Podcasts about security weekly

  • 51PODCASTS
  • 2,517EPISODES
  • 51mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Jul 18, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about security weekly

Latest podcast episodes about security weekly

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - July 18, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later Jul 18, 2026 10:16


In this week's update, we break down Secretary of State Marco Rubio's landmark “Antifa Summit” in Washington, DC, where representatives from more than 60 nations gathered to confront the resurgence of far-left political terrorism and transnational violent extremism. We examine Rubio's powerful opening remarks, including his stark contrast between decades of focus on jihadist threats and the long-standing institutional blind spot on left-wing violence. We cover the Trump administration's new whole-of-government strategy and the renewed international coalition committed to dismantling these networks. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 300 Deep Dive. Face it. The AI, Privacy, and Security Weekly Update for the week ending July 14th., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jul 16, 2026 34:50


This deep dive takes apart the evolving landscape of digital privacy, artificial intelligence, and global security, highlighting how systems designed for convenience often transform into tools for surveillance. Key reports detail the rise of facial recognition in retail, the exploitation of dormant accounts to spread malware, and the vulnerability of smart home devices to international espionage. We also explore shifting labor trends, noting a massive surge in cybersecurity interest and a move toward skill-based hiring over traditional degrees. Furthermore, we discuss the technological rivalry between the US and China, where cost-cutting and data extraction drive the adoption of rival AI models. Ultimately, this update serves as a warning that security is a continuous process requiring constant vigilance against automated threats and behavioral tracking.

ai china deep dive privacy weekly update security weekly week ending july
IT Privacy and Security Weekly update.
Face it. The A.I., Privacy, and Security Weekly Update for the Week Ending July 14th. 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jul 15, 2026 25:28


In this week's updateUK shops are about to call the police on you within four seconds of you walking through the door - and you don't have to do anything wrong first.A GitHub account sat completely silent for 19 months, then woke up and dropped a working mass-exploit kit within minutes - and age on the internet is not the same as trust.Fifty-five percent of Americans have quietly stopped posting on social media - and the reason isn't what the platforms want to admit.Recruiters say they can't find workers. New graduates say they can't find jobs. The economy says both of them are right - and AI is not actually the villain in this one.Applied AI engineering is becoming one of the hottest jobs in tech, and the skill that matters most is not writing clever prompts - it's building report cards for AI that catch the model when it quietly does something dangerous.The Pentagon opened a paid cybersecurity apprenticeship that requires no degree, no experience, and no prior skills - and 70,000 people showed up within days.Russian intelligence didn't hack into military networks to spy on NATO supply convoys - they just looked through the security cameras of ordinary homes with default passwords.The US and China are fighting an AI war on two fronts simultaneously: American companies are secretly using Chinese models to cut costs, and Chinese teams are running millions of fake conversations with American AI to steal what makes it work.Cloudflare has stopped asking you to click the traffic lights. Now it just watches your mouse move - for your entire visit - and decides from there.This week's stories are united by a single uncomfortable observation: the systems we built for convenience keep turning into systems of surveillance, and the systems we built for security keep being the ones we forgot to secure. Some of this week is alarming. Some of it is genuinely useful. All of it is worth understanding. Let's face it.Find the full transcript to this week's podcast here.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - July 11, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later Jul 11, 2026 7:16


In this week's update, we break down the FBI's latest counterintelligence successes, including the neutralization of active foreign spies, a surge in counterintelligence arrests, the disruption of hundreds of plots, cartel-related arrests, the removal of dozens of Chinese intelligence operatives, and more. We also examine persistent and evolving threats from China, Russia, Iran, and other adversaries, including sophisticated Chinese recruitment operations. We cover fresh intelligence on Iranian plots to assassinate President Trump, the risks tied to increased Iranian encounters at the northern border, and the warning signs law enforcement and security professionals should be watching for. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 299 Deep Dive. Tracked: The AI, Privacy and Security Weekly Update for the Week ending July 7th., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jul 9, 2026 53:29


These stories highlight the multifaceted challenges of the burgeoning AI era, ranging from geopolitical regulatory shifts to novel cybersecurity threats. While the U.S. government leverages export controls to extract security commitments from AI developers, international bodies like the EU are implementing strict enforcement deadlines for high-risk systems. Technological advancements are simultaneously enabling autonomous ransomware attacks and revolutionary scientific discoveries, such as AI-designed antibiotics. However, this rapid integration creates significant strain on local energy infrastructure and reveals the persistent necessity of human expertise in traditional engineering. Furthermore, the legal landscape is evolving as courts and legislatures move to protect digital privacy and shield minors from the emotional manipulation of AI companions. Collectively, these reports underscore that as AI becomes a universal tool, society must grapple with its physical, ethical, and security implications.

IT Privacy and Security Weekly update.
July 07, 2026 Tracked: The AI, Privacy, and Security Weekly Update for the Week Ending July 7th., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jul 8, 2026 23:13


Episode 299 Discoveries in this week's update...Microsoft's Windows has been quietly assigning every PC a persistent tracking ID that survives VPNs, new IP addresses, and most attempts to disappear - and a hacker just got arrested because of it.Anthropic built a secret tracker inside its own developer tool to watch for Chinese users - and the company that made its name on responsible AI had to remove it after researchers found the hidden code.The Supreme Court just handed every smartphone owner in America a constitutional privacy right they didn't know they had - and it changes what law enforcement can do with your location data forever.An Air Force engineer with a saw and a point to make took down 13 license plate reader cameras - and thousands of strangers across the country sent him money to say thank you.An AI agent was given a web browser, a payment system, and instructions to help - and attackers left invisible instructions on websites that redirected the money somewhere else entirely.The first ransomware attack run entirely by an AI agent - start to finish, no human required - happened this week, and the kill chain took minutes not days.The MEP who sat on the European Parliament committee investigating Pegasus spyware had his own phone infected with Pegasus spyware while he was doing it.Amazon just told everyone who bought a Fire Stick that they no longer control what runs on it - and the feature they killed was the one most commonly used to limit Amazon's ability to track you.This week, the theme writes itself: everything is watching something.Your operating system, your AI assistant, your TV stick, the cameras on every corner, the spyware on the phones of the people writing the rules about spyware.The stories this week are sometimes alarming, occasionally darkly funny, and always worth paying attention to - because the first step to not being tracked is knowing what's doing the tracking.Let's discover.Find the full transcript to theis podcast here.

Paul's Security Weekly
Mastering agent permissions and Identiverse interviews - Howard Ting, Ajay Gupta, Sandy Bird, Amir Ofek - ESW #466

