semperis.Geoffrey has spent decades building and leading companies at the intersection of AI and cybersecurity, including MistNet.ai, an AI-native threat detection platform acquired by LogRhythm, and Xage Security, where he drove zero trust adoption across the U.S. military, global energy firms, and Fortune 500 enterprises. At SecureAuth, he leads a platform built around continuous, real-time identity authority across workforces, APIs, and AI agents.In this episode, Geoffrey argues that agents combine the speed of automation with the unpredictability of humans, making real-time per-action authorization the only viable control model. He discusses why “friendly fire” from well-meaning employees is the biggest threat vector right now, how MCP vendors are ignoring their own OAuth spec, and what a practical agent rollout with real guardrails actually looks like.This episode reframes authorization as the problem the identity industry has been deferring for years and can no longer avoid.Guest Bio Geoffrey Mattson is a serial entrepreneur and globally recognized cybersecurity and AI executive with decades of experience building market-defining companies and technologies that protect the world's most critical systems.He is currently CEO of SecureAuth, a leader in AI-driven identity and access management with its Continuous Authority, ensuring ongoing verification across workforces, customers, APIs, and AI agents. This is enabled through its Private Authority Platform, which puts authentication and authorization under your control through any deployment model (cloud, on prem, hybrid, air-gapped).Prior to SecureAuth, Mattson served as CEO of Xage Security, where he led the company in Zero Trust for critical environments from energy to agentic AI. Under his leadership, Xage achieved rapid adoption across the U.S. military, global energy firms, and Fortune 500 enterprises.Previously, Geoffrey Mattson was co-founder and CEO of MistNet.ai, an AI-native threat detection platform acquired by LogRhythm. He pioneered decentralized analytics and machine learning approaches for real-time cyber defense, and later served as SVP of Product at LogRhythm, driving global expansion and shaping the next generation of SIEM/SOAR solutions.Earlier, he held senior executive roles at Juniper Networks, overseeing a $2B product portfolio and leading major M&A efforts, and at Huawei Technologies as SVP and CTO for networking and data center platforms. His engineering leadership at Corona Networks, Caspian, and Bay Networks helped build foundational technologies in network and security architecture.Guest Quote “With agents, you have the power and the speed of an automated process with the unpredictability of a human. And in fact, we are seeing their behavior and their psychology makes them even perhaps less predictable than a human.”Time stamps 01:45 Meet Geoffrey Mattson: Serial Entrepreneur and Cybersecurity Executive 02:40 Why Identity Is Having a Moment 08:40 Defining Agent Identity 12:15 Behavioral Guardrails for Agents 14:37 Agent Identity Lifecycle 17:36 Just-in-Time vs. Standing Privilege 18:02 C-Suite Pressure and Friendly Fires 21:00 When Agents Live Off the Land 26:12 MCP, OAuth, and Token Pitfalls 28:04 Threat Models and Rollout Strategy 30:13 LLMs and Policy Authoring 31:23 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Geoffrey on LinkedInConnect with Sarah on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, June 5th, 2026: Coreutils for Windows; Cisco Unified Comm Manager Fix and Exploit; OAuth Orphans

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 5, 2026 6:12


Microsoft's Coreutils for Windows https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048 Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW Firmware Update for Acer Connect W6x Router https://community.acer.com/en/kb/articles/19672 OAuth marketplace apps keep access after publishers vanish https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

CISSP Cyber Training Podcast - CISSP Training Program
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 4, 2026 24:26 Transcription Available


Send us Fan MailThe breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach private repository files and ultimately an NPM token that could enable a supply chain attack.From there, we zoom out to the bigger cloud security problem: non-human identities. Service accounts, API keys, and OAuth tokens multiply fast, and they are frequently overprivileged, poorly tracked, and left active long after an integration is retired. We also talk about why SaaS-to-SaaS connections are so hard to secure, and why agentic AI makes visibility even more urgent. If you do not know what systems are connected, what data crosses those links, and who owns the risk, you are effectively trusting an invisible tunnel into your environment.To make this actionable, we lay out a four-phase third-party risk management (TPRM) framework you can apply immediately: build a vendor and integration inventory with tiering, run real due diligence (SOC 2 Type II, ISO 27001, data access scope, subprocessors and fourth parties), lock protections into contracts (DPA language, right to audit, breach notification expectations), then enforce ongoing monitoring and governance with quarterly token reviews, logging, and incident response playbooks. If you are studying for the CISSP, you will also see exactly how this maps to Domain 1, Domain 3, Domain 4, and Domain 5.Subscribe for more practical CISSP training, share this with a teammate who owns vendor approvals, and leave a review so more security pros can find it. What is the one integration you would audit first?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Business of Tech
Vendor Outcomes, Warranties, and the Shift from Risk Manager to Delivery Arm for MSPs

