POPULARITY
Categories
Skype of Cthulhu presents a Call of Cthulhu scenario. The Island by David Khoo. June, 1925 Lisboa, Portugal The investigators set sail, after being warned not tell any of the crew where they are headed. Dramatis Persone: Gary as the Keeper Meredith as Jose Fernandez, Reporter Jim as Professor Joao Pereira, Archeologist Steve as Natalie Greenwood, Archeologist Max as Bertram Arbuthnot Montgomery, Dilettante Download Subcription Options Podcast statistics
Send us Fan MailDavid Schwartz, CEO of PIA, challenges the notion of an impending “SaaS-pocalypse.” He argues that while AI capabilities like vibe coding allow users to build quick custom features, they do not replace full-scale Software-as-a-Service platforms. Developing and maintaining reliable enterprise software requires ongoing DevOps support, bug fixes, R&D, and strict adherence to security and compliance frameworks like SOC, HIPAA, and GDPR. For most businesses, attempting to build and maintain custom alternatives internally creates unsustainable overhead and introduces significant operational and security risks compared to established SaaS vendors.David also discusses his transition to leading PIA, an AI-driven help desk automation platform built by MSP veterans for the MSP market. Drawing from his background co-founding Wireless Watchdog and working in IT services, he explains how PIA addresses persistent labor challenges by automating level-one service desk tickets and streamlining repetitive workflows.See our 2025 interview with David: https://www.e-channelnews.com/update-interview-with-pias-new-ceo-david-schwartz/
Interview Highlights: A Layered Toolset: LSU runs dual EDR platforms (Microsoft Defender and CrowdStrike), Splunk as its SIEM for log management, and Splunk SOAR (via partner TekStream) to coordinate incident response across the statewide SOC program. Phishing Remains Enemy #1: Across higher ed generally, phishing is the top entry point for attackers; Jain recalled a pre-MFA, pre-COVID incident where compromised accounts cascaded across multiple universities, forcing account suspensions every five minutes. AI on the Email Front Line: LSU uses AI specifically to catch executive impersonation—fake emails posing as the chancellor or vendors like Dell requesting changed payment routing numbers—flagging them for review before delivery. On the SOC side, AI builds context around alerts (device mismatches, unusual IP patterns) that a human analyst then validates before escalating—keeping a human in the loop rather than fully automating decisions. Fighting AI With AI—Proactively: LSU deploys honeypots, like a dummy Moodle instance, to lure AI-driven attackers, capture their IPs and techniques, then feed that threat intelligence into production systems to auto-block similar attacks before they happen. The Real AI Risk Is Data, Not the Tool: Jain's biggest concern with staff using ChatGPT, Copilot, or Claude isn't the AI itself—it's uploading sensitive student, HR, or research data to platforms that may train on it. Louisiana state law bars public institutions from using Chinese-linked LLMs; Jain flagged that individual (non-Enterprise) Cursor licenses can violate this because some underlying models have Chinese ties. Building Homegrown AI Tools: LSU faculty built "MikeGPT," an internal GPT-based tool on Azure, letting departments create custom agents—like one that lets students query a syllabus directly or an in-progress agent that answers questions from an 80-90 page data governance policy. Both hosts agreed that narrow, tailored AI tools solving specific institutional pain points—rather than general chatbot use—represent the most valuable and lowest-risk way to bring AI into daily operations.
On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with John Hultquist, Chief Analyst at Google Threat Intelligence Group (ex-Mandiant, ex-FireEye, founder of CYBERWARCON & SLEUTHCON).Drawing on over two decades of tracking state-sponsored adversaries like Sandworm, John cuts through the hype to explain what modern threat intelligence actually does: it keeps CISOs from burning millions of dollars on the wrong technology, spots adversary shifts before static IOCs exist, and bridges the gap between raw binary reverse-engineering and executive decision-making.In this episode, John unpacks how threat actors are weaponizing AI and bypassing commercial costs entirely and traces the real shift underway: adversaries embedding adversarial prompt-injection payloads inside malware to shut down automated SOC scanners.What's Inside:1. The economics of illicit AI: Underground access vs. hijacked enterprise compute2. Malware poison pills designed to neutralize automated LLM triage3. Why firmware and ICS layers are becoming primary targets for disruption4. Behavioral detection models when living-off-the-land means zero usable IOCs5. Lessons from tracking Sandworm and convincing leadership to act before the lights go out
Skype of Cthulhu presents a Call of Cthulhu scenario. The Island by David Khoo. June, 1925 Lisboa, Portugal While preparing for the expedition, two members have a disquieting encounter with a fortune teller. Dramatis Persone: Gary as the Keeper Meredith as Jose Fernandez, Reporter Jim as Professor Joao Pereira, Archeologist Steve as Natalie Greenwood, Archeologist Max as Bertram Arbuthnot Montgomery, Dilettante Download Subcription Options Podcast statistics
Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-476
See what the team at The Successful Bookkeeper has on right now → If you have ever wondered what it actually looks like to build AI into your accounting practice — not in theory, but day-to-day — this episode is for you. Sam Leon, CPA and founder of TaxWeave, joined guest host Louie Prosperity to share exactly how he went from experimenting with ChatGPT to building his own secure AI platform for tax professionals. The conversation is practical, honest about the risks, and full of ideas you can act on right away. Chapters [00:00] Introduction and Sam's Background [02:45] Why Sam Chose Claude Over Others [06:30] Claude Code: Beyond Just Chatting [09:30] Workflow Automation for Bookkeepers [12:30] The Data Security Problem [16:30] Building TaxWeave as a Secure Platform [20:00] Top AI Tasks to Tackle First [24:00] Keeping Up as AI Models Evolve [26:30] How Sam Checks His AI Outputs [28:30] Where to Find Sam and TaxWeave Here's a special gift for YOU. Visit Plooto.com/TSB and try it for FREE for two months! That's a FREE 30-day trial, plus an extra free month for Successful Bookkeeper podcast listeners! Don't miss out, sign up TODAY! From Curiosity to Real Workflows Sam has been watching technology waves roll through the accounting profession for years — cryptocurrency, machine learning, practice management software. When AI chatbots arrived, he started testing them immediately, but it was a specific feature of Claude that changed how he worked: the ability to connect the tool directly to files on his computer. "That's how I got started with a lot of the more time-saving workflows that I was doing," he explains. The shift from chatting with AI to feeding it real documents opened the door to genuine time savings rather than novelty. The Tasks Best Suited for Automation Sam is direct about where AI earns its keep: document summarization, transaction categorization, and building QuickBooks rules. He recently spoke with a bookkeeper who used AI to generate an extensive list of transaction rules that could be imported straight into QuickBooks — a task that would have taken hours to build manually. His broader advice is to start with tasks that are data-heavy and repeatable, then layer AI on top of the tools you already use rather than replacing them outright. Handling Sensitive Data the Right Way This is where Sam slows down and gets careful, and so should you. For tax professionals in the US, IRS Code Section 7216 governs what client information can be shared with third-party systems — and most AI platforms have not yet been through the kind of SOC 2 certification process that established tax software has. Sam's personal rule: never upload anything containing Social Security numbers, EINs, or last names. For bookkeeping work, he sees a slightly lower barrier since transaction lists are often less personally identifying, but the principle holds. "Being more cautious than not — if you're unsure about it, probably take another step to make sure that information really doesn't have any personal identifying information on it." Upgrading to a Teams or Business plan on these platforms also adds a layer of data protection over personal accounts. Building TaxWeave: From Workaround to Platform The manual redaction problem — using Adobe to black out client details before running documents through AI — was slow and error-prone. That frustration pushed Sam to start building TaxWeave, a platform designed to handle the redaction automatically inside a secure environment, then run AI workflows on the cleaned documents. He built the initial prototype using Claude Code, which lets you describe what you want in plain language and generates the underlying code. "The barrier where you had to understand how to do that — it's removing that," he says. TaxWeave currently focuses on tax practice project management and client organization, with AI workflow integration being the layer built on top. Keeping Up as the Models Keep Changing AI models update constantly, and Sam's advice is to treat your workflows the same way you treat your engagement letters — review them periodically and adjust. He recommends using the Projects feature in Claude to maintain context across sessions, and revisiting your saved instructions whenever a new model version drops. You can even ask the AI itself what needs updating. For quality control, Sam still does his own research to verify AI-generated answers and checks outputs manually, paying attention over time to where the tool is weakest. "You can start to see what it's weaker on — what kind of things does it always miss — and what you can start trusting it with." Links Mentioned TaxWeave: taxweave.ai Sam Leon on LinkedIn: search Samuel Leon CPA Claude (Anthropic): claude.ai PureBookkeeping: purebookkeeping.com Pluto (sponsor): pluto.com/tsb About the Guest Sam Leon is a CPA with 14 years of experience in tax accounting, specializing in corporate tax, startup tax issues, R&D credits, and individual returns. After building his solo firm, The Millennial CPA, he was recognized in the 2026 Accounting Today Best Firms for Technology Awards. He is currently developing TaxWeave, an AI-powered platform built specifically for tax practices, and is active in conversations across the profession about safe, practical uses of AI in accounting.