Paul's Security Weekly

Play Episode Listen Later Jul 6, 2026 77:39


Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represented. On the surface, this looks like a cloud/hyperscaler permissions challenge, but it isn't that simple. As agents like Claude Code, Codex, and Hermes are connected to enterprise cloud agents, the risk spreads outside VPCs and onto endpoints. Check out the episode to learn more about some of the most common risks Sandy finds and how Sonrai goes about addressing them. This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Segment Resources AWS Bedrock agent permissions: what you need to lock down before you go live Making Enterprise AI Agents Accountable with Amir Ofek, CEO and Co-Founder of aizome Organizations looking to unlock the power of Enterprise AI Agents, and in a controlled and safe way at the speed of AI. Identity is at the heart of it. However, NHI Governance Is Not Enough for Enterprise AI Agents. The identity industry has responded to the rise of AI agents the same way it responds to every new identity challenge: extend existing frameworks. Map agents to human owners. Enforce least privilege. Govern them like non-human identities. It is a reasonable instinct. It is also insufficient in ways that matter enormously. Non-human identity security was built for a deterministic world - service accounts, API keys, bots. These identities do what they are configured to do. Their behavior is predictable enough that static governance models work. Enterprise AI agents are categorically different. Not in degree - in kind. They don't execute fixed instructions. They reason, plan, and adapt in response to context. Their scope shifts with every task. Their behavior at runtime can diverge significantly from anything true at provisioning time. Unlike any identity that came before them, they frequently change their intent, at a pace no governance model built for human movers or machine credentials was designed to handle. Wrapping them in the same framework you use for a service account isn't wrong. It's just insufficient in precisely the places where risk accumulates. Download the SANS AI Security Maturity Model eBook This segment is sponsored by aizome. Visit https://securityweekly.com/aizomeidv to learn more about them! The Human Authorized. The Agent Acted. Who's Accountable? Interview with Howard Ting - CEO - Opal Security A self-driving car still has a license plate The accountability didn't change just because the driver did. The same has to be true for AI agents, but most environments can't trace an agent action back through the layers of delegation to the human who authorized it. Howard Ting, CEO of Opal Security, joins Security Weekly to discuss what the accountability model looks like when employees run swarms of agents, and what has to be in place before that accountability chain is tested. https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access This segment is sponsored by Opal Security. Visit https://securityweekly.com/opalidv to learn more about them! Next Evolution of Identity Security: AI for Lower Cost, Efficiency & Governance with Ajay Gupta - President & CEO - SDG Organizations have invested heavily in identity platforms, but many still struggle to maximize security, efficiency, and governance outcomes. As AI transforms both cyber defense and cyber threats, Identity Security is emerging as a critical foundation for securing human and non-human identities alike. In this discussion, we explore how AI is helping organizations reduce costs, improve operations, defend against AI-powered attacks, and address the governance challenges created by AI agents—highlighting the convergence of Identity Security, AI Security, and AI Governance. This segment is sponsored by SDG. Visit https://securityweekly.com/sdgidv to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-466

Enterprise Security Weekly (Audio)
Mastering agent permissions and Identiverse interviews - Howard Ting, Ajay Gupta, Sandy Bird, Amir Ofek - ESW #466

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jul 6, 2026 77:39


Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represented. On the surface, this looks like a cloud/hyperscaler permissions challenge, but it isn't that simple. As agents like Claude Code, Codex, and Hermes are connected to enterprise cloud agents, the risk spreads outside VPCs and onto endpoints. Check out the episode to learn more about some of the most common risks Sandy finds and how Sonrai goes about addressing them. This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Segment Resources AWS Bedrock agent permissions: what you need to lock down before you go live Making Enterprise AI Agents Accountable with Amir Ofek, CEO and Co-Founder of aizome Organizations looking to unlock the power of Enterprise AI Agents, and in a controlled and safe way at the speed of AI. Identity is at the heart of it. However, NHI Governance Is Not Enough for Enterprise AI Agents. The identity industry has responded to the rise of AI agents the same way it responds to every new identity challenge: extend existing frameworks. Map agents to human owners. Enforce least privilege. Govern them like non-human identities. It is a reasonable instinct. It is also insufficient in ways that matter enormously. Non-human identity security was built for a deterministic world - service accounts, API keys, bots. These identities do what they are configured to do. Their behavior is predictable enough that static governance models work. Enterprise AI agents are categorically different. Not in degree - in kind. They don't execute fixed instructions. They reason, plan, and adapt in response to context. Their scope shifts with every task. Their behavior at runtime can diverge significantly from anything true at provisioning time. Unlike any identity that came before them, they frequently change their intent, at a pace no governance model built for human movers or machine credentials was designed to handle. Wrapping them in the same framework you use for a service account isn't wrong. It's just insufficient in precisely the places where risk accumulates. Download the SANS AI Security Maturity Model eBook This segment is sponsored by aizome. Visit https://securityweekly.com/aizomeidv to learn more about them! The Human Authorized. The Agent Acted. Who's Accountable? Interview with Howard Ting - CEO - Opal Security A self-driving car still has a license plate The accountability didn't change just because the driver did. The same has to be true for AI agents, but most environments can't trace an agent action back through the layers of delegation to the human who authorized it. Howard Ting, CEO of Opal Security, joins Security Weekly to discuss what the accountability model looks like when employees run swarms of agents, and what has to be in place before that accountability chain is tested. https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access This segment is sponsored by Opal Security. Visit https://securityweekly.com/opalidv to learn more about them! Next Evolution of Identity Security: AI for Lower Cost, Efficiency & Governance with Ajay Gupta - President & CEO - SDG Organizations have invested heavily in identity platforms, but many still struggle to maximize security, efficiency, and governance outcomes. As AI transforms both cyber defense and cyber threats, Identity Security is emerging as a critical foundation for securing human and non-human identities alike. In this discussion, we explore how AI is helping organizations reduce costs, improve operations, defend against AI-powered attacks, and address the governance challenges created by AI agents—highlighting the convergence of Identity Security, AI Security, and AI Governance. This segment is sponsored by SDG. Visit https://securityweekly.com/sdgidv to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-466

Paul's Security Weekly TV
Mastering agent permissions and Identiverse interviews - Amir Ofek, Howard Ting, Ajay Gupta, Sandy Bird - ESW #466

Paul's Security Weekly TV

Play Episode Listen Later Jul 6, 2026 77:39


Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represented. On the surface, this looks like a cloud/hyperscaler permissions challenge, but it isn't that simple. As agents like Claude Code, Codex, and Hermes are connected to enterprise cloud agents, the risk spreads outside VPCs and onto endpoints. Check out the episode to learn more about some of the most common risks Sandy finds and how Sonrai goes about addressing them. This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Segment Resources AWS Bedrock agent permissions: what you need to lock down before you go live Making Enterprise AI Agents Accountable with Amir Ofek, CEO and Co-Founder of aizome Organizations looking to unlock the power of Enterprise AI Agents, and in a controlled and safe way at the speed of AI. Identity is at the heart of it. However, NHI Governance Is Not Enough for Enterprise AI Agents. The identity industry has responded to the rise of AI agents the same way it responds to every new identity challenge: extend existing frameworks. Map agents to human owners. Enforce least privilege. Govern them like non-human identities. It is a reasonable instinct. It is also insufficient in ways that matter enormously. Non-human identity security was built for a deterministic world - service accounts, API keys, bots. These identities do what they are configured to do. Their behavior is predictable enough that static governance models work. Enterprise AI agents are categorically different. Not in degree - in kind. They don't execute fixed instructions. They reason, plan, and adapt in response to context. Their scope shifts with every task. Their behavior at runtime can diverge significantly from anything true at provisioning time. Unlike any identity that came before them, they frequently change their intent, at a pace no governance model built for human movers or machine credentials was designed to handle. Wrapping them in the same framework you use for a service account isn't wrong. It's just insufficient in precisely the places where risk accumulates. Download the SANS AI Security Maturity Model eBook This segment is sponsored by aizome. Visit https://securityweekly.com/aizomeidv to learn more about them! The Human Authorized. The Agent Acted. Who's Accountable? Interview with Howard Ting - CEO - Opal Security A self-driving car still has a license plate The accountability didn't change just because the driver did. The same has to be true for AI agents, but most environments can't trace an agent action back through the layers of delegation to the human who authorized it. Howard Ting, CEO of Opal Security, joins Security Weekly to discuss what the accountability model looks like when employees run swarms of agents, and what has to be in place before that accountability chain is tested. https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access This segment is sponsored by Opal Security. Visit https://securityweekly.com/opalidv to learn more about them! Next Evolution of Identity Security: AI for Lower Cost, Efficiency & Governance with Ajay Gupta - President & CEO - SDG Organizations have invested heavily in identity platforms, but many still struggle to maximize security, efficiency, and governance outcomes. As AI transforms both cyber defense and cyber threats, Identity Security is emerging as a critical foundation for securing human and non-human identities alike. In this discussion, we explore how AI is helping organizations reduce costs, improve operations, defend against AI-powered attacks, and address the governance challenges created by AI agents—highlighting the convergence of Identity Security, AI Security, and AI Governance. This segment is sponsored by SDG. Visit https://securityweekly.com/sdgidv to learn more about them! Show Notes: https://securityweekly.com/esw-466

Enterprise Security Weekly (Video)
Mastering agent permissions and Identiverse interviews - Amir Ofek, Howard Ting, Ajay Gupta, Sandy Bird - ESW #466

Enterprise Security Weekly (Video)