Business of Tech

Play Episode Listen Later Jun 3, 2026 13:03


Outcome-based managed security and attached vendor warranties are driving a new form of coverage-based vendor lock-in for MSPs and IT service providers. Vendors such as Intezer and SPECTRA are introducing performance guarantees, SLAs, and cyber resilience warranties that require MSPs to fully standardize on their architectures. This evolving model shifts accountability for enforcement and risk management from the individual MSP to the vendor's operating model, thereby altering the independent role of the MSP within client environments. A notable example is Intezer's Amplify Partner program, which asserts that its platform can process 100% of security alerts while escalating fewer than 2% for human review—claims the company frames as outcomes rather than product specifications. SPECTRA's use of certification-linked warranties, distributed via Ingram Micro, establishes channel-distributable assurance products with explicit conditions attached at every level. According to a Check Point report, while 77% of organizations report having adopted AI for cloud security, only 26% feel capable of enforcing those strategies, revealing a gap between security intent and operational ability. This structural shift is further illustrated by Merlin Cyber's FedRAMP managed service offering, Lumen's MDR enhancements targeting mid-market MSPs, and Trustlogix's addition of intent-based authorization controls. The FBI's announcement regarding Microsoft 365 OAuth token hijacking and recent vulnerabilities in widely used platforms like ConnectWise Automate underscore the real-world risks of automation platforms being targeted. These developments collectively point to growing operational complexity, rising compliance burdens, and the need for MSPs to separate their commitments from upstream vendor claims. For operators, the trend demands increased scrutiny of warranty terms, claim denial conditions, and SLA language before making any client-facing assurances. MSPs risk absorbing liability if they repeat vendor marketing claims without contractual clarity or operational control. Effective governance now requires independently produced, audit-ready evidence that documents compliance and enforcement separate from vendor portals. As assurance sales proliferate, the operational gap between acting as an underwriter versus a reseller will drive market differentiation, affecting both pricing structures and eligibility for vendor-backed coverage. 00:00 Channel-Ready Security 03:41 Policy vs. Reality 05:59 MFA Isn't Enough 09:12 Why Do We Care?    Supported by:  ScalePad Moovila   

alphalist.CTO Podcast - For CTOs and Technical Leaders
#138 From Hacker News to W3C: How One Amazon Engineer Accidentally Shaped the Future of AI Browsers // Alex Nahas, MCP-B

alphalist.CTO Podcast - For CTOs and Technical Leaders

Play Episode Listen Later May 21, 2026 41:12


Alex Nahas is 28 years old and has already initiated a W3C web standard. Working as a backend engineer at Amazon, he ran into a problem most enterprises face: MCP requires OAuth, but most enterprise infrastructure runs on SAML. His solution was elegant: run the MCP server in client-side JavaScript, letting AI agents use the browser's existing authentication context rather than rebuilding auth from scratch. What started as an internal tool became an open source project, then a viral Hacker News post published while under anesthesia, and ultimately an invitation from Google and Microsoft to help shape WebMCP as an official web standard. In this episode, Alex and Tobi explore what WebMCP actually is, why the browser is the most underestimated sandbox in AI development, and what the agentic web might look like two years from now. Topics covered: What MCP actually is and why it's just an RPC framework at its core Why OAuth is a dealbreaker for most enterprise infrastructure How WebMCP lets AI agents operate within existing browser authentication The Hacker News post that started it all, and why Alex doesn't remember posting it How Chrome is natively building WebMCP support The chicken-and-egg problem of standard adoption Real-time bidding for agents and what it means for digital advertising Why agents don't need their own identity Where the agentic web is headed in the next two years

Identity At The Center
#422 - Decoded - Securing AI Agents with Standards You Already Have

Identity At The Center

Play Episode Listen Later May 15, 2026 78:17


Episode 422 is the debut of Decoded by Identity at the Center, a new sub-series hosted by Jeff Steadman and Sean O'Dell dedicated to unpacking the specifications and standards powering IAM. Joining them is Pieter Kasselman, VP of Open Standards at Defakto and chair of the WIMSE working group. The conversation covers why traditional non-human identity approaches break at agentic scale, how SPIFFE and SPIRE enable short-lived automated credential provisioning without long-lived secrets, and why treating agents as workloads unlocks a decade of existing standards. Pieter walks through critical OAuth specs including JWT authorization grant, token exchange, client ID metadata, and the emerging transaction tokens draft. Sean connects these to practical gateway architecture, continuous access evaluation, and policy-based authorization. The episode closes with real-world deployment examples and a clear takeaway: the tools to secure agentic identity are available today.Episode Links:Pieter Kasselman: https://www.linkedin.com/in/pieter-kasselman-0259862/AI Agent Authentication and Authorization: https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/Workload Identity in Multi-system environments (WIMSE): https://ietf-wg-wimse.github.io/OAuth SPIFFE Client Authentication: https://datatracker.ietf.org/doc/draft-ietf-oauth-spiffe-client-auth/Transaction Tokens: https://datatracker.ietf.org/doc/draft-ietf-oauth-transaction-tokens/08/Agentic Identity Control Framework. You Already Have the Pieces. Now Build It. by Sean O'Dell: https://www.linkedin.com/pulse/agentic-identity-control-framework-you-already-have-pieces-o-dell-61b5e/Timestamps:00:00 Introduction to Decoded by Identity at the Center00:13 The mission of the Decoded sub-series03:02 Guest intro: Pieter Kasselman, VP of Open Standards at Defakto06:21 Why agentic identity is urgent: scale, multi-platform, and shifting threat landscape10:42 The real cost of API keys and credential sprawl in agentic systems13:23 Agentic identity identifiers and how SPIFFE assigns unique workload IDs21:00 Credential types: X.509, JWTs, and workload identity tokens31:00 Connecting SPIFFE to OAuth and dynamic registration with client ID metadata38:18 SPIFFE SVIDs, multiple credentials per agent, and governance traceability41:44 Authentication versus authorization: delegation versus impersonation47:00 Transaction tokens: binding access to specific transactions to stop token theft51:21 Identity chaining and cross-domain authorization55:00 Shared Signals Framework and dynamic authorization57:00 Gateways, CAEP, and mid-flight token revocation for rogue agents59:31 What you can deploy today with SPIFFE, OAuth, and existing IDPs01:02:58 Policy-based access control and why instance-level governance cannot scale01:04:58 Workload identity federation: Anthropic and Google Agent ID updates01:07:13 Cross-platform federation and the law of agentic utility01:11:55 Elevator pitch: agents are workloads and 95% of the problem is solved now01:17:03 What is coming next: a transaction tokens deep diveKeywords:agentic identity, SPIFFE, SPIRE, OAuth, transaction tokens, Shared Signals Framework, WIMSE, workload identity, non-human identity, authorization delegation, JWT, CAEP, API gateway, IAM standards, AIMS, Jeff Steadman, Sean O'Dell, Pieter Kasselman, IDAC, Identity at the Center, Jim McDonald, Decoded by Identity at the CenterDecoded by Identity at the Center:Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Sean O'Dell: https://www.linkedin.com/in/seanodentity/Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Visit the show on the web at https://idacdecoded.com/

