POPULARITY
Nexus sells driver's license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, a Texas healthcare breach, and a Russian national accused of targeting thousands of freelancers with remote-access malware. Maria Varmazis shares the latest space-cyber news. Our guest is Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. AI threatens the government's bug supply. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices we are joined by Rob Allen, Chief Product Officer at Threat Locker, talking about protecting against AI in the workplace. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security) OpenAI's Astra Becomes First Model to Cross Critical Cybersecurity Threshold (SecurityWeek) Sality botnet infrastructure dismantled in joint global takedown (Bleeping Computer) Crooks Are Learning to Love AI Hallucinations (IEEE Spectrum) MSSA Reference Architecture 2.0 (Mobile Satellite Services Association (MSSA)) Exploit Published for Fresh Cleo Harmony Vulnerability (SecurityWeek) Malicious Virtualizor Update Served via BGP Hijacking (SecurityWeek) Nutex Health Says Patient Data Stolen, Hackers Threaten Leak (Infosecurity Magazine) US charges Russian for infecting 80,000 freelancers with malware (Bleeping Computer) How AI could make it harder for governments to use hacking tools (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Noob Spearo Podcast | Spearfishing Talk with Shrek and Turbo
At 26, Matty Parker was locked into a Pilbara mining job. He came over for one Coral Sea trip, went home, sold everything inside a couple of months, and drove across Australia to get out of the golden handcuffs. Twenty-five years of spearing later he manages Divers World in Cairns — the biggest and longest-running shop up that way — and runs MBP Spearfishing Charters, and he's the bloke every local kept telling Shrek to interview. This one gets into the weeds properly: his entire dogtooth setup top to tail, the three-point brief he gives clients before a Coral Sea drift ("when you think you're closer, get closer again"), why he keeps a scorecard of every fish landed and lost and what one-in-three actually looks like, the 10–30kg window where doggies get eaten fastest, and why he moves off a spot the moment it fires. There's also a proper, unflinching yarn about the shark situation in North Queensland after an ugly year for Aussie spearos, and Matty's flat-out best answer of the episode — what it costs you to spend two years shooting fish in eight metres. Cost 'em nothing. Gain everything. If you're saving for a blue water trip, thinking about your first big gun, or you just want to hear a bloke who's put in the hours talk about hunting instead of depth numbers, this one's for you. Matty Parker @mbp_spearfishing Spearfishing Gallery (Add guest photos here) Important Timestamps 00:00:44 — Shrek sets up the episode: dogtooth gear, guiding pitfalls, social media's grip on spearos, and the shark conversation nobody wants to have 00:01:20 — Free shout out to Spearo App, a completely free spearfishing forecasting app, and the level of detail that gobsmacked Shrek 00:03:00 — Fish One Hook's power band size calculator, plus the free Noob Spearo scorecards at spearfishingcourses.com.au/scorecard 00:05:34 — Matty comes highly recommended — Shrek explains who kept telling him to get Matty on the show 00:06:49 — Started spearing at 10 in a small northern WA town; the Coral Sea trip at 26 that made him sell up and drive across Australia away from the golden handcuffs of mining 00:09:13 — Why "the trip of a lifetime" is the wrong mindset to bring on charter, and what the fish actually are (a bonus) 00:11:01 — WA vs the East Coast: fish density and shore access over there, weather-dependent reef trips over here 00:13:05 — Seven trout a day in Queensland is "astronomical", and why the North QLD weather is a green zone in itself 00:14:12 — His first Coral Sea mission: two doggies landed before he lost one, then the figures went backwards fast 00:15:07 — Why hiding your gear from other spearos isn't okay — shot placement