Skype of Cthulhu presents a Call of Cthulhu scenario. The Second Coming by Randall Padilla. September 11, 3040 Somewhere near Neptune The crew of the spaceship Ludlow is on routine patrol when they receive a distress signal from a colony ship. Dramatis Persone: Jim as the Keeper of Arcane Lore Gary as Gary Hall, Engineer Rachel as Rachael Cheng, Biologist Ely as Jonathan Jackson, Astrophysicist Download Subcription Options Podcast statistics
Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-476
Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-476
Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Today, we sat down with leaders from Elastic and Google Distributed Cloud to discuss how their unique combination of skills can address cybersecurity, AI operations, and resilience in sovereign air-gapped environments. Most listeners hear the phrase "air-gapped" and think absolute safety. Sean MacKirdy from Elastic offers insight into air-gapped environments. He reminds the audience that, by definition, an air-gapped system cannot get updates from the Internet. That means they are vulnerable to attacks. Further, data transfers, cross-domain guards, patching cycles, supply chains, USB devices, and insiders remain potential entry points. Google's TJ Banasik's solution is to consolidate tools. For example, common tools include capabilities like endpoint detection, user behavior analytics, and vulnerability management. Elastic Security can be combined with Google Distributed Cloud. For example, Elastic uses specialized, self-managed platforms to provide unified security for air-gapped environments. This automation reduces fatigue, staffing requirements, response time, and integration complexity in a SOC. This interview provides a brief overview of the concepts discussed. For more details, please attend the Google Public Sector Summit on October 20, 2026, at the Reagan Center in Washington, DC. You'll see how Elastic and Google Distributed Cloud work together, with subject matter experts in the room with you. Federal agencies must consider how to protect air-gapped networks amid regulatory authorization, data sovereignty, and operational risk. That is why it is important to meet face-to-face with developers from Elastic and Google to determine the optimized solution for your agency. The Google Public Sector Summit presents the perfect opportunity to accomplish that task.
Interview Highlights: The Scale of LSU Security: Sumit Jan's 14-person team protects roughly 20,000 endpoints, 6,000 servers, and over 100,000 users across LSU's identity management, incident response, and ERP security. Unlike a single corporation, LSU functions like a multi-company organization—academics, research, athletics, and community relations all require different, case-by-case security approaches rather than one uniform policy. Goodbye Mainframe: LSU fully retired its legacy mainframe system in 2025, migrating student records, registration, and grades to Workday, alongside a parallel move to Okta for identity and access management just 30 days later. Shifting to SaaS platforms like Workday reduces institutional risk by providing built-in redundancy and backups, versus the fragility of aging on-campus legacy hardware. Born From the Ransomware Wave: A surge of ransomware attacks on higher-ed institutions nationally pushed LSU to partner with the Board of Regents and GOHSEP to build a shared Security Operations Center (SOC) model in 2022–2023. A Student-Powered SOC: LSU's SOC, run through LONI, now supports 34 public higher-ed institutions statewide, staffing students 8-to-5 while a private partner covers nights, weekends, and holidays. TigerSOC Expands the Model: A second SOC, TigerSOC, has LSU students working as subcontractors for Atlanta-based Techstream, gaining real-world experience securing casino, healthcare, and banking clients—complete with federal background checks where required. Strong Job Outcomes: Nearly all graduating SOC analyst students land security jobs at or before graduation, often earning more within a year or two than LSU can pay a starting analyst. Open to Any Major: Jan intentionally recruits beyond computer science, arguing critical thinking matters more than a technical background—psychology, sociology, and engineering majors all bring valuable cross-disciplinary perspective to security analysis.
Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-476
Podcast: ICS Cyber Talks PodcastEpisode: Adir Ben Hamo Director CISO @Phibro Animal Health on CISO's cyber & governance challenges & AI 2026Pub date: 2026-09-10Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationנסיון לחזור לשגרה (סוג של) בתקווה שימשיך.... חלפו למעלה מארבע שנים מאז הראיון הקודם שעשיתי עם אדיר, מאז העומס על הסיסו רק גדל בצורה אקספוננציאלית והצורך לקיים ממשל תאגידי בנושא סייבר הפך לחובה. הדבר נכון לגופים גדולים ובינלאומיים ולמעשה לכול ארגון באשר הוא, במקום שאין גידור סיכונים ולמשתמש הקצה אין גבולות ברורים והבנה הנושא של "טעות" הופכת לסיכון ארגוני בל ישוער. נחשון פינקו מארח את אדיר בן חמו דירקטור וסיסו גלובלי בחברת פיברו מוצרי בריאות לבעלי חיים על שילוב מערכות מידע ומערכות תפעוליות, שדרוג תשתיות ותוכנות בסביבת ייצור עלמנת לבנות מודל אחיד לפריסה העולמית. תהליכי ממשל ארגוני עבודה בסין מול רגולציות שונות מהמוכר והידוע של המערב חילופי דורות וכניסת דורות צעירים בצוותי התפעול מביאים איתם מודעות סייבר, רצון לשנות ולהשתפר בעזרת טכנולוגיות עדכניות ה SOC ככלי רב ערך וההבדל בין חברות בארה"ב וישראל ההיי. איי שמדיר שינה מעיניו של כול סיסוThe podcast and artwork embedded on this page are from Nachshon Pincu, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
En la entrevista del programa La Miel en tu radio conversamos con la Lic. Com. Soc. Sofia Tasat - SADA - Buenos Aires 12/09/2026. Quien nos comparte toda la información sobre el balance del Congreso FILAPI 2026.