Resilient Cyber
Identity as Infrastructure in the Agentic Era

Resilient Cyber

Play Episode Listen Later May 13, 2026 33:30


In this episode of Resilient Cyber, I sat down with Karl McGuinness — author of Control Plane and one of the sharpest voices working on identity in the agentic era — to unpack what most of the industry is still getting wrong about IAM for AI agents.Karl's thesis is a provocation: we spent two decades optimizing authentication and authorization, and we built that stack for human-paced execution. Agents remove the presence, pacing, and natural scope-limiting that made those controls work — and no amount of stronger credentials, tighter scopes, or faster JIT provisioning closes the structural gap. The real frontier isn't AuthN or AuthZ. It's delegation: how approved intent becomes bounded authority that stays governed across delegation chains, unfamiliar tools, consent expansion, revocation, and task termination.Chris and Karl dig into:↳ Why the industry optimized for the wrong question, and what changes when agents enter the loop ↳ The Execution Mandate — agents don't need your passport, they need your authority ↳ Why governing the stay matters more than governing the entry, and what continuous evaluation of authority looks like in practice ↳ Mission-Bound OAuth, including Karl's own pessimistic case against it ↳ AAuth vs. OAuth as the substrate for agentic identity, and what signal will tell us which one wins ↳ Why Mission Shaping is necessary but not sufficient when quiet expansion, headless execution, and stale state are in play ↳ Open-world OAuth, MCP, and first-contact trust — what the newer standards solve and the substrate gaps no draft is closing ↳ ID-JAG and Cross-App Access (XAA): why enterprise SaaS needs to abandon app-by-app OAuth islands ↳ The widening gap between IETF drafts and the "agentic IAM" being sold at RSA, and the minimum viable posture for teams running agents in production todayWhether you're a CISO, an identity architect, or a security leader trying to separate vendor narrative from substrate reality, this is a clear-eyed map of where agentic IAM actually is and where it has to go.

Cloud Security Today
Identity for AI agents

Cloud Security Today

Play Episode Listen Later May 10, 2026 45:37


AI agents are moving from answering questions to taking action. That changes everything for identity and access management.In this episode, Ken Huang joins Matt to break down why traditional IAM was not built for agentic AI, where service accounts and OAuth scopes fall short, and what CISOs should do now to govern agents before they hit production at scale.Episode LinksKen's substackKen's paper from 2011 on AI (he was way ahead!)NIST AI RMF

North Meets South Web Podcast
Unused APIs, Passport testing traps, and local AI bottlenecks

North Meets South Web Podcast

Play Episode Listen Later May 7, 2026 36:17


In this episode, Michael shares details from a major internal platform shift at work, including the decision to completely remove an underused public JSON API and rebuild integrations around real customer needs instead of hypothetical use cases. The conversation dives deep into Laravel Passport, Sanctum, OAuth flows, request authorisation, and some tricky edge cases around testing authenticated APIs.Jake then broadens the conversation into AI infrastructure, local model hosting, security implications of autonomous AI systems, NVIDIA hardware demand, and the future potential of photonic processors as a solution to the growing power and cooling bottlenecks facing AI workloads.Show linksLaravel PassportLaravel SanctumLaravel Passport actingAs testing helpersPHP enumsPHPStanLarastanZapierClaudeNVIDIA DGX systemsPhotonic processors

Business of Tech
Shadow AI Shifts MSP Role: From AI Access to Proving Control and Recovery