Play Episode Listen Later Jul 6, 2026 77:39


Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represented. On the surface, this looks like a cloud/hyperscaler permissions challenge, but it isn't that simple. As agents like Claude Code, Codex, and Hermes are connected to enterprise cloud agents, the risk spreads outside VPCs and onto endpoints. Check out the episode to learn more about some of the most common risks Sandy finds and how Sonrai goes about addressing them. This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Segment Resources AWS Bedrock agent permissions: what you need to lock down before you go live Making Enterprise AI Agents Accountable with Amir Ofek, CEO and Co-Founder of aizome Organizations looking to unlock the power of Enterprise AI Agents, and in a controlled and safe way at the speed of AI. Identity is at the heart of it. However, NHI Governance Is Not Enough for Enterprise AI Agents. The identity industry has responded to the rise of AI agents the same way it responds to every new identity challenge: extend existing frameworks. Map agents to human owners. Enforce least privilege. Govern them like non-human identities. It is a reasonable instinct. It is also insufficient in ways that matter enormously. Non-human identity security was built for a deterministic world - service accounts, API keys, bots. These identities do what they are configured to do. Their behavior is predictable enough that static governance models work. Enterprise AI agents are categorically different. Not in degree - in kind. They don't execute fixed instructions. They reason, plan, and adapt in response to context. Their scope shifts with every task. Their behavior at runtime can diverge significantly from anything true at provisioning time. Unlike any identity that came before them, they frequently change their intent, at a pace no governance model built for human movers or machine credentials was designed to handle. Wrapping them in the same framework you use for a service account isn't wrong. It's just insufficient in precisely the places where risk accumulates. Download the SANS AI Security Maturity Model eBook This segment is sponsored by aizome. Visit https://securityweekly.com/aizomeidv to learn more about them! The Human Authorized. The Agent Acted. Who's Accountable? Interview with Howard Ting - CEO - Opal Security A self-driving car still has a license plate The accountability didn't change just because the driver did. The same has to be true for AI agents, but most environments can't trace an agent action back through the layers of delegation to the human who authorized it. Howard Ting, CEO of Opal Security, joins Security Weekly to discuss what the accountability model looks like when employees run swarms of agents, and what has to be in place before that accountability chain is tested. https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access This segment is sponsored by Opal Security. Visit https://securityweekly.com/opalidv to learn more about them! Next Evolution of Identity Security: AI for Lower Cost, Efficiency & Governance with Ajay Gupta - President & CEO - SDG Organizations have invested heavily in identity platforms, but many still struggle to maximize security, efficiency, and governance outcomes. As AI transforms both cyber defense and cyber threats, Identity Security is emerging as a critical foundation for securing human and non-human identities alike. In this discussion, we explore how AI is helping organizations reduce costs, improve operations, defend against AI-powered attacks, and address the governance challenges created by AI agents—highlighting the convergence of Identity Security, AI Security, and AI Governance. This segment is sponsored by SDG. Visit https://securityweekly.com/sdgidv to learn more about them! Show Notes: https://securityweekly.com/esw-466

IT Privacy and Security Weekly update.
Episode 298. Deep Dive. You're Unbelievable. The A.I., Privacy, and Security Weekly Update for the Week Ending June 30th 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jul 2, 2026 42:00


This week's update details a rapidly shifting technological landscape where AI-driven advancements are fundamentally altering global security and corporate ethics. Several reports highlight how adversarial capabilities from rival nations now match elite Western models, prompting urgent international warnings from intelligence agencies about a coming surge in cyber warfare. Domestically, the reports track significant legal and privacy challenges, ranging from Meta's controversial testing methods involving minors to landmark Supreme Court rulings on digital surveillance. Furthermore, our updates emphasize a growing systemic risk within the software industry, as AI-generated code introduces hidden vulnerabilities and leaks sensitive credentials. This collection collectively underscores a critical pivot point where defensive infrastructure must evolve rapidly to keep pace with automated threats. High-stakes stories of supply chain dependencies and data breaches illustrate the difficulty of maintaining security in a globally interconnected environment. Ultimately, the stories serve up a warning that institutional understanding is currently trailing behind the speed of AI integration. Oh yeah!

IT Privacy and Security Weekly update.
You're Unbelievable. The A.I., Privacy, and Security Weekly Update for the Week Ending June 30th 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jul 1, 2026 22:33


Episode 298. In this week's update: Meta contractors spent months posing as suicidal, drug-curious teenagers to test rival chatbots - and the platforms being probed had no idea it was happening.A Chinese AI lab just matched Anthropic's top cybersecurity model on its own turf - and the question isn't whether export controls work, it's whether they ever could.The New York Times says Microsoft didn't just host OpenAI's training runs - it built a 285,000-core machine specifically engineered to feed on its journalism, and the lawsuit's whole strategy just shifted because of it.A shell trick older than most AI startups just walked straight past ten out of eleven coding agent guardrails - and the fix isn't as simple as updating a blocklist.Nearly two out of three AI chatbot apps tested on iPhone are leaking the keys to someone else's wallet - and you'd never know it just by using them.A federal gun-enforcement agency ran more than 300 warrantless phone-tracking searches using data bought from ad networks - until a prosecutor and a judge themselves said no.Companies fired workers to save money on AI, and now some of them are paying five times more for the AI than they ever paid the humans - Gartner says that's not a fluke, it's the trend.Five allied nations' top cybersecurity agencies just used the word 'urgent' in the same breath as 'months, not years' - and that combination doesn't happen by accident.Welcome back, everyone. This is a week where the gap between how fast AI is moving and how fast our safeguards, our laws, and our budgets are catching up gets impossible to ignore, from corporate testing practices that crossed a line to a legal theory that could put cloud infrastructure itself on trial to a federal agency that finally got told no. It runs from alarming to sobering to genuinely urgent, and there isn't a soft landing at the end of it. Let's get into it.Find all the story links and the full transcript for this podcast here.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - June 27, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later Jun 27, 2026 7:31


In this week's update, we first break down the ideologically motivated shooting in Montreal, where a 25-year-old gunman opened fire on the headquarters of Aylo, the parent company of Pornhub. The attacker left behind a lengthy manifesto blending incel ideology with anti-capitalist and Marxist views, specifically targeting the pornography industry. We also report on the sharp increase in Iranian nationals attempting to enter the United States illegally across the northern border with Canada. DHS Secretary Mullin highlighted daily rise in arrests, with many individuals having direct ties to Iran's Islamic Revolutionary Guard Corps. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 297. Deep dive. Bullies and the AI, Privacy and Security Weekly update for the week ending June 23rd., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 25, 2026 47:02


This week we dive deep, highlighting a volatile period for the technology sector, defined by increased government intervention and emerging security threats. The U.S. administration is reportedly targeting AI firms like Anthropic over national security and military compliance, while other companies face critical zero-day vulnerabilities and disputes over bug bounty programs. Beyond security, the landscape is shifting due to ambitious legislative proposals to redistribute AI wealth and major corporate pivots, such as Midjourney's move into medical imaging and GM's expansion into energy storage. Supply chain issues also persist, with AI-driven hardware shortages driving up consumer electronics prices globally. Meanwhile, advancements in 3D-printed batteries and enterprise knowledge graphs signal a new era of infrastructure design. Ultimately, these developments reveal a complex environment where geopolitical strategy, ethical accountability, and rapid innovation are becoming inextricably linked.