AI is transforming cybersecurity, but securing AI systems is a unique challenge. In this full course session, InfosecTrain breaks down the core differences between securing with AI and securing AI itself. Discover AI/ML foundations, blue and red team defense tactics, MLOps, API security, and practical threat modeling techniques to future-proof your security career.The "course titled" Practical AI Security Engineering Program provides hands-on expertise to defend AI pipelines.
AZ TRT 2.0 – Best of Cybersecurity from Business to Government AZ TRT S07 EP14 (296) 9-6-2026 What We Learned This Week Cyber and CIO mgmt Common Cyber Issues TRM Labs on security ACTRA - Cyber threats affect everyone from Gov't to business to private & growing Clips from past shows focusing on Cybersecurity and threats to both business and Government. . Seg. 1 Clips from Related Shows: Cybersecurity, Disruption, Blockchain & Terrorism w Ari Redbord of TRM Labs - BRT S02 EP31 (78) 8-1-2021 What We Learned This Week Cybersecurity is extremely important industry for national security TRM Labs startup in cyber-security, monitors blockchain OFAC - Gov't administers economic and trade sanctions Ransomeware – specific breach, takeover of a computer system, holds data hostage Programatic Money Laundering – bad guys create new addresses, create 'shell' companies Guest: Ari Redbord, Head of Legal and Government Affairs w/ TRM Labs https://www.linkedin.com/in/ari-redbord-4054381b4/ https://www.trmlabs.com/post/trm-labs-appoints-ari-redbord-as-head-of-legal-government-affairs Ari is formerly a US Attorney, and worked in the Treasury Department, now advises the Government on cybersecurity, and Blockchain. Cybersecurity is a fast growing and extremely important industry for national security, and corporate interests. There are Nation States acting as bad players in the cyber realm and targeting the US Government and US business. We discuss the advancements in technology on cyber crime, blockchain, crypto, and online fraud. How is the FBI dealing with Ransomware, and other cyber attacks on prime targets like the Colonial Pipeline, or other big corps. What Regulations are coming in banking, and Fintech, with KYC (Know Your Customer), plus the big banks like JP Morgan Chase and Goldman are on board. What the blockchain ledger can help solve in security, to monitor criminal activity in real time with the help of crypto exchanges like Coinbase. Lastly, what TRM Labs does for clients, how they advise, operate, and who they work with. Full Show: HERE Phishing, Malware & Cybersecurity - Try Not to Get Pwned - BRT S02 EP47 (94) 11-21-2021 What We Learned This Week: Have I been Pwned? Means have I been breached / hacked – did someone hack my email or website Phishing – most common type of email threat, like when you receive a strange email with a link – Do Not Open – DELETE (and alert other office staff of the email) Ramsonware – hack your website, or data – hold it hostage for an extortion 'ransom' payment Dark Web – where stolen data, & info is being bought & sold VPN Connections – direct and secure Guests: Vince Matteo, Seven Layer Networks, Inc. https://sevenlayers.com/ Vince Matteo is a certified penetration tester, a security researcher, and a senior consultant at Seven Layers (.com) where he focuses on securing small businesses. Vince is the author of "Hacking 101 – A Beginner's Guide to Penetration Testing", he's a bug bounty hunter with 17 published critical vulnerabilities, and he's presented talks on offensive hacking at security conferences -- most recently GrrCON in Grand Rapids, MI and BSides in College Station, TX. Outside of work, Vince is an accomplished endurance athlete, an Ironman age group champion, and in his spare time, you can find him in the desert -- training for the next hundred-mile ultramarathon. Full Show: HERE Seg. 2 Cybersecurity Response Plan w/ Frank Grimmelmann of ACTRA - AZ TRT S06 EP03 (264) 2-9-2025 What We Learned This Week ACTRA Arizona Cyber Threat Response Alliance Cyber threats affect everyone from Gov't to business to private and growing Companies need to be responsive with speed to be effective + share information of attacks ACTRA has members from both government and private sector ACTRA helped create a state cybersecurity response model that other states can use Guest: Frank Grimmelmann https://www.actraaz.org/actra/leadership President & CEO/Intelligence Liaison Officer Mr. Grimmelmann also serves as Co-Chair (together with Arizona's Chief Information Security Officer) for the Arizona Cybersecurity Team ('ACT'), created through the Governor's Executive Order signed in March 2018. He also serves as a Founding Member of the National Leadership Group for the Information Sharing & Analysis Organization Standards Organization ('ISAO SO') at the University of Texas San Antonio (UTSA), created under the President's Executive Order 13691 in February 2015. As ACTRA's leader, Mr. Grimmelmann was invited as the first private sector representative in the Arizona Counter Terrorism Information Center (ACTIC) and served as its first private sector Executive Board representative from 2014-2019. He presently acts as ACTRA's designated private sector liaison to ACTRA's Key Agency and other non-Member Stakeholders. Full Show: HERE Seg. 3 Cybersecurity & Compliance w/ Paige Hanson of Secure Labs - AZ TRT S06 EP15 (277) 8-17-2025 What We Learned This Week: A cybersecurity breach can cost more than just data—it can damage infrastructure and destroy client confidence. Even smaller companies (50–100 employees) need structured safeguards, compliance, and often outside MSSPs to stay secure. Secure Labs provides a roadmap for companies to meet regulatory standards like HIPAA, ISO 27001, and SOC 2, helping them win bigger clients. AI-driven threats like voice cloning and deepfakes make personal and business digital security more important than ever. Compliance isn't cheap—outside audits can run $5,000–$50,000 annually, while Big Four audits may exceed $100,000. Guest: Paige Hanson, Co-Founder of Secure Labs LinkedIn: https://www.linkedin.com/in/hello-paige-hanson Founder of SecureLabs | Helping businesses meet their security compliance standards | Fractional GRC |
This Week In Startups is made possible by: Northwest Registered Agent - https://www.northwestregisteredagent.com/twistdomain NetSuite - https://www.netsuite.ai/twist Vanta - http://www.vanta.com/twist Check out a full transcript and summary of today's show, created by Plaud: https://web.plaud.ai/s/pub_c2b45bfe-abad-43ce-b7ef-41118f55f738::Vo2MH6PuXBzTCaxKRDjHH0zu8FbzgDpQL5OnfBfMzLP22CQRxciqE74Mq4YDD-LwYXGZCazgIeglPuwC Today's show: An Anthropic researcher quit this week, saying both leading labs are gambling with everyone's lives. His coworker chimed in and predicts there is a greater than 10% chance that AI will end humanity IN THE NEXT 10 YEARS. Jason and Lon take it to Yohei Nakajima of Untapped Capital, Ben Lerer of Lerer Hippeau, and Rebecca Lynn of Canvas Prime, who cannot decide whether it is the greatest PR strategy in history or some kind of mass psychosis. Learn why Jason says founders should never hand a frontier lab their proprietary data, whether or not they're offered free credits. PLUS, who really solved Navier-Stokes, and what does the OpenAI–Buckmaster fight mean for anyone doing real work inside ChatGPT or Claude? Guests: Yohei Nakajima on X: https://x.com/yoheinakajima Untapped Capital: https://untapped.vc/ Ben Lerer on X: https://x.com/BenjLerer Lerer Hippeau: https://www.lererhippeau.com/ Rebecca Lynn on X: https://x.com/VCRebecca Canvas Prime: https://www.canvas.vc/ Relevant Links: Jacob Coxon quits Anthropic - "gambling with our lives" https://techcrunch.com/2026/09/09/gambling-with-our-lives-anthropic-researcher-quits-warns-against-self-improving-ai/ Evan Hubinger, Anthropic's Alignment Science lead, on X: >10% odds within a decade — https://x.com/EvanHub/status/2097497037956891126 Future of Life Institute — the 2015 Puerto Rico AI safety conference Jason asks Lon to pull up → https://futureoflife.org/ Meta debuts Muse (Axios) —https://www.axios.com/2026/09/08/meta-debuts-muse-personal-ai-agent Harmonic — https://harmonic.ai/ China blocks Meta's Manus acquisition (CNBC) —https://www.cnbc.com/2026/04/27/meta-manus-china-blocks-acquisition-ai-startup.html