Business of Tech

Play Episode Listen Later May 6, 2026 12:51


The episode identifies a structural shift in how AI adoption is being managed within IT environments: control and accountability are now central concerns, overtaking simple discussions of AI usage or feature deployment. Shadow AI—unmanaged or improperly governed AI agents—has emerged as a tangible risk vector. Government entities, such as the White House, and technology vendors including Microsoft, Cisco, and OpenAI are framing AI not only as a productivity tool but increasingly as a source of operational and security liabilities that demand more robust oversight. A key example comes from an incident reported by TechRepublic in which an AI agent within a coding workflow deleted both a production database and its backups, resulting in a prolonged, business-impacting recovery from a three-month-old backup. In parallel, the Hacker News highlighted findings from scans of one million exposed AI services, characterizing the market's current AI security posture as lacking, with many endpoints widely reachable unintentionally. Microsoft's public transition of Agent365 from preview to release was directly tied to fears over the risks associated with shadow AI, indicating industry recognition of autonomous agents as a new attack surface requiring governance. Supporting developments further validate this trend. Cisco's open sourcing of AI Bill of Materials (BOMs) tools, Wiz's tracking of non-human identities tied to AI workloads, and OpenAI's rollout of advanced account security all signal a growing industry emphasis on making AI deployments auditable and restrictable. Practices such as phishing-resistant authentication—driven by token theft campaigns analyzed by Microsoft—and continuous permission monitoring, as advocated by Material Security, are now increasingly viewed as necessary safeguards rather than optional enhancements. Providers like Enforcer and products such as Copilot Manager are explicitly focused on surfacing shadow AI usage and enforcing credential discipline, underlining the growing demand for proof-of-controls. MSPs and IT service providers now face greater operational complexity and contract risk tied to AI automation. Client expectations are shifting from baseline AI access to demonstrable governance—requiring non-human identity inventories, documented permission boundaries, and validated recovery frameworks for AI-powered workflows. Token harvesting and persistent OAuth grants increase the likelihood that MSPs will be held responsible not just for prevention, but for rapid containment, rollback, and producing evidence during security incidents. Failure to meet tightened SLAs around backup immutability, authentication protections, and agent visibility could soon become a material contract exposure. 00:00 Agents Gone Rogue 03:50 Govern the Agent 06:24 MSP at Risk 09:54 Why Do We Care?  Supported by:  CometBackup ScalePad  Upcoming event:  The Pivotal Point of IT: Building Services for the AI-First Era Date: May 13 at 1p.m. EDT Register: https://go.acronis.com/davesobelaiera

Segurança Legal
#416 – Saber sem conhecer

Segurança Legal

Play Episode Listen Later Apr 30, 2026 43:03


Neste episódio comentamos sobre os desafios e as soluções técnicas para a aferição de idade na internet, um tema que ganhou forte destaque com as novas regras do ECA Digital. Você irá descobrir como funcionam os protocolos de conhecimento zero, também conhecidos como Zero-Knowledge Protocol ou ZKP, e de que forma eles permitem comprovar a maioridade de um usuário sem expor dados pessoais sensíveis. Você entenderá a diferença entre ferramentas invasivas, como a biometria facial, e métodos técnicos que respeitam a privacidade e a proteção de dados, utilizando criptografia aplicada e padrões internacionais de segurança da informação. Além disso, você vai aprender sobre os impactos práticos da regulamentação da ANPD no controle de acesso a conteúdos restritos e como evitar o rastreamento excessivo por grandes empresas de tecnologia. O debate também aborda táticas de engenharia social, destacando uma série educativa sobre phishing baseada na psicologia da fraude, que é um conhecimento essencial para evitar golpes online e vazamento de dados. Ao longo da discussão, você verá que é possível equilibrar a proteção no ambiente digital com a garantia da intimidade, sem adotar modelos de vigilância em massa durante a autenticação de sistemas. Para não perder nenhuma discussão sobre tecnologia, direito e sociedade, assine o podcast na sua plataforma de áudio favorita e siga nossos perfis no YouTube, Mastodon, Blue Sky, Instagram e TikTok. Aproveite para avaliar o programa e compartilhar o conteúdo com outras pessoas interessadas no assunto. Você também pode apoiar o projeto acessando a plataforma de financiamento coletivo indicada no áudio ou enviando suas dúvidas e sugestões diretamente para o nosso e-mail oficial. Esta descrição foi realizada a partir do áudio do podcast com o uso de IA, com revisão humana  Visite nossa campanha de financiamento coletivo e nos apoie!  Conheça o Blog da BrownPipe Consultoria e se inscreva no nosso mailing ShowNotes The Psychology of Fraud, Persuasion and Scam Techniques LEI Nº 15.211, DE 17 DE SETEMBRO DE 2025 – Dispõe sobre a proteção de crianças e adolescentes em ambientes digitais (Estatuto Digital da Criança e do Adolescente) DECRETO Nº 12.880, DE 18 DE MARÇO DE 2026 – Regulamenta a Lei nº 15.211, de 17 de setembro de 2025, que dispõe sobre a proteção de crianças e adolescentes em ambientes digitais, e institui a Política Nacional de Promoção e Proteção dos Direitos da Criança e do Adolescente no Ambiente Digital. Mecanismos confiáveis de aferição de idade – ORIENTAÇÕES PRELIMINARES Radar tecnológico – Mecanismos de aferição de idade