IT Privacy and Security Weekly update.
Bullies, and the AI, Privacy, and Security Weekly update for the week ending June 23rd., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 24, 2026 22:32


Episode 297 The U.S. government gave one of America's most important AI companies 90 minutes to shut off its best models - and the reason they gave keeps changing.The real story behind the Anthropic ban has nothing to do with a jailbreak - and everything to do with autonomous weapons and who gets to say no to the Pentagon.The FBI just seized thirteen websites posing as consulting firms - and the fake recruiters behind them may have already messaged someone you know.Hackers spent two months inside Novo Nordisk's systems and walked out with something new: the company's AI models themselves.Your next smartphone is going to cost significantly more - not because of tariffs, but because AI data centers ate all the memory chips.Sixty percent of what TikTok serves to brand new accounts is AI-generated slop - and it's worse when the account belongs to a child.The war in Ukraine has become the world's first live demonstration of AI-assisted combat, and the people planning the next conflict are paying very close attention.Meta is quietly lobbying Congress right now to make it legally impossible for families to sue the company when its algorithms harm their children - and almost nobody is talking about it.This has been a week where the people with the most power moved fastest and quietest - in government backrooms, in corporate lobbying offices, on battlefield drone feeds, and in the recommendation engines shaping what our kids see.Some of these stories are alarming.Some are clarifying.All of them deserve your attention.Let's get into it.Find the full transcript to this podcast here.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - June 20, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later Jun 20, 2026 8:21


In this week's update, we break down the FBI's successful disruption of a domestic terror plot targeting the UFC Freedom 250 event at the White House. This plot, which involved explosive drone attacks, sniper positions, and perimeter breaches coordinated via encrypted chats, serves as a clear emerging threat indicator of how accessible commercial drones and online coordination are lowering barriers for domestic extremists. We also examine the sharp rise in drone violations and enforcement actions around FIFA World Cup events. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting https://www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 296. Deep Dive. "Recognized" by The AI, Privacy, and Security Weekly Update for the Week Ending June 16th. 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 18, 2026 58:09


This week's update illustrates a global landscape rapidly transforming under the influence of artificial intelligence, highlighting both its innovative potential and significant societal risks. Surveillance capabilities are expanding through SignalTrace, which links vehicle data to personal electronics, while military navigation increasingly relies on spatial data harvested from mobile gaming. Within the workforce, professionals are navigating a "botsitting" paradox where productivity gains are often offset by the labor of managing AI errors and oversight. Simultaneously, the educational sector faces a crisis as reliance on digital tools correlates with a measurable decline in students' reading comprehension and attention spans. Security concerns are also intensifying, evidenced by CISA's new mandates for faster software patching to counter automated cyberattacks. Ultimately, these reports suggest that the true challenge of the AI era lies in managing data correlation and organizational adaptation rather than just technical advancement.

IT Privacy and Security Weekly update.
"Recognized" by The AI, Privacy, and Security Weekly Update for the Week Ending June 16th., 2026 Episode 296

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 16, 2026 24:39


 Episode 296. In this week's update:Your license plate reader just got an upgrade, and now it wants to know what's in your pocket, too.The government finally admitted what security pros have been saying for years: AI means you have three days to patch, not three months.AI adoption went from 'we're running a pilot' to 'we're running the business,'  and nobody sent a memo.Workers are saving 11 hours a week to AI, then spending six of those hours babysitting the AI  and someone had to invent a word for that.Microsoft's AI chief said AI would automate most white-collar work, then clarified he meant 'tasks'  and that one-word swap changes everything.Meta dropped $14 billion on AI talent, shipped its first proprietary model, and is now discovering that building the thing and selling the thing are completely different jobs.A UK police officer allegedly used AI to fabricate evidence, and this isn't the first time British law enforcement has had an AI problem.Pokémon Go players spent years scanning the world for virtual creatures, and that data is now helping real drones navigate without GPS.This has been a week where the gap between what AI promises and what AI actually delivers has become very interesting to look at from the factory floor to the courtroom to the battlefield. Some stories are alarming. Some are clarifying. A few are genuinely strange. Let's get recognized.Find the full transcript to this podcast here.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - June 13, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later Jun 13, 2026 5:16


In this week's update, we examine the violent protests and riots that erupted across the United Kingdom following the arrest of a Sudanese asylum seeker for an attempted beheading in Belfast. Similar anti-immigrant demonstrations flared in London and Glasgow, while the US Embassy in London issued a security alert warning of continued rioting over the following days. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 294. Deep Dive. Headache and the AI Privacy and Security Weekly Update for the Week Ending June 9th. 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 11, 2026 40:18


This week we highlight the dual-natured impact of artificial intelligence on global security, privacy, and administrative productivity. On the defensive side, tools like Google's Gemini are blocking billions of fraudulent ads, while the NHS is deploying Microsoft Copilot to drastically reduce clinical paperwork. Conversely, bad actors are leveraging AI-driven phishing to compromise digital assets and developing adaptive malware that can reason through system defenses. Serious privacy concerns also emerge, evidenced by Meta's controversial development of facial recognition for smart glasses and the misuse of automated license plate readers by law enforcement. Additionally, the reports detail how nation-state actors use professional networks like LinkedIn for espionage and how criminals exploit autonomous transit for physical crimes. Ultimately, the collection suggests that as AI becomes a central pillar of modern life, the most critical security skill is the ability to verify identity in an increasingly deceptive digital landscape.

IT Privacy and Security Weekly update.
Headaches and the AI Privacy and Security Weekly Update for the Week Ending June 9th. 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 10, 2026 22:17


In this week's update:The NHS is about to hand half a million clinicians an AI assistant for their paperwork - and the question isn't whether it will work, it's whether healthcare will ever look the same again.An innocent man spent a month behind bars because an AI license plate reader put him in two places at once - and the cameras that could have cleared him were right there the whole time.China's military intelligence services have quietly turned LinkedIn into a recruitment tool, and the side gig that seemed too good to be true may be the most expensive mistake of your career.Anthropic spent a year watching how criminals actually use AI, and what they found is less about catastrophe and more about something far more unsettling: amplification.Researchers just demonstrated an AI-powered worm that doesn't just exploit weaknesses - it reasons, adapts, and chooses its own attack path in real time.Meta removed a facial recognition system from its smart glasses app this week - a system that, according to Meta, did not yet exist.A San Francisco burglar used a Waymo robotaxi as a getaway car, and between deleted footage and blurred faces, the case is still wide open months later.Hidden inside the GPS signal that guides every phone, every ship, and every missile on the planet, a researcher just found something the military has been quietly broadcasting for nearly two decades.Welcome back, everyone. This week, we are taking you from a British hospital corridor to a San Diego courtroom, from LinkedIn's shadowy recruitment pipeline to the hidden depths of a GPS signal that billions of people use every single day. Buckle up - this one covers the full spectrum, from the bureaucratic to the alarming to the genuinely mind-bending. Find the full transcript to this podcast here.

AlertsUSA Homeland Security Weekly Update
AlertsUSA Homeland Security Weekly Update - June 1, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later Jun 6, 2026 6:46


In this week's update, we examine the high-stakes launch of the 2026 FIFA World Cup this coming week in Mexico City and Guadalajara, where Mexican authorities have deployed nearly 100,000 security personnel amid U.S. State Department travel warnings for crime, terrorism, and cartel-linked violence in Jalisco. We also break down the troubling new Kaspersky wardriving study exposing widespread insecure public Wi-Fi networks around the venues — and the persistent lone-offender and jihadist threats that will follow the tournament into the United States for Saturday's SoFi Stadium opener. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

Paul's Security Weekly
Scaling to $100M as the Security Weekly Index Hits an All Time High - Joshua Gould - BSW #450

Paul's Security Weekly

Play Episode Listen Later Jun 3, 2026 53:01


The ultimate goal, scale a company to $100M and go IPO. Easier said than done. We've seen some make it and others that get stuck. What's he difference? Joshua Gould, CEO at thebigword, joins Business Security Weekly to discuss how to scale to $100M. From startup to platform, Joshua helps us understand the challenges and how to address them. If you're a founder looking to scale, this is an interview you can't miss. Segment Resources: https://en-gb.thebigword.com/ http://www.youtube.com/@Exec_Craft https://www.linkedin.com/in/joshuadgould/ In the Security Money segment, the Security Weekly Index and NASDAQ set new records. After CyberArk's acquisition, the Security Weekly Index is now comprised of the following 24 companies: SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-450

ceo hits scaling easier ipo index nasdaq 100m gould security weekly segment resources business security weekly
Paul's Security Weekly TV
Scaling to $100M as the Security Weekly Index Hits an All Time High - Joshua Gould - BSW #450