OpenAI fought dirty— https://techcrunch.com/2026/09/08/openai-fought-dirty-on-career-making-math-problem-says-nyu-mathematician/ Savvy Wealth — https://www.wealthmanagement.com/ria-news/savvy-wealth-raises-100m-valuation-hits-600m Augmodo — https://www.augmodo.com/ E2B — https://e2b.dev/ Daptic — https://www.daptic.com/ Timestamps: 0:00 Jacob Coxon quits Anthropic: "crunch time" and "endgame" 4:53 Evan Hubinger: >10% odds AI kills all humans in a decade 11:22 Northwest Registered Agent - Got a new business idea? Northwest Registered Agent helps you bring it to life. Get a free domain, email, phone number, and more - with no purchase required! Learn more at https://www.northwestregisteredagent.com/twistdomain 12:23 "You have succeeded in scaring the bejesus out of Americans" 14:59 Jobs, the wealth divide, and which industries get wiped out first 20:07 NetSuite - For the first time ever, you can try NetSuite Next for free. If your revenues are at least in the seven figures, go to https://NetSuite.ai/TWIST 21:09 Savvy Wealth's $100M round 26:52 The Kalanick story and why Jason built a syndicate backstop 29:04 Vanta - Get $1000 off your SOC 2 at https://www.vanta.com/twist 32:05 Meta ships Muse 32:56 Can Meta be trusted 35:29 Threads Metrics 49:27 Robinhood's free-share referral 51:16 NYU's Tristan Buckmaster accuses OpenAI of fighting dirty on Navier-Stokes 57:43 Jason: "It's a trap" 59:03 Harvey goes open-weight, Go.AI on-prem, Covenant Labs 1:12:22 High performing portfolio companies Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp Follow Lon: X: https://x.com/lons Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis Check out all our partner offers: https://partners.launch.co/ Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland Check out Jason's suite of newsletters: https://substack.com/@calacanis Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com
Welcome back to Fintech Takes. I'm Alex Johnson, joined by two of my favorite Jasons (Jason Mikula of Fintech Business Weekly and Jason Henrichs of Alloy Labs) to go deep on the FDIC's very early effort to create standards for third-party risk management (particularly for bank-fintech partnerships). Banking didn't get here by accident. FIS, Fiserv, and Jack Henry ran the market for decades. Long contracts locked banks into these three providers and left little room for anyone else, which set the stage for fintech's rise. Then, we explore what happened when the pendulum swung too far in the other direction. From there, we consider whether certification can actually reduce risk. Henrichs points to SOC 2 as a cautionary tale, while Mikula questions whether meaningful standards can avoid putting very different banks, partners, and business models into a straitjacket. Tune in for a conversation on why there may be no magic top-down solution to bank-fintech risk. The bottom-up version: a dedicated cross-agency examiner group with strong expertise, and narrower, more specific rules (like the reconciliation requirement the FDIC floated and then dropped). --- This episode is brought to you by Ocrolus. Better lending starts with better intelligence. A borrower's cash flow only tells half the story, so Ocrolus fills in the rest with behavior signals and industry benchmarking. Visit https://www.ocrolus.com/ for more. --- Sign up for Alex's Fintech Takes newsletter for the latest insightful analysis on fintech trends, along with a heaping pile of pop culture references and copious footnotes. Every Monday, Wednesday, and Friday: https://workweek.com/brand/fintech-takes/ And for more exclusive insider content, don't forget to check out my YouTube page. --- Follow Alex: YouTube: https://www.youtube.com/channel/UCJgfH47QEwbQmkQlz1V9rQA/videos LinkedIn: https://www.linkedin.com/in/alexhjohnson X: https://www.twitter.com/AlexH_Johnson --- Follow Jason Mikula: Newsletter: https://fintechbusinessweekly.substack.com/ LinkedIn: https://www.linkedin.com/in/jasonmikula/ --- Follow Jason Henrichs: LinkedIn: https://www.linkedin.com/in/jasonhenrichs/ Twitter: https://x.com/jasonhenrichs
All links and images can be found on CISO Series This week's episode is hosted by me, David Spark, producer of CISO Series and Steve Zalewski. Joining us is Varsha Agrawal, head of information security, Prosper Marketplace. In this episode: Lock-in was never about the tech The board wants a green light, not a lesson Time was never the constraint What founders keep getting wrong about security A huge thanks to our sponsor, Vanta No, it's not your imagination. Risk and regulations ARE ramping up—and customers now expect proof of security just to do business. That's why Vanta is a game-changer. Vanta automates your compliance process and brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Companies like Ramp and Writer spend 82% less time on audits with Vanta. That's not just faster compliance—it's more time for growth. Get started at Vanta.com/CISO.
Most cyber companies bought the Claude or ChatGPT seats, handed them to every rep, and are now asking "now what?" Tal Peretz, co-founder and CEO of Onfire AI, has watched that play out across hundreds of mid-market and enterprise security vendors, and his answer is to stop pushing from the top. Start with your best rep and let the rest of the team chase him. Then take the same idea outside: skip the CISO, find the director who owns the budget, and make him the one who carries you up.In this episodeThe three tiers of AI adoption Tal sees in cyber sales teams, and why 85 to 90 percent are stuck at "we gave it to the rep"Why he starts every rollout with the A-players even though they're rarely the best AI usersThe on-site workshop where one rep's transformed week pulled his whole region along"Five by five": the agent that picks a rep's five accounts and five prospects for the week, and why each rep tweaks itWhy trust from the front line, not the tooling, makes or breaks an AI transformationOnly about 2 percent of account entries go through the CISO, so at $50M to $100M ARR the target is the directorWhy "agentic SOC" vendors pitching the CISO are talking to the wrong personHow to reach out on a signal without sounding like a creeper (and why you never mention Reddit)Tal's 2030 take: reps flip from 80 percent admin to 80 percent selling, and quotas go with itAbout the guestTal Peretz is co-founder and CEO of Onfire AI, an AI-driven GTM platform for companies selling to technical buyers. Before Onfire he was CTO at OwnID and spent nearly seven years in Israel's Unit 8200, the last two as Head of R&D.Notable quotes"Sales is a competition. Once you put the best reps first with the AI, everyone wants to fall in line.""Probably your best reps are not the best with AI yet.""If you have fifty million of ARR and you need to grow to 100 million, the CISO is not your target.""Everyone goes to the CISO. So you go to that person, and no one is connecting with him."Chapter timestamps00:04 Why an 8200 alum built for salespeople, not cyber01:55 Spin the wheel: visionary or smoking crack02:51 Three tiers of AI adoption in cyber GTM05:24 Start with your best rep, not your CRO08:15 The five by five use case11:09 Scoring your whole TAM off five years of closed-won16:39 The three barriers to agentic GTM (and the one that matters)21:16 Quality beats volume: the A/B test with people26:46 Only 2 percent get in through the CISO30:59 The SOC example: hundreds of vendors, one buyer32:40 Where the real signals live: Reddit, Discord, GitHub38:11 How to reach out on a signal without being a creeper41:34 What Onfire is building next43:41 Visionary or smoking crack: the reveal Support the showThe Cyber Go-To-Market Talk is the show for cybersecurity sales leaders, founders, CROs, and go-to-market operators looking to improve cyber sales performance and build more predictable revenue growth. Hosted by Andrew Monaghan, founder of Unstoppable.do, covering cyber sales leadership, revenue leadership, sales onboarding, forecasting, pipeline generation, and cybersecurity go-to-market execution.Follow me on LinkedIn for regular posts about growing your cybersecurity startupWant to grow your revenue faster? Check out my cybersecurity sales consulting and trainingNeed ideas about how to grow your pipeline? Sign up for my newsletter.