Where It Happens
How to win with AI Agents in 2026

Where It Happens

Play Episode Listen Later Apr 29, 2026 86:54


Limited BONUS: First 1,000 builders get $1,000. Claim yours while supplies lasts.: https://startup-ideas-pod.link/hyperagent I sit down with Howie Liu, co-founder and CEO of Airtable, to talk about the agent economy and the launch of HyperAgent. We walk through Sequoia's charts on AI agent deployment, the economics of token-based work versus human labor, and why frontier agents have crossed a threshold that changes how companies get built. Howie then does a live show-and-tell of HyperAgent, including a custom "Greg Isenberg contrarian AI" skill he spins up in real time. This one is for anyone building a solopreneur business, operating a fleet of agents, or trying to figure out where to place their bet in the agent ecosystem Timestamps 00:00 – Intro 02:22 – Sequoia's AI agent deployment chart reaction 04:41 – Copilot vs Autopilot territory and the $1T+ opportunity 08:13 – Agent economics vs human labor costs 11:12 – Fastest enterprise adoption curve in history 14:48 – The agent command center and fleet of 20 agents 18:03 – What is HyperAgent? 19:43 – Live demo: hyperlocal real estate market reports 22:38 – HyperAgent as the founder, not just the developer 23:21 – Street View, Zillow redesigns, and visual tool power 24:15 – Command center view across a fleet of agents 25:48 – Skills as the key primitive for frontier agents 26:30 – Building the Greg Isenberg contrarian AI skill live 32:31 – HyperAgent vs Perplexity Computer, Manus, OpenClaw, Codex 34:52 – Reviewing writing skill 36:55 – The arbitrage of persistence 41:31 – Confidence milestones: first dollar, $10K/month 35:27 – Reviewing contrarian tweet drafts live 45:05 – Giving the agent feedback and building rubrics 50:15 – Connectors, OAuth, and building custom API skills 53:03 – How to get started with HyperAgent 01:01:54 – Credit giveaway for listeners 01:03:31 – Closing Thoughts Key Points Frontier agents have crossed a threshold in the last 4–5 months where they function as true autonomous coworkers, not just chat assistants. Reframe agent cost by value delivered: a $150 token spend for a board memo beats hours of human time, so anchor on opportunity cost. The real arbitrage is persistence: 99% of people quit after one shot, while daily practice for 30/60/90 days produces top 1% operators. Skills are the most important primitive in frontier agents, turning generally intelligent models into domain experts through playbooks. HyperAgent's differentiation is a low floor plus a high ceiling, with rubrics, LLM-as-judge evals, and fleet-wide observability for scaling. Aim for $100B companies with under 5 employees, built on fleets of always-on agents mapped to human job roles. The #1 tool to find startup ideas/trends - https://www.ideabrowser.com LCA helps Fortune 500s and fast-growing startups build their future - from Warner Music to Fortnite to Dropbox. We turn 'what if' into reality with AI, apps, and next-gen products https://latecheckout.agency/ The Vibe Marketer - Resources for people into vibe marketing/marketing with AI: https://www.thevibemarketer.com/ FIND ME ON SOCIAL X/Twitter: https://twitter.com/gregisenberg Instagram: https://instagram.com/gregisenberg/ LinkedIn: https://www.linkedin.com/in/gisenberg/ FIND HOWIE ON SOCIAL X/Twitter: https://x.com/howietl Hyperagent: https://www.hyperagent.com Airtable: https://www.airtable.com-

Cyber Security Today
Inside The Vercel Supply Chain Exploit

Cyber Security Today

Play Episode Listen Later Apr 24, 2026 17:39


Inside the Vercel Breach: Highlighting OAuth Token Risk  In a special edition of Cybersecurity Today, host Jim Love and guest Jamie Blasco (CTO, Nudge Security) discuss Vercel, a major developer hosting platform, and a breach tied to OAuth grants and shadow AI. Reporting shared by Contrast Security's David Lindner describes how a Context AI employee downloaded Roblox AutoFarm scripts, got infected with an info stealer, and attackers harvested credentials, compromised Context AI, then used an over-permissioned OAuth token from a Vercel employee who had signed up to Context AI with an enterprise account and clicked "allow all," with Vercel working with Mandiant on a breach allegedly being sold for $2 million. The episode emphasizes that MFA may not mitigate OAuth abuse, urges admin-managed consent, continuous inventory and auditing of OAuth grants, and better visibility into risky third-party app access across Google Workspace and Microsoft 365. Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale.  You can find them at Meter.com/cst 00:00 Special Edition Intro 00:14 Sponsor Message Meter 00:33 Supply Chain Hack Setup 01:16 Breach Seen In Wild 02:36 Meet Jamie Blasko 02:56 Who Is Vercel 04:34 How The Breach Happened 05:58 Context AI And Shadow IT 07:58 OAuth Controls And Audits 09:11 Impact And Open Questions 11:24 Why MFA Falls Short 12:22 Where To Get Help 14:07 Host Takeaways OAuth Risk 14:53 What To Do Next 16:06 Wrap Up And Feedback 16:42 Sponsor Close Meter 17:24 Final Sign Off          

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, April 22nd, 2026: WAV Malware; GitHub OAUTH Phishing; Perforce Settings

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Apr 22, 2026 7:13


A .WAV With A Payload https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910 The Phishy GitHub Issue Case https://blog.atsika.ninja/posts/the-phishy-github-issue-case/ P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet https://morganrobertson.net/p4wned/

Cables2Clouds
Can You Fly With Glass Wings? - Monthly News Update (with a Surprise)