Paul's Security Weekly TV

Play Episode Listen Later Jun 3, 2026 53:01


The ultimate goal, scale a company to $100M and go IPO. Easier said than done. We've seen some make it and others that get stuck. What's he difference? Joshua Gould, CEO at thebigword, joins Business Security Weekly to discuss how to scale to $100M. From startup to platform, Joshua helps us understand the challenges and how to address them. If you're a founder looking to scale, this is an interview you can't miss. Segment Resources: https://en-gb.thebigword.com/ http://www.youtube.com/@Exec_Craft https://www.linkedin.com/in/joshuadgould/ In the Security Money segment, the Security Weekly Index and NASDAQ set new records. After CyberArk's acquisition, the Security Weekly Index is now comprised of the following 24 companies: SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc Show Notes: https://securityweekly.com/bsw-450

ceo hits scaling easier ipo index nasdaq 100m gould security weekly segment resources business security weekly
Business Security Weekly (Audio)
Scaling to $100M as the Security Weekly Index Hits an All Time High - Joshua Gould - BSW #450

Business Security Weekly (Audio)

Play Episode Listen Later Jun 3, 2026 53:01


The ultimate goal, scale a company to $100M and go IPO. Easier said than done. We've seen some make it and others that get stuck. What's he difference? Joshua Gould, CEO at thebigword, joins Business Security Weekly to discuss how to scale to $100M. From startup to platform, Joshua helps us understand the challenges and how to address them. If you're a founder looking to scale, this is an interview you can't miss. Segment Resources: https://en-gb.thebigword.com/ http://www.youtube.com/@Exec_Craft https://www.linkedin.com/in/joshuadgould/ In the Security Money segment, the Security Weekly Index and NASDAQ set new records. After CyberArk's acquisition, the Security Weekly Index is now comprised of the following 24 companies: SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-450

ceo hits scaling easier ipo index nasdaq 100m gould security weekly segment resources business security weekly
IT Privacy and Security Weekly update.
Ep 294. Deep Dive. Bedtime and the A.I., Privacy, and Security Weekly Update for the Week ending June 2nd., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 3, 2026 35:14


This deep dive explores the evolving landscape of artificial intelligence and its profound impact on global cybersecurity and infrastructure. Sources detail the dual nature of AI, highlighting its ability to uncover thousands of software vulnerabilities while simultaneously creating new risks through manipulated support bots and accelerated exploitation timelines. Beyond software, the text addresses physical security threats to undersea data cables and the potential repurposing of Cold War-era plutonium for private energy startups. Technical breakthroughs like certified quantum randomness and new browser-based spying techniques underscore a shifting digital perimeter where traditional trust models are failing. Furthermore, the economic reality of this shift is visible in Anthropic's massive valuation, new usage-based AI pricing, and the unexpected role of remote work in sidelining junior talent. These developments suggest a future where automated containment and government oversight are becoming essential responses to the speed of algorithmic threats.

IT Privacy and Security Weekly update.
Bedtime and the A.I., Privacy, and Security Weekly Update for the Week ending June 2nd., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 3, 2026 23:37


Episode 294. For this week's update:The Trust Problem Nobody Has Solved. The AI verification problem isn't a bug to be patched; it's a structural flaw baked into the architecture of trust itself.  It's like asking a child to set their own bed time.Forget cookies and trackers, a website can now read your entire digital life from the rhythm of your hard drive.Meta's AI support bot did exactly what it was designed to do, and that turned out to be the problem.While the security world chases sophisticated threats, Google quietly closed one of the oldest and most exploited doors in session management.ETH Zurich researchers have done something cryptographers have wanted for decades produced randomness that the laws of physics themselves will guarantee forever.The generation entering the workforce during the remote-work era may be carrying a career penalty they didn't earn and can't yet see.The Software Industry Exhales  For Now. Wall Street spent a year writing software's obituary, and this month the patient sat up, ordered lunch, and posted its best returns since the dot-com era.GitHub just handed its most enthusiastic AI users their first real bill, and for many, the number is somewhere between shocking and career-defining.OK, let's tuck in!Find the full transcript to this podcast here.

Business Security Weekly (Video)
Scaling to $100M as the Security Weekly Index Hits an All Time High - Joshua Gould - BSW #450

Business Security Weekly (Video)

Play Episode Listen Later Jun 3, 2026 53:01


The ultimate goal, scale a company to $100M and go IPO. Easier said than done. We've seen some make it and others that get stuck. What's he difference? Joshua Gould, CEO at thebigword, joins Business Security Weekly to discuss how to scale to $100M. From startup to platform, Joshua helps us understand the challenges and how to address them. If you're a founder looking to scale, this is an interview you can't miss. Segment Resources: https://en-gb.thebigword.com/ http://www.youtube.com/@Exec_Craft https://www.linkedin.com/in/joshuadgould/ In the Security Money segment, the Security Weekly Index and NASDAQ set new records. After CyberArk's acquisition, the Security Weekly Index is now comprised of the following 24 companies: SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc Show Notes: https://securityweekly.com/bsw-450

ceo hits scaling easier ipo index nasdaq 100m gould security weekly segment resources business security weekly
AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - May 30, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later May 30, 2026 8:21


In this week's update, we examine the sharp escalation of coordinated violent protests outside U.S. Immigration and Customs Enforcement facilities. We also dive into the unprecedented security effort underway for the 2026 FIFA World Cup opening June 12 in the United States, as DHS declares an “extremely high” threat level from active jihadist mass-casualty plotting, sophisticated drone attacks, Iranian proxies, Mexican cartels, and ANTIFA networks intent on exploiting soft targets during the global event. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
Episode 293. Deep Dive. Movies, Music, and the AI, Privacy and Security Weekly Update for May 26th 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later May 27, 2026 36:27


The corporate attack surface is expanding as autonomous AI agents and developer tools dissolve traditional security boundaries. The software supply chain is now a strategic vulnerability, allowing compromised “trusted tools” to bypass legacy defenses and move directly into internal environments.Recent incidents demonstrate the scale of the risk. GitHub confirmed unauthorized access to roughly 3,800 repositories after a malicious VS Code extension compromised a developer device. Google Cloud infrastructure also exposed a critical “time-to-vulnerability” gap: deleted API keys remained active for an average of 16 minutes, and in some cases up to 23 minutes, despite appearing revoked in the UI. These delays create exploitable windows for autonomous systems to access AI services or sensitive data before responders can intervene.The Cloud Security Alliance warns of an emerging “agentic threat” driven by excessive privileges, weak configurations, prompt injection, poor accountability, and flaws in machine-to-machine interaction. The challenge is no longer simply malicious code, but malicious intent expressed through natural language.Meanwhile, the labor market reflects a “low hire, low fire” reality rather than mass AI unemployment. Layoffs remain historically normal, but hiring and career mobility have slowed as firms adopt leaner operating models and assess automation's long-term impact. Entry-level opportunities are narrowing as companies demand higher productivity from fewer employees using generative tools.Industry leaders remain divided. Steve Wozniak argues AI cannot replace human creativity, while figures such as Sam Altman and Elon Musk warn disruption may eventually require interventions like Universal Basic Income. Many firms are also using “AI transformation” narratives to justify restructuring and post-pandemic cost corrections.Creative industries are shifting from resisting AI to monetizing it. The AI-generated film Hell Grind reportedly required a $500,000 budget, with most costs tied to compute power. Maintaining visual consistency demanded prompts averaging 3,000 words, revealing that AI production remains management-intensive rather than effortless. Spotify and Universal Music Group are also developing licensing frameworks where artists retain control over AI-generated remixes while platforms monetize premium AI creative tools.Technology companies now face growing friction between rapid AI deployment and user trust. Google's “disregard” search glitch showed how AI systems can misinterpret user queries as commands, undermining reliability. Apple's roadmap, including context-aware Siri capabilities and private cloud compute, highlights the industry's push toward personalized assistants.Ultimately, AI adoption depends on trust. Consumers will embrace assistants only if companies prove the infrastructure behind them is reliable, accountable, and secure enough to protect personal data.