Skype of Cthulhu presents a Call of Cthulhu scenario. This is Our Home by Jim Phillips. December 18, 1976 Staten Island, New York City, New York Mr. Romero's discovery in the past leads to an impossible revelation from one of their own. Dramatis Persone: Jim as the Keeper of Arcane Lore Randall as Frank Romero, Electrical Engineer Rachel as Marsha Janelle, Waitress Steve as Trae Grier, Gas Station Attendant Edwin as Kevin Mazer, Chemistry Teacher Gary as Peter Michale, Ex Pro Quarterback Sean as Kirk Griffin, Actor Download Subcription Options Podcast statistics
Cybersecurity is not an entry-level field. It's a specialization — and that single distinction changes how an experienced IT professional should approach the move.This is a mapping exercise: five defensive security roles that take a lateral pivot from an IT background instead of a restart, what each one actually does day to day, which IT experience feeds it, and the honest gap you'd still have to close for each.No guaranteed timelines, no salary fantasies. Including the part where the U.S. Bureau of Labor Statistics just revised its growth projection down.CHAPTERS00:00 The advice that costs IT pros years00:36 Why cybersecurity is a specialization, not an entry-level field02:56 The three-question pivot test: overlap, adjacency, proof04:13 1. Security Engineer (Infrastructure / Cloud)06:14 2. Identity and Access Management Engineer08:20 3. Network Security Engineer10:33 4. Vulnerability Management Specialist13:00 5. Tier 2 SOC & Incident Response Analyst15:18 What the job market actually says (BLS, August 2026 update)17:06 Make your resume say what your work already was18:44 How to choose: Inventory, Threats, Controls, Scale20:00 Where to go nextTHE WRITTEN VERSIONAll five roles, plus the resume translation table:https://blueteam-academy.com/blog/blue-team-jobs-it-professionals/KEEP IT SAFE — OUR NEWSLETTEROne breakdown a week for IT professionals making this exact move:https://www2.blueteam-academy.com/keep-it-safe-signupFROM IT TO CYBERSECURITYThe program where we teach the Threat & Control Method — Inventory, Threats, Controls, Scale — as a repeatable decision process rather than a tool list: https://www2.blueteam-academy.com/from-it-to-cybersecurity/SOURCESU.S. Bureau of Labor Statistics, Occupational Outlook Handbook, InformationSecurity Analysts (last modified 27 August 2026): 21% projected growth 2025–35,~14,100 annual openings, $129,180 median annual wage (May 2025), 192,900 jobs (2025).https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htmBlue Team Academy is a program for IT professionals moving into defensive cybersecurity. Konnio Technology LLC.#BlueTeam #CybersecurityCareers #ITCareers
Be sure and join us with our special guest, 18 year FDNY veteran, Lieutenant Brian Burik. Brian started his career in EMS in 1997. Then in 2000 he went to the fire academy, and was assigned to Ladder 28 out of probie school. In 2005 Brian went to Rescue 1 until 2012 where he was promoted to Lieutenant, assigned to Division 11, in Tower ladder 146. In 2014 he moved on to SOC to be a part of SCUBA / Swiftwater, bouncing around the unit until 2017. After SOC he went to Rescue School SSL until retiring in 2018. After retirement Brian didn't stop, he went on to create another successful career. No doubt Lt. has some great stories for us and we can't wait to hear them. Especially with his new career, involving most firefighters favorite, coffee or should I say.....CAW-FEE..... Gonna be another great show. We will get the whole skinny. You don't want to miss this one. Join us at the kitchen table on the BEST FIREFIGHTER PODCAST ON THE INTERNET! You can also Listen to our podcast ...we are on all the players #lovethisjob #GiveBackMoreThanYouTake #Oldschool #Tradition #Learyfirefightersfoundation #firefighter #FDNY | Free shipping for Salty listeners until the end of September - https://traditioncoffeeroasters.com/discount/GettinSaltyBecome a supporter of this podcast: https://www.spreaker.com/podcast/gettin-salty-experience-firefighter-podcast--4218265/support.