Cables2Clouds

Play Episode Listen Later Apr 22, 2026 42:46 Transcription Available


Send us Fan Mail“Too dangerous to release” is a bold claim in cybersecurity, so we treat it like any other security headline: we interrogate it. We kick off our monthly news round-up by welcoming Catherine McNamara as a permanent co-host, then dig into Anthropic's Mythos preview model and Project Glasswing, positioned as an AI security and threat intelligence leap that can allegedly find zero-day vulnerabilities at a level the public shouldn't have yet. We ask the uncomfortable questions: where's the independent evidence, what does high-fidelity vulnerability discovery actually look like, and how do we avoid drowning in AI-generated noise?From there, the discussion gets messier in the way real security always is. We talk about tokens, paid code security reviews, and how incentives change when AI companies chase growth, IPO pressure, and government contracts. We also unpack why “ethical” restrictions are hard to enforce in practice and how rumors of source code leaks and fast rewrites complicate any promise of controlled access. If powerful agencies can use AI to speed up exploit discovery, even lower-severity bugs can become dangerous when chained into real attacks.Then we pivot to a concrete lesson every org can use: the Vercel breach. A supply chain compromise plus a single OAuth “Allow All” moment shows how identity and SaaS permissions failures can open the door to data exfiltration. We break down least privilege, blocking risky OAuth grants, shadow SaaS, and why a CASB can be the difference between a contained incident and a headline.We close by connecting AI layoffs to social and economic pressure, including CEO security fears, surprising UBI rhetoric, and Oracle laying off 30,000 people by email. If you care about AI, cloud security, appsec, and what these incentives are doing to the world, this one's for you. Subscribe, share the episode with a friend, and leave a review with your take: is the AI security boom helping defenders more than attackers?Purchase Chris and Tim's book on AWS Cloud Networking: https://www.amazon.com/Certified-Advanced-Networking-Certification-certification/dp/1835080839/Check out the Monthly Cloud Networking Newshttps://docs.google.com/document/d/1fkBWCGwXDUX9OfZ9_MvSVup8tJJzJeqrauaE6VPT2b0/Visit our website and subscribe: https://www.cables2clouds.com/Follow us on BlueSky: https://bsky.app/profile/cables2clouds.comFollow us on YouTube: https://www.youtube.com/@cables2clouds/Follow us on TikTok: https://www.tiktok.com/@cables2cloudsMerch Store: https://store.cables2clouds.com/Join the Discord Study group: https://artofneteng.com/iaatj

Hacker News Recap
April 21st, 2026 | Framework Laptop 13 Pro

Hacker News Recap

Play Episode Listen Later Apr 22, 2026 15:31


This is a recap of the top 10 posts on Hacker News on April 21, 2026. This podcast was generated by wondercraft.ai (00:30): Framework Laptop 13 ProOriginal post: https://news.ycombinator.com/item?id=47852177&utm_source=wondercraft_ai(01:58): Laws of Software EngineeringOriginal post: https://news.ycombinator.com/item?id=47847179&utm_source=wondercraft_ai(03:27): ChatGPT Images 2.0Original post: https://news.ycombinator.com/item?id=47852835&utm_source=wondercraft_ai(04:55): Anthropic says OpenClaw-style Claude CLI usage is allowed againOriginal post: https://news.ycombinator.com/item?id=47844269&utm_source=wondercraft_ai(06:24): Claude Code to be removed from Anthropic's Pro plan?Original post: https://news.ycombinator.com/item?id=47854477&utm_source=wondercraft_ai(07:53): SpaceX says it has agreement to acquire Cursor for $60BOriginal post: https://news.ycombinator.com/item?id=47855293&utm_source=wondercraft_ai(09:21): Meta to start capturing employee mouse movements, keystrokes for AI trainingOriginal post: https://news.ycombinator.com/item?id=47851948&utm_source=wondercraft_ai(10:50): Tim Cook's Impeccable TimingOriginal post: https://news.ycombinator.com/item?id=47847324&utm_source=wondercraft_ai(12:19): The Vercel breach: OAuth attack exposes risk in platform environment variablesOriginal post: https://news.ycombinator.com/item?id=47851634&utm_source=wondercraft_ai(13:47): A Roblox cheat and one AI tool brought down Vercel's platformOriginal post: https://news.ycombinator.com/item?id=47844431&utm_source=wondercraft_aiThis is a third-party project, independent from HN and YC. Text and audio generated using AI, by wondercraft.ai. Create your own studio quality podcast with text as the only input in seconds at app.wondercraft.ai. Issues or feedback? We'd love to hear from you: team@wondercraft.ai

Leveraging AI
286 | How to Automate Anything with Browser Agents & Zero Code with Chris Daigle

Leveraging AI

Play Episode Listen Later Apr 21, 2026 37:15 Transcription Available


You learned how to prompt. Great. Now what?Most business leaders have figured out how to get decent answers from ChatGPT or Claude. But there's a massive gap between writing good prompts and actually building things that run your business. The people closing that gap right now aren't developers. They're business people who figured out one thing: you don't need to code when your browser can do it for you.In this session, Chris Daigle will open his actual setup — Claude Code paired with a browser agent — and build real solutions live. Not slides. Not theory. You'll watch him set up OAuth integrations, automate LinkedIn workflows, and tackle the kind of backend tasks that normally require a developer. All through a browser. All without writing a single line of code manually.Chris calls this evolution "thinking in builds" — the next level beyond prompting. It's where you stop asking AI for answers and start asking it to do the work. And the tools to do it are shockingly accessible: a free browser agent and a $20 Claude subscription.Chris Daigle is the founder of ChiefAIOfficer.com, where he helps mid-market executives and their teams develop AI strategy, implement AI across departments, and become AI-enabled businesses. He trains Chief AI Officers, keynotes at YPO and Vistage events, and has been deep in the agentic AI space since its earliest days. Chris brings the rare combination of strategic thinking and hands-on building.In this session, you'll discover:- How to pair Claude Code with a browser agent like Comet to build real workflows — step by step- What "thinking in builds" means and why it's the skill that separates AI users from AI builders- How to automate OAuth setups, API integrations, and other backend tasks without touching code- Real examples of browser agent workflows you can copy and use immediately- Why even seasoned AI professionals are underestimating what browser agents can do right now- How to safely sandbox your AI agents so they don't destroy your production environment- The exact copy-paste workflow Chris uses to go from idea to working solution in minutesThis is the session where prompting graduates to building. If you've been watching everyone talk about agents but haven't actually deployed one yourself, this is your starting point.About Leveraging AIThe Ultimate AI Course for Business People: https://multiplai.ai/ai-course/YouTube Full Episodes: https://www.youtube.com/@Multiplai_AI/Connect with Isar Meitis: https://www.linkedin.com/in/isarmeitis/ Join our Live Sessions, AI Hangouts and newsletter: https://services.multiplai.ai/eventsIf you've enjoyed or benefited from some of the insights of this episode, leave us a five-star review on your favorite podcast platform, and let us know what you learned, found helpful, or liked most about this show!