IT Privacy and Security Weekly update.
Movies, Music, and the AI, Privacy, and Security Weekly Update for the Week ending May 26th, 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later May 27, 2026 21:13


Episode 293 A two-week shoot, a half-million dollar budget, and not a single human behind the camera, welcome to the future of Hollywood.This year at Cannes, the most talked-about presence on the Croisette wasn't a movie star; it was artificial intelligence.The Cloud Security Alliance is sounding the alarm on a new breed of AI system that doesn't just answer questions, it takes action, on its own, across your entire digital infrastructure.GitHub just confirmed that roughly 3,800 internal repositories were compromised, and the attacker didn't need a zero-day exploit, just a poisoned developer tool your engineers trust every single day.Google API Keys: Here's a question every incident responder needs to answer: if you delete a compromised credential and the attacker keeps using it for the next twenty-three minutes, did you actually stop the breach?The same AI technology making phishing attacks more convincing may also be our best shot at catching them, and this week, a listener's inbox put that to the test.Spotify and Universal Music Group just agreed to let fans remix their favorite songs using AI, and for the music industry, it's the clearest sign yet that the question is no longer whether this happens, but who controls it when it does.In a spring full of AI doomsday commencement speeches, Steve Wozniak walked onto a stage in Michigan and reminded a room full of nervous graduates that they already carry the most powerful intelligence in the room.Welcome back, everyone. We're glad you're here for Episode 293 of the AI, Privacy, and Security Weekly Update. It's May 26th, 2026, and this week we are going big. We're starting in Cannes, we're going to swing through some genuinely alarming security stories, and we're going to land somewhere a little more hopeful at the end. Let's get into it.Find the transcript to this podcast here.

IT Privacy and Security Weekly update.
Leaks and the AI, Privacy, and Security Weekly Update for the Week Ending May 19th., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later May 20, 2026 19:52


EP 292. This week we kick off with a flood of updates: The agency trusted to protect America's critical infrastructure couldn't protect its own credentials.Canada is reopening one of tech's most consequential debates  and this time, your compliance architecture may be in the crosshairs.A researcher's very public falling-out with Microsoft is quietly becoming everyone's security problem.What once took a seasoned red team weeks now takes a small team and a frontier model less than five days.The race to use AI to find flaws faster than attackers is officially underway  and the audit trail question is already lagging behind.AI is flooding the Linux kernel security pipeline with noise, and Linus Torvalds has had enough.Regulators are quietly deploying AI surveillance at a scale that reframes what financial oversight even means.The world's most consequential digital chokepoint just became even more of a geopolitical bargaining chip.Let's go get soaked!Find the full transcript to this podcast here.

IT Privacy and Security Weekly update.
EP 292. Deep Dive. Leaks and the AI, Privacy, Security Weekly Update for the Week Ending May 19th., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later May 20, 2026 47:09


This update highlights a deteriorating security landscape where human error and advanced technology intersect to create significant digital risks. Critical infrastructure faces threats from sensitive credential leaks at federal agencies and the discovery of unpatched Windows zero-day exploits released by disgruntled researchers. Simultaneously, the rise of artificial intelligence is transforming both offense and defense, enabling experts to bypass modern hardware security in record time while overwhelming open-source maintainers with automated bug reports. Governments are responding by expanding surveillance capabilities, seeking nationwide access to vehicle tracking data and using AI to police financial markets. Meanwhile, geopolitical tensions have shifted toward digital choke points, with nations like Iran threatening the physical cables that underpin global internet connectivity. These shifts occur alongside corporate instability, evidenced by mass layoffs at Meta and legal friction between major tech partners over AI integration.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - May 16, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later May 16, 2026 6:41


In this week's update, we examine the discovery of an improvised explosive device planted at the base of an Alabama dam, a direct and serious assault on the primary drinking water supply for roughly 350,000 residents of the Mobile metropolitan area. The incident exposes glaring physical security failures at a federally designated critical infrastructure site and reframes the conversation around U.S. dams, reservoirs, and water systems as immediate national security vulnerabilities. We break down the discovery, the unprecedented threat assessment by utility officials, and the accelerating pattern of both physical sabotage and nation-state cyber attacks on water, energy, and other critical infrastructure documented throughout 2025 and 2026. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 291. Deep Dive. Unintended Outcome and the AI, Privacy, and Security Weekly Update for the Week Ending May 12th., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later May 13, 2026 52:57


This week we highlight the multifaceted global impact of AI infrastructure and digital security, focusing on the physical and financial costs of technological expansion. Reports detail how massive data centers are straining public utilities, causing power disputes in Kenya and Maryland while leading to significant water waste in Georgia. In the realm of cybersecurity, researchers have identified critical vulnerabilities in smart home devices and "zero-day" exploits developed by artificial intelligence, prompting tech giants like Google and Apple to implement stricter protections. Meanwhile, the professional landscape is shifting as Amazon and Nvidia emphasize AI-driven metrics and proprietary software ecosystems, creating new pressures for employees and developers alike. Collectively, these narratives illustrate that while AI offers advancements in molecule design and medical research, its integration into daily life demands greater transparency and more robust infrastructure management.

IT Privacy and Security Weekly update.
Unintended Outcome and the AI, Privacy, and Security Weekly Update for the Week Ending May 12th., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later May 13, 2026 18:51


EP 291.  In this week's update:When a 200-pound internet-connected machine can be hijacked from 6,000 miles away, the smart home has officially become a liability.The moment security researchers have long anticipated has arrived: AI is no longer just defending systems - it's actively being used to break them.The same open ecosystems that accelerated AI adoption are now emerging as a significant and underestimated vector for supply chain attacks.In a landscape where breaches are inevitable, DigiCert's handling of a code-signing compromise offers a rare and instructive model for what accountability actually looks like.A browser trusted with your most sensitive credentials is quietly leaving them exposed in memory - and the vendor considers it working as intended.Google is embedding fraud detection directly into the operating system, signaling a fundamental shift in where the mobile security perimeter now begins.After years of a fragmented messaging security landscape, Apple and Google have closed one of the most glaring cross-platform encryption gaps in consumer technology.Decades of observational data linking coffee to longevity may finally have a molecular foundation - and it has nothing to do with caffeine.Let's go grab a mug!Find all links and the full transcript for this podcast here.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - May 9, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later May 9, 2026 8:01


In this week's update, we examine the Trump administration's new 2026 U.S. Counterterrorism Strategy — a sharp and decisive break from the politicized priorities that dominated the Biden years. The document reframes terrorism as a practical threat to American sovereignty, public order, infrastructure, and civil stability rather than a sociological or ideological problem to be managed through broad domestic monitoring programs. This is not another exercise in bureaucratic caution or political correctness; it is a return to hard-power counterterrorism doctrine and the protection of American citizens first. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
Episode 290. Deep Dive. Assumed Safe. The AI, Privacy, and Security Weekly Update for the Week Ending May 5th, 2026.

IT Privacy and Security Weekly update.

Play Episode Listen Later May 7, 2026 70:23


This Deep dive dives into the dangerous shift in the digital landscape where sophisticated exploits and simple human deception frequently converge. Major security alerts include a long-standing Linux kernel flaw that grants full system control and the rise of automated AI phishing kits that make high-level cyberattacks more accessible to criminals. Beyond technical bugs, the sources detail how identity theft is being used to systematically defraud financial institutions and how public voter records are being weaponized to expose personal information. Regulatory bodies are pushing back against these trends, evidenced by the FTC's crackdown on data brokers and new international guidance for the safe deployment of agentic AI. Meanwhile, the reports suggest that modern ransomware is evolving to bypass traditional encryption, focusing instead on pure data extortion and credential abuse. Ultimately, these sources emphasize that internal system integrity and strict identity verification are now more critical than traditional perimeter defenses.Find more here

IT Privacy and Security Weekly update.
Assumed Safe. The AI, Privacy, and Security Weekly Update for the Week Ending May 5th, 2026.

IT Privacy and Security Weekly update.