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 112: The 'OpenAI hacks Hugging Face' fallout has turned into a story about AI civilizations rising from the ashes, politicians calling for super-intelligence bans, and the emergence of well-funding non-profits doing AI safety work. Who are these people and what's their security expertise? Plus, GPT-6 Astra lands in a trusted-access program nobody can get into, Costin ranks the local models he runs next to his desk, and CrowdStrike sinkholes a botnet that's been alive since 2003. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Introductory banter 1:02 Conference season: LabsCon, Offensive AI Con, Countermeasure 5:40 The Hugging Face story hits the front page 7:04 Dwarkesh, Greenblatt, and the AI-pilled framing 11:51 Swap "agents" for "Python" and the panic goes away 16:34 Does anyone actually know what happened? 21:18 Bernie Sanders wants to ban superintelligence 34:03 Defending against swarms: the 2026 SOC 39:15 Logs, Splunk, and the business model in the way 44:11 What EDR vendors are actually building with AI 56:16 The security poverty line and the endgame 1:07:53 GPT-6 Astra, Fable 5.1, and local model rankings 1:27:25 Google's Fairwind, CodeMender, and agents running Linux 1:45:31 Apple's bet on local inference 1:53:21 The Sality takedown and endgame advice
A fresh wave of price hikes has hit China's smartphone market, as Huawei, Xiaomi and Honor increased retail prices for several current models by between 200 ($29.75) and 1,000 yuan, triggering heated chatter on social media.新一轮涨价潮席卷中国智能手机市场,华为、小米和荣耀将多款在售机型的零售价格上调了200元(约合29.75美元)至1000元不等,引发社交媒体热议。The coordinated adjustments come amid tightened memory chip supply and sustained price increases for key semiconductors.这轮集体调价正值存储芯片供应趋紧、关键半导体价格持续上涨之际。Huawei led the increases, with its Mate 80 series jumping by as much as 1,000 yuan on Tuesday, while the 90 Pro Max sold for an extra 200 yuan. Xiaomi, which had already adjusted prices on Aug 2, raised the Xiaomi 17 and 17 Pro by 300 yuan each — its second hike in less than a month.华为率先涨价,其Mate 80系列周二涨幅高达1000元,90 Pro Max则上涨200元。小米已于8月2日调价一次,随后将小米17和17 Pro各上调300元——这是其不到一个月内的第二次涨价。Honor followed suit, lifting its Power2 by 500 and 600 yuan for its two variants, and increasing its flagship Magic8 series by 300 to 500 yuan across versions, bringing post-hike prices to between 4,799 and 5,999 yuan.荣耀紧随其后,将其Power2的两款机型分别上调500元和600元,旗舰Magic8系列各版本上调300至500元,涨价后售价在4799元至5999元之间。In response to the increases, a Huawei customer service representative said the upward adjustments were necessary because "market prices of key materials have changed, leading to higher production costs".针对此次涨价,华为客服代表表示,上调价格是必要的,因为“关键材料的市场价格发生了变化,导致生产成本上升”。At the crux of the surge is a structural imbalance in global memory chip supplies. As artificial intelligence model training and AI server infrastructure expand at a breakneck pace, major memory makers — Samsung, SK Hynix and Micron — have shifted substantial high-end capacity toward high-margin HBM (high bandwidth memory), mainly used in servers, thus directly squeezing the supply of handset-oriented DRAM and NAND memory chips. That supply crunch has sent mobile memory prices soaring.本轮涨价的根源在于全球存储芯片供应的结构性失衡。随着人工智能模型训练和AI服务器基础设施以惊人速度扩张,三星、SK海力士和美光等主要存储芯片制造商已将大量高端产能转向主要用于服务器的高利润HBM(高带宽内存),从而直接挤压了面向手机的DRAM和NAND存储芯片的供应。这种供应紧张已推动手机存储芯片价格飙升。Market research firm Trend-Force said in a recent report that memory prices have accumulated a five- to seven-fold increase since the start of 2025, forcing brands to either raise prices sharply or discontinue product lines that have turned loss-making.市场研究机构集邦咨询在近期报告中称,自2025年初以来,存储芯片价格已累计上涨五至七倍,迫使品牌要么大幅提价,要么停产已陷入亏损的产品线。The cost pressure, however, is no longer limited to storage. In late July, Qualcomm Inc CEO Cristiano Amon said the chipmaker planned to raise its product prices effective Sept 1.然而,成本压力已不再局限于存储领域。7月下旬,高通公司首席执行官克里斯蒂亚诺·阿蒙表示,这家芯片制造商计划自9月1日起上调产品价格。Amon explained that the hike reflects broader cost increases across the supply chain. This means smartphone makers now face a dual squeeze from both memory and SoC (system-on-chip) costs — a major factor behind the simultaneous retail price adjustments seen on Tuesday.阿蒙解释说,此次涨价反映了整个供应链更广泛的成本上升。这意味着智能手机制造商现在面临着来自存储芯片和SoC(系统级芯片)成本的双重挤压——这也是周二零售端集体调价的主要原因。The current round of price increases differs somewhat from previous ones. In the past, price hikes typically accompanied new product launches, justified by upgraded features or specifications, experts said.专家表示,本轮涨价与此前有所不同。过去,涨价通常伴随新品发布,并以功能或规格升级作为理由。This time around, however, brands are directly raising prices on devices already available in the market. Xiaomi's case is particularly telling: its Tuesday increase came less than a month after its Aug 2 hike, indicating that manufacturers are passing on costs gradually through multiple small adjustments rather than a single large spike, as component costs remain stubbornly elevated.然而,这一次品牌直接上调了已在售机型的售价。小米的案例尤为典型:其周二涨价距离8月2日的上一轮涨价不到一个月,表明在元器件成本持续高企的情况下,制造商正通过多次小幅调整而非一次性大幅提价来逐步转嫁成本。Top executives had already hinted at the coming price increases. On Aug 5, Huawei's executive director and chairman of its terminal business group, Yu Chengdong, warned that "with memory prices so high, all phones may have to see large-scale price rises in the future; otherwise, they would be sold at a loss".企业高管此前已暗示即将到来的涨价。8月5日,华为常务董事、终端BG董事长余承东警告称:“存储芯片价格这么高,未来所有手机可能都不得不大幅涨价,否则就会亏本销售。”In a May livestreaming session, Xiaomi President Lu Weibing predicted that by the second half, some domestic flagship slab phones could break through the 10,000-yuan price barrier.在5月的一次直播中,小米总裁卢伟冰预测,到下半年,部分国产旗舰直板手机可能突破万元价格关口。Indeed, the industry has been grappling with rising prices since the third quarter of last year. Almost every major brand — Samsung, Oppo, Vivo, Huawei and Honor — has raised retail prices to varying degrees, with mid-range and entry-level models typically seeing increases of 300 to 500 yuan, while high-end flagships and foldables have recorded hikes exceeding 1,000 yuan.事实上,自去年第三季度以来,整个行业一直在应对价格上涨压力。几乎所有主流品牌——三星、OPPO、vivo、华为和荣耀——都不同程度地上调了零售价格,中端和入门级机型通常上涨300至500元,而高端旗舰机和折叠屏机型的涨幅则超过1000元。According to US market research firm International Data Corp, China's smartphone shipments in the second quarter stood at approximately 66 million units, a year-on-year decline of 4.3 percent, continuing a streak of quarterly drops. For the first half, total shipments reached about 134 million units, down 4.2 percent from the same period last year.据美国市场研究机构国际数据公司(IDC)数据,第二季度中国智能手机出货量约为6600万部,同比下降4.3%,延续了季度下滑趋势。上半年总出货量约为1.34亿部,较去年同期下降4.2%。coordinated adjustments /kəʊˈɔːdɪneɪtɪd əˈdʒʌstmənts/集体调价memory chip /ˈmeməri tʃɪp/存储芯片semiconductor /ˌsemikənˈdʌktə/半导体high-end /haɪ end/高端的high-margin /haɪ ˈmɑːdʒɪn/高利润的structural imbalance /ˈstrʌktʃərəl ɪmˈbæləns/结构性失衡breakneck pace /ˈbreɪknek peɪs/惊人的速度supply crunch /səˈplaɪ krʌntʃ/供应紧张loss-making /ˈlɒs ˈmeɪkɪŋ/亏损的dual squeeze /ˈdjuːəl skwiːz/双重挤压
Findings from Box's State of AI in the Enterprise survey show 83% of enterprises are now running agents in some capacity.These bots are enabling teams to drive productivity and efficiency, but as with any new technology, smooth integration can be a challenge - and security risk.Recent agent-related incidents in the tech industry have sparked concerns about long-term security implications.In this week's episode of the ITPro Podcast, Ross Kelly and Bobby Hellard speak with Box CISO Heather Ceylan to discuss how Box is using agents internally, and how enterprises can adopt the technology in a safe and secure manner.Highlights“I think for security teams, we can finally, you know, start having the capacity to outpace these attackers. So we've got five core areas of investment for agents for our security team in particular that we've invested in over probably the last year, and we're starting to measure ROI on those right now.“So the first one is in the SOC. I think that's probably the most obvious choice where we've got a lot of operational work. We see the same kinds of incidents. We're automating the triage, we're automating the enrichment, the log correlation, things like that that take a lot of human effort.“But there's still human judgment in the end in terms of what gets escalated to be an incident and what doesn't.”“We're not going to be able to move fast enough. So, we have agents kind of built throughout our software development process, doing those security design and architecture reviews, and if you think about it, it's way more powerful than a human can be because those agents don't just necessarily call out design flaws; they can enforce fixes for those flaws.”“Things are changing quickly. Sometimes it feels like you take two steps forward and then you read something in the news and you're like, oh my gosh, we need to rethink everything.“So I think a lot of security teams are really feeling that now and getting a little bit of fatigue from that.““One of the things that we're trying to carry across all of these that I wasn't really thinking about a year ago, but I'm thinking a lot about now is having that multi-model approach.“We're not in a place where most of the work we do, we can't be reliant on a single model. If you look at vulnerability discovery, we're moving away from being tied to any one specific vendor or any one specific model because you're going to get better results when you take a multi-model approach.”LinksAI is getting better at security – and it's doing it faster than expectedTop security teams use AI agents, says Hack The BoxAI is changing team structures in cybersecurity and creating new roles – here are the jobs in hot demandCan AI fight AI? Where the security gap still exists in cybersecurity, and how MSPs can help