Absolute AppSec
Episode 319 - Vercel Breach, Security vs. Compliance, Pull Request Flows w/ AI Agents

Absolute AppSec

Play Episode Listen Later Apr 21, 2026


Episode 319 covers a range of industry developments, primarily focusing on the recent Vercel security incident and the evolving landscape of AI-driven compliance. The hosts detail how a Vercel employee's use of a consumer-level Context AI plan led to a workspace compromise via a leaked OAuth token, eventually allowing attackers to access sensitive environment variables. This leads to a critical discussion about the SOC 2 provider Delve, with the hosts addressing allegations regarding "fake" compliance automation and the general limitations of auditing frameworks that do not inherently equate to true security. This episode also explores the future of the Pull Request (PR) flow, debating whether traditional human-led code reviews are "dead" due to the massive volume of code generated by AI agents. While they acknowledge that startups are moving toward autonomous commits, Seth argues that the PR concept is evolving into a system of agentic attestation and guardrails rather than disappearing entirely. The episode concludes with community survey results on this shift and a reminder about the hosts' upcoming training sessions in Singapore.

Techmeme Ride Home
Robots Winning The (Literal) Race

Techmeme Ride Home

Play Episode Listen Later Apr 20, 2026 21:42


Vercel confirmed a breach traced to an AI platform's compromised OAuth app. The NSA is using Anthropic's Mythos despite the Pentagon blacklist. Mac Minis face 12-week wait times from AI agent demand, and humanoid robots crushed the Beijing half-marathon. Vercel says its internal systems were accessed after a Vercel employee's Google Workspace account was compromised via a breach at the AI platform Context.ai (BleepingComputer) Sources: the US NSA is using Mythos Preview; one source says Mythos is also being widely used within the DoD, despite Anthropic's supply chain risk designation (Axios) Adobe introduces CX Enterprise, an AI agent-based platform that aims to help corporate customers automate digital marketing and other functions (WSJ) Some Mac Mini and Mac Studio models are unavailable or facing up to 12-week wait times in the US, with analysts citing strong demand from AI agent power users (WSJ) Deezer says AI-generated tracks now account for 44% of daily uploads, totaling ~75K tracks per day and 2M+ per month, but account for just 1-3% of consumption (TechCrunch) Sources: Recursive Superintelligence, a four-month-old start-up developing self-teaching AI and founded by ex-DeepMind and OpenAI engineers, has raised $500M+ (FT) At the Beijing half-marathon, several humanoid robots beat human winners by 10+ minutes; a robot made by Honor beat the human world record held by Jacob Kiplimo (Reuters) Disclaimer: ● Initial 3 week subscription and 4 weeks of medication from $79 plus tax and $179 per month plus tax for 12 week subscription thereafter. Final pricing depends on program selection. ● Noom GLP-1Rx Program involves healthy diet, exercise and support. Individual results vary. Meds & personalization based on clinical need. Not reviewed by FDA for safety, efficacy, or quality. No affiliation with Novo Nordisk Inc., the only US source of FDA-approved semaglutide. Not available in all 50 US states ● Based on an analysis of self reported data from 1,254 engaged Noom users. Learn more about your ad choices. Visit megaphone.fm/adchoices

Critical Thinking - Bug Bounty Podcast
Episode 169: Attacking OAuth 2.1

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Apr 9, 2026 30:16


Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!====== This Week in Bug Bounty ======Intigriti is providing free Burp Pro for Hackers!https://www.intigriti.com/blog/news/intigriti-collaborates-with-portswigger-to-support-ethical-hacking-excellence====== Resources ======Django-allauth Account Takeover (ZeroPath Audit)https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilitiesCVE-2025-4144: Cloudflare Workers PKCE Bypasshttps://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9CVE-2025-54576: OAuth2-Proxy Auth Bypasshttps://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass====== Timestamps ======(00:00:00) Introduction(00:02:16) OAuth 2.0 Standards(00:12:08) Agent to Agent Communication(00:17:19) CVE Case studies