and gear are the only two things we control, so share them 00:18:22 — THE FULL DOGTOOTH RIG, TOP TO TAIL: a 130–150cm conventional gun (he runs a 70" Riffe Rader), three or four 16mm rubbers, 8.7mm shaft, slip tip, 23m float line, a 3-atmosphere float, a short 2–5m line, and a second 3-atmosphere float. Nothing else 00:21:19 — The shot-placement point most people miss: all that gun power is for getting through a foot-and-a-half of fish, not for taking longer shots 00:22:14 — Stone shots, the anti-climax-then-relief feeling, and why hearing the boys screaming on the surface is the best part 00:23:25 — "Doggies bring out the best and the worst in everyone" — diving on each other and shooting each other's fish vs. proper team work 00:25:33 — What happens in the first 60 seconds after the shot: withstand the first run, then get it up fast, because that's when they get eaten 00:26:31 — Matty's shark theory — the 10–30kg window where doggies are too strong to overpower but small enough for sharks to eat quickly, and why big fish often survive longer 00:27:28 — The scorecard he's kept since day one: every shot fired that doesn't end on the boat counts as a loss, and he's landing roughly one in three 00:29:42 — The three-point brief: get closer twice (take two more kicks when you think the shot's on), take your time, and work as a team 00:30:44 — Fish karma — why not taking the bad shot pays you back somewhere else, maybe a year later in another country 00:32:16 — There are blokes on Matty's list who can't buy their way back onto a trip 00:33:53 — Life in the shop at Divers World, and the pre-YouTube days of nagging the newsagent for the first-Thursday-of-the-month dive mag 00:35:00 — The apprenticeship problem: "everyone wants to be the tradesman and no one wants to do their apprenticeship" — plus 100 hours a year, five years, then start pushing depth 00:36:59 — An 8kg red doesn't taste as good as a 4kg red, so who exactly are you shooting big fish for? 00:37:20 — Matty's definition of a good spearo: someone who knows how to find fish and hunt them. That's it. "If you want to be a free diver, go be a free diver" 00:38:31 — Shrek on the gap between physiology and wisdom — you can learn to lay on the bottom in 20m quickly, but the ocean will still beat you 00:42:54 — Advice for green divers: pool training, join the club, then find one or two people at your level and grow together 00:43:11 — The self-check Matty runs on every dive: surface, look around, and if no one's within 20 metres you're only diving at 30% today 00:46:25 — How MBP started — the client on the tender who reignited it, four or five years of trips through the shop, then going out on his own 00:47:38 — His October 4–12 Coral Sea trip and the nine-day structure: steam out overnight, wake up in the Coral Sea, six full dive days 00:51:08 — Why the Coral Sea holds every Australian dogtooth record — the vis, the pinnacles rising from a kilometre of water, and how few boats actually get out there 00:52:14 — Doggies aren't migratory and aren't even tuna — they're mackerel (Gymnosarda unicolor), resident on their pinnacles, and Matty's seen the same fish a year apart 00:53:18 — When to be in the water: tide change, first light, and the golden hour on a shoal 00:55:00 — Why he never dives the same spot twice on a trip, even after a 20-fish afternoon — spread the pressure and the fish are there in three years 00:56:59 — Eating doggie: it freezes badly, ciguatera risk on the big models, sashimi most nights on the boat, and euro mounts for the jaws 00:59:28 — Burley and flashers: pilchards over fish frames (running a knife through fish aggravates sharks), and his basic buzz-bomb flasher with a knife jig and three double-sided mirrors 01:01:00 — Flash with purpose — "don't just do it because I said go over there and flash", plus why he stays on the flasher to call the dives 01:02:22 — Tracking a big gun with a breakaway: gun down, hand on the handle, and steering it through the water by the muzzle like a surfboard 01:04:21 — Finding the white dot on