Skype of Cthulhu presents a Call of Cthulhu scenario. Moonchild by Paul Fricker. October, 2013 Springfield, Massachusetts While the classmates discover their memories of the night in question are disjointed, they make the journey to that strange place for the first time in years. Dramatis Persone: Edwin as the Keeper Randall as Ray West, IT Professional Gary as Maggi Stern, Retail Manager Meredith as Alicia Jucio, Antiques Dealer Steve as Melinda Moody, Journalist Max as Erik Wilson, Accountant Jim as John Vinocur, Nurse Download Subcription Options Podcast statistics
Skype of Cthulhu presents a Call of Cthulhu scenario. This is Our Home by Jim Phillips. December 17, 1976 Staten Island, New York City, New York Mr. Griffin has an unusual conversation and the team makes plans for... the end. Dramatis Persone: Jim as the Keeper of Arcane Lore Randall as Frank Romero, Electrical Engineer Rachel as Marsha Janelle, Waitress Steve as Trae Grier, Gas Station Attendant Edwin as Kevin Mazer, Chemistry Teacher Gary as Peter Michale, Ex Pro Quarterback Sean as Kirk Griffin, Actor Download Subcription Options Podcast statistics
Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode, Ron sits down with Myke Lyons, CISO at Cribl, who cut his teeth in telemetry and logging decades ago and has landed right back there in the age of AI. Ron and Myke dig into why most telemetry failures aren't data problems at all, they're decisions nobody made about why the logs are being collected in the first place. Myke breaks down what to track on every agent in your environment, why token spend belongs on the security team's plate, why dashboards are quietly dying, and why treating an AI agent like just another employee is a mistake that's going to bite security teams hard. Underneath it all is one question Myke keeps circling back to: do you actually know what normal looks like for every agent in your environment? Impactful Moments 00:00 - Introduction 01:50 - Myth Busting: AI Agents Aren't Just Another User Account 04:25 - Meet Myke Lyons, CISO at Cribl 05:05 - What it means to run security at a telemetry company 06:10 - From gigabytes of logs at GE to petabytes today 07:45 - MITRE ATT&CK, Cribl's new APEX framework, and orienting telemetry 10:20 - Why most telemetry problems are decision problems, not data problems 13:20 - OCSF and how security teams are rethinking their schemas 14:25 - Why the dashboard is dying 17:35 - What Myke wants to track about every AI agent 20:10 - How to spot an agent going rogue 23:15 - Making your data AI-ready and the case for schematizing everything 27:10 - Tokenomics: treating AI spend as a security responsibility 29:05 - The non-negotiable logs every org should be collecting 31:50 - Hot takes: build vs. buy, tier two to three, and Myke's daily AI briefing 33:35 - Closing thoughts and outro Links Connect with Myke Lyons on LinkedIn: https://www.linkedin.com/in/mykelyons/ Learn more about Cribl: https://cribl.io/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/
Skype of Cthulhu presents a Call of Cthulhu scenario. This is Our Home by Jim Phillips. December 16, 1976 Staten Island, New York City, New York Mr. Michale discovers the future is not fixed while Mr. Griffin makes a long awaited appointment. Dramatis Persone: Jim as the Keeper of Arcane Lore Randall as Frank Romero, Electrical Engineer Rachel as Marsha Janelle, Waitress Steve as Trae Grier, Gas Station Attendant Edwin as Kevin Mazer, Chemistry Teacher Gary as Peter Michale, Ex Pro Quarterback Sean as Kirk Griffin, Actor Download Subcription Options Podcast statistics
Skype of Cthulhu presents a Call of Cthulhu scenario. The Island by David Khoo. June, 1925 Lisboa, Portugal Professor Arthur Penhale-Clarke and his daughter Sylvia gather a group of friends together to discuss the adventure of a lifetime. Dramatis Persone: Gary as the Keeper Meredith as Jose Fernandez, Reporter Jim as Professor Joao Pereira, Archeologist Sean as Natalie Greenwood, Archeologist Max as Bertram Arbuthnot Montgomery, Dilettante Download Subcription Options Podcast statistics
Joey “Devil Doc Talk” Martinez sits down with Lt Col (Ret.) Hunter K. Jones — U.S. Naval Academy graduate, former Air Force OSI federal agent, and Founder & CEO of Jones & Associates.Hunter's path runs from Navy football to some of OSI's hardest missions: felony crime, narcotics, executive protection, counterintelligence, counterespionage, and counterterrorism. He deployed twice as a Special Agent in Charge during Operations Iraqi Freedom and Enduring Freedom, served as Global Security Director and Personal Security Advisor to Air Force Chief of Staff Gen. John Jumper, commanded a 24-agent unit at Hill AFB, and later led plans, programs, and policy at U.S. Central Command.After the uniform he carried that standard into Booz Allen Hamilton, Boeing, Penn Medicine's cybersecurity SOC, and national-security business development. He still coaches high school football to teach life lessons and grow future leaders. He and his wife Tara are raising two sons in the same Berwyn, PA neighborhood where he grew up.Together they talk command under pressure, life after the badge, and why Service To Others Above Self still matters when the mission changes.Watch. Like. Share it with someone who served.The Devil Doc Talk Show — hosted by Joey “Devil Doc Talk” Martinez (U.S. Navy Corpsman combat veteran). Entertain & Empower. Produced by ADAX Entertainment (veteran-owned).ALL LINKS: https://linktr.ee/thedevildoctalkshow YouTube: https://www.youtube.com/@thedevildoctalkshow Apple: https://podcasts.apple.com/us/podcast/the-devil-doc-talk-show/id810683741 Spotify: https://open.spotify.com/show/5RbFbsF6rUd7zX5J2UDf03 Instagram: https://www.instagram.com/devildoctalk/ X: https://x.com/DevilDocTalk Email: thedevildoctalkshow@gmail.comLIKE if this hit home. COMMENT: What did your next mission look like after service? SUBSCRIBE for more conversations that entertain and empower.#DevilDocTalkShow #HunterJones #OSI #AirForce #NavalAcademy #VeteranPodcast #Leadership #VeteranTransition #ServiceToOthers #ADAXEntertainment© 2026 The Devil Doc Talk Show / ADAX Entertainment. “Service To Others Above Self”
Cybersecurity interviews don't test what you already know from IT — they test how you think. This video walks through all three interview rounds, the four kinds of questions you'll actually face, and one repeatable way to structure your answers that works across every single one of them.Based on our full written guide: https://blueteam-academy.com/blog/cybersecurity-job-interview-prep/00:00 Intro00:39 Why Cybersecurity Interviews Are Different02:39 The HR Screening Call04:49 The Technical Round: Research & Frameworks08:31 The Four Question Buckets11:21 How to Answer a Scenario Question13:33 SOC vs GRC vs IAM vs Cloud Security15:11 Portfolio, Home Lab, or Certifications?17:18 The Manager Round & Handling "I Don't Know"20:19 Mistakes That Sink Candidates + What to Ask the Interviewer22:18 After the Interview + Key TakeawaysSources referenced in this video:ISC2, 2025 Cybersecurity Workforce Study — https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-StudyWant a structured way to turn your IT experience into a cybersecurity career? Link in the pinned comment.For more breakdowns like this one, the Keep IT Safe newsletter is there too.#CyberSecurity #BlueTeam #ITCareer #SOCAnalyst #CyberSecurityJobs
Read the full stories at CISOSeries.com. This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.