Identity At The Center
#410 - Sponsor Spotlight - Strivacity

Identity At The Center

Play Episode Listen Later Mar 25, 2026 60:25


In this Sponsor Spotlight, Jeff Steadman and Jim McDonald welcome back Stephen Cox, co-founder and CTO of Strivacity, for his third appearance and second sponsored episode. Stephen explains Strivacity's role as a CIAM platform and how it is evolving to address agentic AI identity. Topics include why agentic AI changes the identity equation, how agents differ from humans in authentication and authorization, the delegation model and open standards such as OAuth and token exchange, the limitations of API keys in agentic contexts, where MCP fits into the identity picture, managing multi-agent chains and subagents, and why the accountability model must be established before agentic systems reach production. The episode closes with a lighter note on simulation baseball.This episode is sponsored by Strivacity. Learn more at strivacity.com.Connect with Stephen: https://www.linkedin.com/in/stephencox/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at idacpodcast.comTIMESTAMPS00:00:00 Introduction and welcome00:02:30 About Strivacity and agentic AI platform support00:06:30 Why now is the right time to address agentic identity in CIAM00:09:00 How agent authentication and authorization differ from humans00:14:30 Good bots vs bad bots and the history of autonomous agents in CIAM00:19:00 Building your own agent identity solution: five key focus areas00:23:00 Where Strivacity sits in the agentic identity stack00:26:00 Why open standards matter and the vendor lock-in conversation00:28:00 Managing multiple delegated agents and user-facing control00:32:00 API keys and their limitations in agentic AI contexts00:38:00 MCP servers, proxies, and agent-to-agent protocols00:43:00 Multi-agent chains, subagents, and constrained delegation00:46:00 How existing Strivacity customers extend to agentic use cases00:48:00 The one thing you must get right: the accountability model00:51:00 Lighter note: simulation baseballKEYWORDSIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Strivacity, Stephen Cox, CIAM, customer identity, agentic AI, AI agents, delegated identity, OAuth, token exchange, MCP, Model Context Protocol, API keys, non-human identity, authorization, authentication, delegation model, accountability, multi-agent, subagents, OpenID Connect, least privilege, identity governance

Where It Happens
My OpenClaw setup that finally works (Complete Walkthrough)

Where It Happens

Play Episode Listen Later Mar 19, 2026 64:41


I sit down with Moritz Kremb, an OpenClaw power user and agency builder based in Berlin, to break down how to actually make OpenClaw useful. Moritz walks through a 10-step optimization guide covering everything from troubleshooting and memory management to model selection and security basics. He then demos two real systems he built with OpenClaw: a full short-form video content pipeline and a conversational CRM. This episode is for anyone who tried OpenClaw, hit a wall, and wants a clear path to turning it into a superhuman digital employee. Timestamps 00:00 – Intro and episode promise 02:17 – What is OpenClaw 03:17 – OpenClaw vs. ChatGPT vs. Claude Code 07:43 – Where Claude Cowork and Dispatch fit in 09:47 – Why choose OpenClaw over Cowork 11:03 – Step 1: Setting up OpenClaw 14:46 – Step 2: Personalize your workspace files 18:04 – Step 3: Fix and optimize memory 22:43 – Step 4: Choose the right model (OAuth method) 25:56 – Anthropic ban and model provider gray areas 27:33 – Step 5: Organize Telegram groups and topics 30:19 – Step 6: Understand the three browser modes 35:18 – Step 7: Skills — built-in, marketplace, and custom 39:03 – Step 8: Optimize the heartbeat file 42:00 – Step 9: Security basics and prompt injection 48:08 – Step 10: Least access principle and agent-owned accounts 49:52 – Use case 1: No AI Slop content system 58:37 – Use case 2: Conversational CRM 01:01:15 – Final thoughts on the future of personal agents 01:02:55 – Jensen Huang's take: OpenClaw as the new computer Key Points Upload the OpenClaw documentation into a Claude project to create a dedicated troubleshooting baseline — it solves roughly 99% of setup issues. Use the OAuth method (your existing $20 ChatGPT or Anthropic subscription) to avoid expensive API costs, and always configure backup models. Memory problems are almost always caused by memory never being saved in the first place; add an auto-save instruction to the heartbeat file so it logs every 30 minutes. Organize your OpenClaw conversations into separate Telegram groups and topics with group-specific system prompts to avoid context bleed. Stronger models are meaningfully more resistant to prompt injection; pair that with least-access principles and agent-owned accounts for a solid security posture. Custom skills are the path to real automation — whenever you do something repeatedly, tell your OpenClaw to turn it into a skill. The #1 tool to find startup ideas/trends - https://www.ideabrowser.com LCA helps Fortune 500s and fast-growing startups build their future - from Warner Music to Fortnite to Dropbox. We turn 'what if' into reality with AI, apps, and next-gen products https://latecheckout.agency/ The Vibe Marketer - Resources for people into vibe marketing/marketing with AI: https://www.thevibemarketer.com/ FIND ME ON SOCIAL X/Twitter: https://twitter.com/gregisenberg Instagram: https://instagram.com/gregisenberg/ LinkedIn: https://www.linkedin.com/in/gisenberg/ FIND MORITZ ON SOCIAL X: https://x.com/moritzkremb Youtube: https://www.youtube.com/@promptwarrior/videos Instagram: https://www.youtube.com/@promptwarrior/

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, March 4th, 2026: CrushFTP Brute Force; Android Patches 0-Day; 0Auth Phishing Abuse

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Mar 4, 2026 5:03


Bruteforce Scans for CrushFTP https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762 Android March 2026 Patches, including 0-Day (CVE-2026-21385) https://source.android.com/docs/security/bulletin/2026/2026-03-01 OAuth redirection abuse enables phishing and malware delivery https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/