the tail knuckle in black water — and why the fish is invisible without it 01:05:39 — He works out every diver on the boat at the dinner the night before the charter 01:06:40 — "I won't shoot a doggy under 30 kilo" — how expectations set by social media wreck people's trips before they get wet 01:08:14 — Shrek's horror story: the charter client who wouldn't buddy up, 100 nautical miles offshore, and how far Shrek escalated it 01:11:33 — A week with no reception, and how the bloke you wanted to push over the side on day one is your mate by day four 01:13:52 — Shrek's vision statement — reconnecting people with themselves, their food, the natural world and each other 01:15:18 — Beyond doggies: red emperor, Maori sea perch, buffalo emperor, iron jaw and green job fish, plus the wahoo, yellowfin and marlin you have to go and hunt separately 01:16:37 — The 140–150kg marlin that snapped a straight shaft last year — another argument for slip tips 01:17:32 — Reading current in the Coral Sea (it's all ocean current, not tidal), and the October moon that fired then went dead five weeks later 01:19:59 — The Noob Spearo x MBP trip: a Great Barrier Reef trip heading north past Lizard Island in March 01:20:40 — What the B in MBP stands for, and the middle name Shrek and Matty share 01:21:43 — SHARKS: an ugly year for Aussie spearos, and Matty's honest read on why it's changed 01:22:03 — His two-part theory — social media virtue signalling plus an education gap — and the fact that a shark now has no commercial value in Australia 01:24:51 — Shrek's flake confession, and how spearos take an abundant freezer completely for granted 01:26:18 — The maths on shark bycatch, and how visibly the aggression has changed in the water in five years 01:27:57 — The angry email Shrek wrote about "just buy your fish from the supermarket" comments on dead divers' posts 01:29:53 — Matty's in-water protocol: he can read an area in ten minutes and pull everyone out. "There's no fish that's worth any part of my body" 01:31:06 — The reefs off Hinchinbrook with resident, territorial bull sharks, and bites that happened in 20m of vis 01:33:21 — Shark deterrents: no one wearing one has been bitten, the scorpion tail zapping you on the duck dive, and how confidence itself changes a shark's read on you 01:35:00 — Shrek gets charged on the bottom by a bull shark, and the seasons where he simply can't relax enough to dive properly 01:36:42 — The most dangerous thing beginners (and plenty of experienced blokes) do: gun handling, clipped guns pointing at the diver behind them, finger on the trigger 01:38:36 — The best answer of the episode: if you could only shoot fish in eight metres for the next two years, what does it cost you? "Cost 'em nothing. And you gain everything" 01:40:09 — Shrek's traditional ocean poo story request, answered from a back deck in California 01:41:16 — Where to find Matty and both trips, plus the price bracket 01:43:31 — Outro: Deep North with Matty and Shrek, March 2027 — spearfishingcourses.com.au/deepnorth Links Mentioned, Partner Deals and Discounts + Froth Connect with Matty Parker MBP Spearfishing Charters — Coral Sea and Great Barrier Reef charters out of Cairns Instagram: @mbp_spearfishing MBP Spearfishing Charters on Facebook Divers World Cairns — where Matty manages the shop
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-941
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Show Notes: https://securityweekly.com/psw-941
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-941
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Show Notes: https://securityweekly.com/psw-941
http://www.Threatlocker.com/cisoAll links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Edward Contreras, senior evp and CISO, Frost Bank. Joining is sponsored guest Rob Allen, chief product officer, ThreatLocker. In this episode: Not my job, still my problem The tools people actually use Mac, Windows, and the debate that won't quit Hiring for imagination, not acronyms A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.
Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. “Easy,” Rob Allen said, “it's already blocked if you're using Threatlocker.” Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting “cyber-enabled crime” mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-473
Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting "cyber-enabled crime" mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-473
Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting "cyber-enabled crime" mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-473
Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Topic Segment For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company? News Segment Finally, in the enterprise security news, we check the vibes New MCP standard and AI text watermarking what does combatting "cyber-enabled crime" mean? A closer look at Cl0p One 3rd party was responsible for all the AI sandbox escapes and hacking reports vulnerabilities Comcast can track your movements with WiFi A novel solution to the AI datacenter water use concerns All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-473
Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in safeguards, organizations can choose to enforce security policies using ThreatLocker. Rob will discuss how ThreatLocker can enforce AI boundaries through Allowlisting, Ringfencing™, Endpoint Firewall, and Web Content Control, with Community Policies that govern what agentic AI tools can run, do, access, and reach. Segment resources: - https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents - https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools - https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, 3 cybersecurity issues that should keep every CEO awake at night, You Don't Find Your Leadership Style. You Mentor Your Way Into It., Cybersecurity Starts With Communication – And We May Be Getting It Wrong, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-461
Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in safeguards, organizations can choose to enforce security policies using ThreatLocker. Rob will discuss how ThreatLocker can enforce AI boundaries through Allowlisting, Ringfencing™, Endpoint Firewall, and Web Content Control, with Community Policies that govern what agentic AI tools can run, do, access, and reach. Segment resources: - https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents - https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools - https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, 3 cybersecurity issues that should keep every CEO awake at night, You Don't Find Your Leadership Style. You Mentor Your Way Into It., Cybersecurity Starts With Communication – And We May Be Getting It Wrong, and more! Show Notes: https://securityweekly.com/bsw-461
Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in safeguards, organizations can choose to enforce security policies using ThreatLocker. Rob will discuss how ThreatLocker can enforce AI boundaries through Allowlisting, Ringfencing™, Endpoint Firewall, and Web Content Control, with Community Policies that govern what agentic AI tools can run, do, access, and reach. Segment resources: - https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents - https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools - https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, 3 cybersecurity issues that should keep every CEO awake at night, You Don't Find Your Leadership Style. You Mentor Your Way Into It., Cybersecurity Starts With Communication – And We May Be Getting It Wrong, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-461
Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in safeguards, organizations can choose to enforce security policies using ThreatLocker. Rob will discuss how ThreatLocker can enforce AI boundaries through Allowlisting, Ringfencing™, Endpoint Firewall, and Web Content Control, with Community Policies that govern what agentic AI tools can run, do, access, and reach. Segment resources: - https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents - https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools - https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, 3 cybersecurity issues that should keep every CEO awake at night, You Don't Find Your Leadership Style. You Mentor Your Way Into It., Cybersecurity Starts With Communication – And We May Be Getting It Wrong, and more! Show Notes: https://securityweekly.com/bsw-461
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/swn-591
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-460
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-460
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-448
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Show Notes: https://securityweekly.com/bsw-448
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-448
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Show Notes: https://securityweekly.com/bsw-448