Play Episode Listen Later May 6, 2026 22:26


Episode 290. This week, we assume nothing in our collection of stories...A flaw hiding in plain sight for nearly a decade has quietly turned every Linux system's most trusted layer into an open door.Attackers have discovered that the easiest way to install malware is to convince users the malware is the cure.A new phishing kit is lowering the barrier to industrial-scale credential theft to roughly the cost of a Netflix subscription. Ransomware didn't slow down in Q1 2026  it mutated, and the new strain doesn't even need encryption to extort you.Credit Union Loan Fraud The most methodical fraud playbook circulating underground right now doesn't involve a single line of malicious code.A teenager with a forum alias just handed a third of France's population an identity problem they didn't ask for.Six of the world's most serious cybersecurity agencies just issued a unified warning that most organizations deploying agentic AI are not ready for what they've built.A new paper argues that the discipline meant to stress-test AI safety has itself become the thing it was designed to find a vulnerability dressed up as a control.The arc runs from infrastructure to brand to process to institution to the security function itself. Each story is a different flavor of the same failure: someone trusted something they shouldn't have, or built a system that assumed others would.Let's go verify!Find the full transcript to this podcast here.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - May 2, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later May 2, 2026 7:46


In this week's update, we examine the UK's Joint Terrorism Analysis Centre raising the national terrorism threat level from SUBSTANTIAL to SEVERE, following a vicious antisemitic stabbing in London's Golders Green Jewish community. The US Embassy in London followed up with a security alert for Americans in the country. We break down the attack, Ashab al-Yamin's first claim of responsibility for lethal strikes on individuals rather than property, and the escalation of this Iranian proxy front's sustained low-tech terror campaign. This is not random street crime; it is state-sponsored Islamist proxy warfare, with Tehran outsourcing violence to radicalized cutouts. The campaign is active, ongoing, and now more lethal—copycats and further escalation are expected. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 289. Deep Dive.. Everything looked fine. The A.I., Privacy and Security Weekly update for the week ending April 27th 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Apr 30, 2026 30:45


Warren Buffett once said it's only when the tide goes out that you discover who's been swimming naked. This week, the tide went out on several fronts simultaneously, and what it revealed was uncomfortable, instructive, and in some cases, long overdue.France opened the week with a breach that should trouble every government running centralised identity infrastructure. Up to 19 million records tied to passports, ID cards, and driver's licenses are now circulating on criminal forums. What makes this worse than a typical data leak is the context: a similar dataset from the same agency surfaced in 2025. This wasn't a surprise attack on a hardened target. It was a recurring failure wearing the face of a solved problem.The Bitwarden supply chain story carried a similar energy. No vaults were cracked, no passwords were stolen, and most users never noticed a thing. But a malicious package briefly moved through npm as part of the Checkmarx campaign, targeting the developers who build the software everyone else depends on. The lesson isn't technical — it's structural. Your security posture now extends to every build pipeline, every dependency, and every automation script upstream of your product.Then came FAST16.SYS, and the week shifted into something darker. This rootkit, which appears to predate Stuxnet, didn't steal data or trigger alarms. It quietly altered precision calculations in memory while leaving every file on disk untouched. Systems looked healthy. Outputs looked reasonable. The only thing wrong was the answer. It is the most patient form of sabotage imaginable, and it reframes what advanced threats are actually capable of when detection, not damage, is the real objective.AI brought its own escalation this week. Researchers are now using AI systems to attack other AI systems at machine speed — probing, learning, and refining exploits far faster than any human team. At the same time, agent browsers like Interceptor are quietly repositioning the browser itself as an autonomous actor, raising legitimate questions about oversight when software is doing the clicking, typing, and deciding on your behalf.Anthropic's Mythos model access story tied several threads together neatly. Contractor credentials, open-source reconnaissance, and data exposed in a third-party breach combined to give a small group access to a restricted model. The intent was curiosity, not sabotage — but the mechanism was a textbook illustration of how third-party access chains create exposure that principal organisations rarely see coming.Apple closed out the privacy section with a rare win, patching a logging bug that had been silently retaining Signal message fragments for up to a month — long after deletion, long after the app was removed. The FBI had already used it in court. The patch is clean and the fix is automatic, but the episode is a pointed reminder that ephemeral and permanent are closer together than most people assume.The week closed on strategy. OpenAI and Microsoft have restructured their foundational partnership, removing exclusivity and capping revenue payments. The AI infrastructure layer is becoming contested ground, and this deal confirms that no single partnership, however dominant it once appeared, is permanent.This week's stories didn't shout. They accumulated. And that, more than anything, is the point.

IT Privacy and Security Weekly update.
Everything looked fine. The A.I., Privacy, and Security Weekly update for the week ending April 27th 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Apr 29, 2026 18:33


EP 289. Let's climb to the top of this week's stories:France's most trusted identity infrastructure has become its biggest liability, and nineteen million citizens are now paying the price.The real lesson from Bitwarden's close call isn't about passwords it's about how quietly an attack can move through the software you never see being built.A newly uncovered rootkit predating Stuxnet has rewritten what we thought we knew about state-level sabotage and its most dangerous feature was making everything look perfectly normal.The arms race in AI security has hit a new threshold machines are now the ones probing for weaknesses, and they don't need sleep to do it.The browser is no longer just a window to the web it's becoming an autonomous actor, and that changes everything about who's actually in control.A restricted AI model, a contractor's borrowed credentials, and a private Discord channel Anthropic's Mythos access story is a case study in how third-party trust becomes a front door.A logging bug quietly turned one of the world's most trusted encrypted messaging apps into an inadvertent evidence locker and it took an FBI courtroom testimony to bring it to light.OpenAI and Microsoft have redrawn the map of AI's most consequential partnership, and the shift from exclusivity to optionality signals a new phase in who controls the infrastructure layer.Tighten your shoelaces, and let's get to the bottom of this.Find this week's transcript here.

AlertsUSA Homeland Security Weekly Update
Homeland Security Weekly Update - April 18, 2026

AlertsUSA Homeland Security Weekly Update

Play Episode Listen Later Apr 25, 2026 6:31


In this week's update, we look into the U.S. Embassy in London's urgent security alert warning American citizens of attacks and threats targeting Jewish and American institutions across the UK and Europe. We break down the cluster of linked arson strikes on synagogues, ambulances, and community sites in London, the emergence of the Iranian proxy front Ashab al-Yamin, and Tehran's textbook playbook of outsourcing low-tech terror to cutouts for deniability. This is not random street crime; it is state-sponsored Islamist proxy warfare. The campaign is active, ongoing, and expanding—copycats and escalation are expected. Stay frosty. An expanded written version of this report can be found in this week's Threat Journal newsletter. You can subscribe for free by visiting www.ThreatJournal.com. A link to this issue will be sent to you immediately via email. AlertsUSA Homepage http://www.AlertsUSA.com – (Homeland Security Alerts for Mobile Devices) AlertsUSA on Facebook https://www.facebook.com/alertsusa AlertsUSA on Twitter https://twitter.com/alertsusa Threat Journal on Twitter https://twitter.com/threatjournal Threat Journal Homepage https://www.ThreatJournal.com

IT Privacy and Security Weekly update.
EP 288.5 Deep Dive. No Privacy, but the AI, Privacy and Security Weekly Update for the Week ending April 21st. 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Apr 23, 2026 48:26


This Deep Dive highlights the evolving landscape of digital threats, ranging from deceptive browser extensions and AI vulnerabilities to state-sponsored surveillance and blockchain exploits. The text is structured as a series of case studies and news alerts that emphasize how modern risks often stem from social engineering and automated scanning rather than purely technical flaws. A recurring theme is the trade-off between convenience and security, illustrating how everyday tools like WordPress plugins or AI coding assistants can be weaponized for data harvesting. Ultimately, the source serves as a strategic warning for users and organizations, arguing that robust defense requires constant vigilance against the invisible vulnerabilities embedded in global digital infrastructure.