If you have to ditch your entire appsec strategy because you expect 2026 to bring more vulns more quickly, then you probably didn't have a good strategy in the first place. Rob Allen shares how the mentality of "assume breach" doesn't have to be a defeatist attitude and can instead be a way to change a catastrophic breach into a more contained one. We also talk about proactive security and what an "avoid breach" attitude could look like, including how to apply the macro lessons of default deny and network isolation to writing secure code. Resources https://www.threatlocker.com/blog/the-claude-mythos-preview-proves-now-is-the-time-for-zero-trust?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=claudemythosaswq226&utmcontent=claudemythosasw-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-network-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztnaq226&utmcontent=ztna-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-cloud-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztcaq226&utmcontent=ztca-&utm_term=podcast This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-382
If you have to ditch your entire appsec strategy because you expect 2026 to bring more vulns more quickly, then you probably didn't have a good strategy in the first place. Rob Allen shares how the mentality of "assume breach" doesn't have to be a defeatist attitude and can instead be a way to change a catastrophic breach into a more contained one. We also talk about proactive security and what an "avoid breach" attitude could look like, including how to apply the macro lessons of default deny and network isolation to writing secure code. Resources https://www.threatlocker.com/blog/the-claude-mythos-preview-proves-now-is-the-time-for-zero-trust?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=claudemythosaswq226&utmcontent=claudemythosasw-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-network-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztnaq226&utmcontent=ztna-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-cloud-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztcaq226&utmcontent=ztca-&utm_term=podcast This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/asw-382
If you have to ditch your entire appsec strategy because you expect 2026 to bring more vulns more quickly, then you probably didn't have a good strategy in the first place. Rob Allen shares how the mentality of "assume breach" doesn't have to be a defeatist attitude and can instead be a way to change a catastrophic breach into a more contained one. We also talk about proactive security and what an "avoid breach" attitude could look like, including how to apply the macro lessons of default deny and network isolation to writing secure code. Resources https://www.threatlocker.com/blog/the-claude-mythos-preview-proves-now-is-the-time-for-zero-trust?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=claudemythosaswq226&utmcontent=claudemythosasw-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-network-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztnaq226&utmcontent=ztna-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-cloud-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztcaq226&utmcontent=ztca-&utm_term=podcast This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-382
If you have to ditch your entire appsec strategy because you expect 2026 to bring more vulns more quickly, then you probably didn't have a good strategy in the first place. Rob Allen shares how the mentality of "assume breach" doesn't have to be a defeatist attitude and can instead be a way to change a catastrophic breach into a more contained one. We also talk about proactive security and what an "avoid breach" attitude could look like, including how to apply the macro lessons of default deny and network isolation to writing secure code. Resources https://www.threatlocker.com/blog/the-claude-mythos-preview-proves-now-is-the-time-for-zero-trust?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=claudemythosaswq226&utmcontent=claudemythosasw-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-network-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztnaq226&utmcontent=ztna-&utm_term=podcast https://www.threatlocker.com/capabilities/zero-trust-cloud-access?utmsource=cyberriskalliance&utmmedium=sponsor&utmcampaign=ztcaq226&utmcontent=ztca-&utm_term=podcast This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/asw-382
In this episode, Rob Allen, CEO of Intermountain Health, discusses how the organization is navigating rapid transformation through AI, digital innovation, and large-scale operational change while staying focused on caregiver support, simplification, and proactive care.
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-925
All links and images can be found on CISO Series. Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Steve Zalewski. Joining us is our sponsored guest, Rob Allen. In this episode: The vulnerable stack Changing the structural economics Change the terrain The cost-benefit equation A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Show Notes: https://securityweekly.com/psw-925
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-925
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Show Notes: https://securityweekly.com/psw-925
All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Michelle Wilson, CISO, Movement Mortgage. Joining is sponsored guest Rob Allen, chief product officer, ThreatLocker. This show was recorded in front of a live audience at ThreatLocker's conference, Zero Trust World 2026. In this episode: Risk as a daily habit AI agents talking to AI agents The code on the lock Words that shape decisions A huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.
Welcome to this episode of Monday Night Project, this week we cover WWF Superstars April 20th 1991 where we will see :- The British Bulldog vs. Mike Starr The Orient Express (Kato & Tanaka) (w/Mr. Fuji) vs. Rob Allen & Scott Casey Ted DiBiase (w/Sensational Sherri) vs. Jim Powers The Legion Of Doom (Animal & Hawk) vs. Mark Ming & Randy Sharkey The Warlord (w/Slick) vs. Dale Wolfe The Dragon vs. Louie Spicolli The Mountie (w/Jimmy Hart) vs. Jim Evans Follow the show on facebook Memphis Continental Wrestling Cast (facebook.com/memphiscast) Visit our brand new tshirt store at https://www.unforgettablevision.com/roster/old-bakery-productions You can watch the show at www.patreon.com/memphiscast
NIST struggles with an NVD backlog. Cisco and Splunk ship critical patches. Researchers flag a systemic flaw in Anthropic's MCP. ShinyHunters leak 13.5 million McGraw Hill accounts. Cargo theft goes cyber. A Tennessee hospital breach hits 337,000 patients. Two Americans are sentenced in a North Korean fake-IT-worker scheme. Our guest is Rob Allen, Chief Product Officer at ThreatLocker, describing security gaps addressed by zero trust. OpenAI lets security teams take off the training wheels. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment we are joined by Rob Allen, Chief Product Officer at ThreatLocker, security gaps addressed by zero trust. If you enjoyed this conversation check out the full interview here. Selected Reading NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities (Infosecurity Magazine) Cisco says critical Webex Services flaw requires customer action (Bleeping Computer) Splunk Enterprise Update Patches Code Execution Vulnerability (SecurityWeek) Systemic Flaw in MCP Protocol Could Expose 150 Million Downloads (Infosecurity Magazine) Data breach at edtech giant McGraw Hill affects 13.5 million accounts (Bleeping Computer) Freight Hacker Wields Code-Signing Service to Evade Defenses (GovInfo Security) Data Breach at Tennessee Hospital Affects 337,000 (SecurityWeek) US nationals behind DPRK IT worker 'laptop farm' sent to prison (Bleeping Computer) OpenAI Launches GPT-5.4 Cyber And It's Built Specifically for Defenders (TechGlow) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
In the AI era, cybersecurity is undergoing a fundamental shift as AI agents transform both the speed and scale of attacks. In this interview, Gibb Witham, President and Chief Financial Officer of Hack The Box, explains why organizations must move beyond assumed AI capability toward measurable, validated cyber readiness for both humans and AI systems. Drawing on real-world benchmarks, agentic AI testing, and hands-on training, Witham outlines how security teams can safely adopt AI by proving performance under pressure. The discussion highlights why the future of cybersecurity depends on training, testing, and reinforcing human and AI operators together before they are trusted in critical environments. This segment is sponsored by Hack The Box. Visit https://securityweekly.com/hacktheboxrsac to learn more about them! As credential-based attacks continue to dominate headlines, many organizations are realizing that identity alone is no longer a sufficient control. This conversation explores the shift toward device-based access enforcement and why tying access to both user and device is becoming critical. We'll discuss how this evolution is reshaping Zero Trust strategies across modern environments. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-568
In the AI era, cybersecurity is undergoing a fundamental shift as AI agents transform both the speed and scale of attacks. In this interview, Gibb Witham, President and Chief Financial Officer of Hack The Box, explains why organizations must move beyond assumed AI capability toward measurable, validated cyber readiness for both humans and AI systems. Drawing on real-world benchmarks, agentic AI testing, and hands-on training, Witham outlines how security teams can safely adopt AI by proving performance under pressure. The discussion highlights why the future of cybersecurity depends on training, testing, and reinforcing human and AI operators together before they are trusted in critical environments. This segment is sponsored by Hack The Box. Visit https://securityweekly.com/hacktheboxrsac to learn more about them! As credential-based attacks continue to dominate headlines, many organizations are realizing that identity alone is no longer a sufficient control. This conversation explores the shift toward device-based access enforcement and why tying access to both user and device is becoming critical. We'll discuss how this evolution is reshaping Zero Trust strategies across modern environments. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! Show Notes: https://securityweekly.com/swn-568