IT Privacy and Security Weekly update.
No Privacy, but the AI, Privacy and Security Weekly Update for the Week ending April 21st. 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Apr 22, 2026 18:21


EP 288. No privacy, but so much is going on that you might not notice for the next 20 minutes. We start with…A senator who has been right before is raising alarms he cannot fully explain, and that pattern alone should command attention. Traveling with a locked phone just became a legal liability in one of the world's most-visited financial hubs. A hundred thousand users thought they were downloading videos; they were handing over their digital fingerprints.That free app may be paying for itself in ways you never agreed to and will never see on a receipt.North Korea's most prolific hacking group has refined its macOS playbook down to a single terminal command and a moment of misplaced trust.A six-figure plugin acquisition quietly became an eight-month undetected supply chain attack hiding in plain sight.The promise of building software in minutes is colliding with a harder truth: speed without security discipline is just a faster way to expose your users.The same government arguing in court that an AI model is a national security threat is quietly using it to scan its own networks.Let's take a peek…Find the full transcript to this podcast here.

IT Privacy and Security Weekly update.
Episode 287.5. Deep Dive. Taxing. The AI, Privacy, and Security Weekly Update for the Week ending April 14th 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Apr 16, 2026 37:22


Cybersecurity is entering an “invisibility crisis,” where threats are no longer loud, external attacks but subtle abuses of normal system behavior. Techniques like SockStress exploit TCP assumptions to drain resources, residential proxy networks turn everyday users into unwitting infrastructure, and fake VPNs weaponize trust to exfiltrate data. Even ransomware response processes are being hijacked, transforming incident response into an attack surface. At the same time, transparency mechanisms are failing—Google, Meta, and Microsoft frequently ignore user opt-outs—highlighting a systemic breakdown in consent and accelerating calls for digital sovereignty.This shift feeds directly into geopolitics. Nations increasingly view reliance on foreign technology as a strategic risk, pushing “digital sovereignty” agendas. France, for example, is migrating government systems to domestic or open-source alternatives like Linux and Jitsi, and relocating sensitive health data infrastructure. Meanwhile, advanced AI proliferation introduces a paradox: companies restrict powerful models to prevent misuse, yet real-world breaches—such as the Tianjin Supercomputer incident, where attackers exfiltrated 10 petabytes via a compromised VPN—demonstrate how stealthy, persistent threats can evade detection at scale.Critical infrastructure remains especially vulnerable. Iran-linked actors have targeted industrial control systems (PLCs), showing how cyber intrusions can translate into physical manipulation. The message is clear: internet-connected industrial systems must adopt stronger controls, including multifactor authentication and continuous monitoring, particularly across energy and water sectors.Alongside these risks, the workforce itself is transforming. AI is shifting human roles from execution to oversight—people increasingly “direct” rather than “do.” However, this creates a paradox: while AI boosts productivity, it also increases complexity, oversight demands, and cognitive load. Managers now supervise fleets of AI agents, and professionals often refine AI outputs instead of producing original work. Despite widespread tech layoffs, judgment, accountability, and problem framing are becoming the most valuable—and scarce—skills.The broader theme is one of diminishing visibility and control. Whether in cybersecurity, geopolitics, or labor, systems are becoming more opaque, automated, and interdependent. Even efforts to uncover foundational truths—like identifying Satoshi Nakamoto—remain inconclusive despite advanced analysis. In this environment, the key differentiator is no longer technical capability alone, but human judgment: the ability to question assumptions, verify continuously, and navigate a world where the greatest risks are hidden in plain sight.

IT Privacy and Security Weekly update.
Taxing. The AI, Privacy, and Security Weekly Update for the Week ending April 14th 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Apr 15, 2026 22:41


Episode 287. On the day before the tax deadline in the US, we've got the most taxing update yet, full of unexpected deductions:OpenAI has unveiled bold policy recommendations to cushion the societal impact of advanced AI, including robot taxes, a public wealth fund, and trials of a four-day workweek.  Add in cake for all, and we'd swear Marie Antoinette was running the company.As AI assumes more decision-making roles, human work is evolving from task execution to high-level direction, judgment, and problem framing. Hopefully, there's still time to talk to your school's guidance counselor about changing your major.Professionals are now building personal “AI teams” of multiple specialized agents, dramatically expanding individual capacity while reshaping workloads and expectations.Citing potential misuse risks, OpenAI is restricting access to its most powerful new cybersecurity model, following a cautious approach already adopted by Anthropic.  “It's so good you can't have it.”A hacker group known as “FlamingChina” claims to have exfiltrated over 10 petabytes of sensitive data from China's National Supercomputing Center in Tianjin in one of the largest breaches on record.Iran-linked hackers have reportedly disrupted critical operational systems at U.S. oil, gas, and water facilities, in a demonstration of “You hit us, we hit you.”A new independent audit reveals that Google, Microsoft, and Meta shockingly continue tracking users even after privacy opt-out signals are enabled.The New York Times has published a detailed investigation naming British cryptographer Adam Back as the strongest circumstantial candidate yet to be Bitcoin's mysterious creator, Satoshi Nakamoto.  Quick, now's the time to get really friendly with Adam.And just like filing taxes, the sooner we get to it, the sooner we get our refund!  Let's go!

IT Privacy and Security Weekly update.
Episode 285.5 Deep Dive. Patience and the AI, Privacy, and Security Weekly Update for the Week Ending March 31st., 2026

IT Privacy and Security Weekly update.

Play Episode Listen Later Apr 2, 2026 44:39


The Deep Dive for Episode 285.5 explores how patience has become a defining weapon in modern AI, privacy, and security threats. State-backed actors like Red Menshen are quietly compromising telecom infrastructure with stealthy kernel-level implants, turning networks into long-term surveillance platforms while remaining almost invisible. Social engineering is evolving too: campaigns like ClickFix prove that attackers no longer need exotic exploits when they can simply coach users into pasting malicious commands themselves. At the same time, the AI software ecosystem is showing its fragility, as the LiteLLM supply-chain scare demonstrates how a single compromised package can ripple across countless downstream systems.On the frontier-model side, Anthropic's leaked “step change” system underscores how rapidly capabilities are accelerating while governance and operational controls struggle to keep pace. Research on AI essay grading highlights a similar misalignment, showing that LLM-based evaluators often reward surface polish over genuine understanding, raising serious concerns for any high-stakes use of automated assessment. Governments are moving to assert control: the US Department of Defense is driving AI vendors toward a single baseline that prioritizes military requirements, while China's latest Five‑Year Plan positions AI as an instrument of national power, emphasizing large-scale deployment, self-reliance, and ecosystem-level strategy. Finally, the Meta–Manus standoff illustrates how cross-border AI deals sit at the intersection of innovation, capital, and state control, turning corporate decisions into geopolitical flashpoints. Taken together, this episode illustrates that we are not just watching a tech race, but a slow, methodical restructuring of global power through technology, one that rewards deep security, thoughtful governance, and a healthy respect for the risks of quiet, patient adversaries.

Paul's Security Weekly
Firmware Backdoors Be Spying On You - PSW #914

Paul's Security Weekly

Play Episode Listen Later Feb 19, 2026 126:14


AI says that this is the show where we turn coffee into threat intelligence and cigar smoke into packet captures. This week: a firmware backdoor living its best life inside Android tablets a fresh BeyondTrust RCE that already has scanners circling like seagulls over a french fry. Lenovo Vantage reminds us that “preinstalled convenience” is just another way to spell “attack surface.” Texas is taking a swing at TP-Link supercomputers with a 20-year-old Munge bug that still has teeth. Your AI coding assistant might be quietly squirreling away secrets macOS gets a visit from an infostealer delivered as helpful add-ons Chrome extensions allegedly spy on millions open source maintainers drowning in AI-generated nonsense Windows flirting with smartphone-style permission prompts. Put your passwords in a vault, not in a repo, and stay tuned for Paul's Security Weekly! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-914

Paul's Security Weekly
Security Money: The Index and NASDAQ Diverge - BSW #435

Paul's Security Weekly

Play Episode Listen Later Feb 18, 2026 32:13


The Security Weekly 25 index and the NASDAQ diverge. Funding and acquisitions continue shift to AI. Are security stocks out of favor? Netskope enters the index, but does not replace CyberArk, as Thoma Bravo buys Verint. We'll dig into all of this and more! The index is now made up of the following 25 stocks: SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc CYBR Cyberark Software Ltd TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-435