In the AI era, cybersecurity is undergoing a fundamental shift as AI agents transform both the speed and scale of attacks. In this interview, Gibb Witham, President and Chief Financial Officer of Hack The Box, explains why organizations must move beyond assumed AI capability toward measurable, validated cyber readiness for both humans and AI systems. Drawing on real-world benchmarks, agentic AI testing, and hands-on training, Witham outlines how security teams can safely adopt AI by proving performance under pressure. The discussion highlights why the future of cybersecurity depends on training, testing, and reinforcing human and AI operators together before they are trusted in critical environments. This segment is sponsored by Hack The Box. Visit https://securityweekly.com/hacktheboxrsac to learn more about them! As credential-based attacks continue to dominate headlines, many organizations are realizing that identity alone is no longer a sufficient control. This conversation explores the shift toward device-based access enforcement and why tying access to both user and device is becoming critical. We'll discuss how this evolution is reshaping Zero Trust strategies across modern environments. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-568
Leo Laporte takes to the expo floor at RSAC 2026 in San Francisco's Moscone Center for a rapid-fire series of conversations with leading security vendors and thinkers. From Thinkst Canary's honeypot deception tactics to Bitwarden's new Agent Access SDK, Tailscale's AI gateway, and Aikido Security's fully autonomous AI pen testers, the dominant theme is clear: the AI agent era has arrived and security hasn't caught up. Plus, a surprise meeting with WannaCry kill-switch hero Marcus Hutchins. Thinkst Canary, ThreatLocker, and Bitwarden are sponsors of the TWiT.tv Network. 0:29 Haroon Meer | Thinkst Canary – Honeypots & Deception Tech 6:35 Bob Boyle | Torq – AI-Powered Security Automation 9:50 Juan Quesada | Yubico – FIDO2, Passkeys & Pre-Registered YubiKeys 12:33 Rob Allen | ThreatLocker – Zero Trust & Deny by Default 25:53 Arun Singh | Drata – Trust Management & Compliance 27:34 Jelmer Snoeck | Keycard Labs – Ephemeral Tokens for AI Agents 35:26 Kasey Babcock | Bitwarden – Agent Access SDK 41:52 Roeland Delrue | Aikido Security – Autonomous AI Pen Testing 48:56 Bill Keeler | Semperis – Identity Security & "Midnight in the War Room" 52:08 MalwareTech Marcus Hutchins & Cybersecurity Girl Caitlin Sarian 54:30 Chris Hughes | Zenity – Securing AI Agents at Runtime 1:01:35 Jillian Murphy | Tailscale – Networking, Aperture & Free Forever Host: Leo Laporte Guests: Haroon Meer, Rob Allen, Bob Boyle, Juan Quesada, Arun Signh, Kasey Babcock, Roeland Delrue, Bill Keeler, Marcus Hutchins, Caitlin Sarian, Chris Hughes, and Jillian Murphy Download or subscribe to TWiT Events at https://twit.tv/shows/twit-events. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
Leo Laporte takes to the expo floor at RSAC 2026 in San Francisco's Moscone Center for a rapid-fire series of conversations with leading security vendors and thinkers. From Thinkst Canary's honeypot deception tactics to Bitwarden's new Agent Access SDK, Tailscale's AI gateway, and Aikido Security's fully autonomous AI pen testers, the dominant theme is clear: the AI agent era has arrived and security hasn't caught up. Plus, a surprise meeting with WannaCry kill-switch hero Marcus Hutchins. Thinkst Canary, ThreatLocker, and Bitwarden are sponsors of the TWiT.tv Network. 0:29 Haroon Meer | Thinkst Canary – Honeypots & Deception Tech 6:35 Bob Boyle | Torq – AI-Powered Security Automation 9:50 Juan Quesada | Yubico – FIDO2, Passkeys & Pre-Registered YubiKeys 12:33 Rob Allen | ThreatLocker – Zero Trust & Deny by Default 25:53 Arun Singh | Drata – Trust Management & Compliance 27:34 Jelmer Snoeck | Keycard Labs – Ephemeral Tokens for AI Agents 35:26 Kasey Babcock | Bitwarden – Agent Access SDK 41:52 Roeland Delrue | Aikido Security – Autonomous AI Pen Testing 48:56 Bill Keeler | Semperis – Identity Security & "Midnight in the War Room" 52:08 MalwareTech Marcus Hutchins & Cybersecurity Girl Caitlin Sarian 54:30 Chris Hughes | Zenity – Securing AI Agents at Runtime 1:01:35 Jillian Murphy | Tailscale – Networking, Aperture & Free Forever Host: Leo Laporte Guests: Haroon Meer, Rob Allen, Bob Boyle, Juan Quesada, Arun Signh, Kasey Babcock, Roeland Delrue, Bill Keeler, Marcus Hutchins, Caitlin Sarian, Chris Hughes, and Jillian Murphy Download or subscribe to TWiT Events at https://twit.tv/shows/twit-events. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
Leo Laporte takes to the expo floor at RSAC 2026 in San Francisco's Moscone Center for a rapid-fire series of conversations with leading security vendors and thinkers. From Thinkst Canary's honeypot deception tactics to Bitwarden's new Agent Access SDK, Tailscale's AI gateway, and Aikido Security's fully autonomous AI pen testers, the dominant theme is clear: the AI agent era has arrived and security hasn't caught up. Plus, a surprise meeting with WannaCry kill-switch hero Marcus Hutchins. Thinkst Canary, ThreatLocker, and Bitwarden are sponsors of the TWiT.tv Network. 00:00:00 Intro – Leo Laporte at RSAC 2026, Moscone Center 00:00:29 Haroon Meer | Thinkst Canary – Honeypots & Deception Tech 00:06:35 Bob Boyle | Torq – AI-Powered Security Automation 00:09:50 Juan Quesada | Yubico – FIDO2, Passkeys & Pre-Registered YubiKeys 00:12:33 Rob Allen | ThreatLocker – Zero Trust & Deny by Default 00:25:53 Arun Singh | Drata – Trust Management & Compliance 00:27:34 Jelmer Snoeck | Keycard Labs – Ephemeral Tokens for AI Agents 00:35:26 Kasey Babcock | Bitwarden – Agent Access SDK 00:41:52 Roeland Delrue | Aikido Security – Autonomous AI Pen Testing 00:48:56 Bill Keeler | Semperis – Identity Security & "Midnight in the War Room" 00:52:08 MalwareTech Marcus Hutchins & Cybersecurity Girl Caitlin Sarian 00:54:30 Chris Hughes | Zenity – Securing AI Agents at Runtime 01:01:35 Jillian Murphy | Tailscale – Networking, Aperture & Free Forever Host: Leo Laporte Guests: Haroon Meer, Rob Allen, Bob Boyle, Juan Quesada, Arun Signh, Kasey Babcock, Roeland Delrue, Bill Keeler, Marcus Hutchins, Caitlin Sarian, Chris Hughes, and Jillian Murphy Download or subscribe to TWiT Events at https://twit.tv/shows/twit-events. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis, principal of Duha. Joining us is our sponsored guest, Rob Allen, chief product officer, ThreatLocker. In this episode: Your best employee is your biggest risk Stop guessing the next attack AI is not a feature Stop blaming the user Huge thanks to our sponsor, ThreatLocker ThreatLocker makes Zero Trust practical. With Default Deny, Ringfencing, and Elevation Control, CISOs get real control that's easy to manage and built to scale. Stop threats before they execute and reduce operational noise without adding complexity. See how simple prevention can be at ThreatLocker.com/CISO.
On this episode of DGTL Voices, Ed interviews Rob Allen, the CEO of Intermountain Health. They discuss Rob's journey from a dairy farm in Wyoming to leading a major healthcare organization, emphasizing the importance of caregivers, the role of digital transformation in healthcare, and the significance of vulnerability in leadership. Rob shares insights on finding creativity, evolving definitions of success, and the lessons learned from his upbringing. The conversation highlights the value of relationships in leadership and the commitment to making a positive impact in healthcare.
Interview Segment - Rob Allen - Clickfix "Clickfix" attacks aren't new, but they're certainly more common these days. Rob Allen joins us to help us understand what they are, why they work on your employees, and how to stop them! We tie it into infostealers and ransomware actors. Plenty of practical recommendations for how to spot and prevent these attacks in your environment, don't miss it! This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Interview Segment - Rob Allen - Zero Trust World Threatlocker's 6th annual Zero Trust World event is happening next month! This three day event runs from March 4th through the 6th once again in sunny Orlando, Florida. This year's event is packed with hands-on hacking workshops, competitions, prizes, and keynotes from Marcus Hutchins, and Linus and Luke from Linus Tech Tips. Security Weekly will be there as well, doing live interviews and recording an episode of ESW live! This segment is sponsored by ThreatLocker's annual Zero Trust World. Visit https://securityweekly.com/ztw to learn more about the conference and register with discount code ZTW26ESW! News Segment For this week's enterprise news, we discuss OpenClaw! funding! acquisitions! testing out AI models' offensive security capabilities more openclaw! the need for more transparency and testing in the vendor space A photobooth service leaks drunken pictures of wedding parties The salty snack that helps server uptime All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-445
Everyone is turning to LLMs to generate code, including attackers. Thus, it's no great surprise that there are now examples of malware generated by LLMs. We discuss the implications of more malware with Rob Allen and what it means for orgs that want to protect themselves from ransomware. Resources https://www.bleepingcomputer.com/news/security/voidlink-cloud-malware-shows-clear-signs-of-being-ai-generated/ https://research.checkpoint.com/2026/voidlink-early-ai-generated-malware-framework/ https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools/ This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-368