Podcast: Industrial Cybersecurity InsiderEpisode: Why Detection Alone Can't Stop the Next OT AttackPub date: 2026-08-26Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationDetection got fast, but remediation didn't. And that gap is exactly where attackers live.Manufacturers have spent the last decade building visibility into their plants: sensors, dashboards, alerts flying into every SOC. But knowing about a threat and fixing it are two different problems, and most industrial teams are still solving the second one at human speed. A ticket gets opened. A maintenance window gets scheduled. Three departments get looped in. Meanwhile, the attacker isn't waiting for anyone's approval.In this episode, Craig Duckworth talks with Tal Kollender, founder and CEO of Remedio, about what's actually keeping industrial environments exposed: misconfigurations left untouched for months, unnecessary services quietly giving attackers a path to move laterally, and aging systems nobody wants to be the one to touch. Tal makes the case that patching alone will never close this gap and explains why safe automated remediation is becoming essential as AI accelerates attacks faster than most security teams can keep up.They also dig into the reality of OT: uptime and safety come first, IT security tools often can't reach the controls layer, and the wrong change can cause real damage on the plant floor. It's a candid look at what it takes to align security and operations, and why building that trust is the real first step toward proactive protection instead of reactive cleanup.If you're responsible for securing a plant floor, a fleet of facilities, or the budget behind either one, this conversation gives you a clear, practical way to think about closing the gap between seeing a threat and actually stopping one.Chapters:(00:00:00) Why machine speed detection needs machine speed remediation(00:01:00) Tal's path from teenage hacker to cybersecurity founder(00:06:00) Misconfigurations and lateral movement in industrial environments(00:11:00) Why patching and configuration changes are difficult in OT(00:15:00) Moving from reactive detection to proactive hardening(00:17:00) Aligning people, process, and technology(00:22:00) AI adoption, unmanaged risk, and doing more with less(00:25:00) Bridging the IT and OT divide without disrupting operations(00:29:00) The first practical step toward proactive industrial securityLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityTal Kollender on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you'd like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
See what the team at The Successful Bookkeeper has on right now → If you've been watching the AI wave roll in and wondering what it means for your bookkeeping practice, this episode is for you. Alex Lee, co-founder and CEO of Truewind, brings a clear-eyed perspective grounded in three and a half years of building AI tools specifically for accountants. His message is direct: the future of accounting has always been about you, and that isn't changing. Chapters [00:00] Opening: Fear and Opportunity [01:18] Alex Lee's Unlikely Path to AI [04:18] The Future Is Still You [08:00] Will AI Replace Bookkeepers? [12:00] Crawl, Walk, Run: Getting Started [16:30] AI Adoption Across the Profession [19:30] Data Privacy and Security Checklist [24:00] Vision for Accounting's Future [27:00] About Truewind The Work That Has Always Mattered Alex draws a useful historical line — from carving debits and credits in limestone, to paper ledgers, to file cabinets, to cloud software, and now AI. "I see AI as the next iteration of technology that may shape how accountants are doing the work," he says. "But ultimately, the work of the accountants is the same." What AI does is create space for bookkeepers to spend more time on the things that are genuinely hard to automate: being a trusted advisor, being a real business partner, and — as Alex puts it — shaking hands and looking someone in the eye. Those things don't disappear no matter how good the models get. The Spreadsheet Comparison Worth Remembering When the fear of replacement comes up — and it does — Alex points to a pattern that has played out before. When spreadsheets arrived, people predicted mass job losses in accounting. Instead, the profession grew. Some small business owners did start managing their own five-line chart of accounts, and some will use AI to handle basic recordkeeping themselves. But that's not your client. "As accountants, it puts you in a very unique position to elevate yourself in terms of your AI skills and demonstrate to businesses, I know how to use this tool exceptionally well." The expertise gap has always been the value. AI doesn't close that gap — it widens it in your favor if you lean in. A Crawl, Walk, Run Framework for Getting Started Alex is practical about adoption. Start by picking one AI tool you've already heard of — maybe tried once — and use it for everyday tasks: drafting a client email, writing a performance review, planning a trip. Get comfortable at that level before adding complexity. Walking looks like connecting your AI to your Slack, email, or call recordings and asking it to synthesize information — summarizing client pain points before a proposal, for example. Running is letting AI handle a meaningful portion of your day-to-day operations. "Just get started," Alex says. "Over time, get more sophisticated, and then over time, let it be the primary operating system for you." Handling Data Privacy the Right Way Financial data demands careful handling, and Alex doesn't gloss over it. His checklist for vetting any AI vendor: confirm they are SOC 2 Type 2 compliant with a reputable auditor (not a quick rubber-stamp), verify that data privacy agreements exist between your vendor and the underlying model providers like OpenAI or Anthropic, and look for a genuine philosophy of data protection — not just a claim on a website. For teams that are still nervous about connecting client data to AI tools, his advice mirrors the crawl-walk-run approach: start by using AI internally with your own team's Slack and shared drives. Build confidence there before expanding to client-facing workflows. A Bigger Demand for Accountants Is Coming Alex's outlook for the next one to five years is genuinely optimistic. He sees AI acting as a catalyst for what he calls a "Cambrian explosion of demand for accounting." As business models shift from billable hours toward fixed-fee engagements and technology enables firms to handle more clients with the same headcount, he expects more businesses — not fewer — to seek out qualified accounting professionals. "Accountants can get more done with less, driving an influx of demand for what accounting firms can provide." The firms positioning themselves now, building AI literacy and deepening client relationships, are the ones that will be ready to capture that demand. Links Mentioned Truewind — Alex's AI-powered accounting platform The Successful Bookkeeper — show resources and guest information PureBookkeeping — episode sponsor, proven system to grow your bookkeeping business About the Guest Alex Lee is the co-founder and CEO of Truewind, an AI-powered accounting platform built for accounting firms and corporate finance teams. Before founding Truewind, Alex worked as an aerospace engineer at Boeing, spent time in venture capital, and built a financial planning and analysis company. Truewind launched in the same month as ChatGPT and has spent the past three and a half years building what Alex describes as an "agentic workspace" for accountants — integrating with QuickBooks Online, Sage Intacct, and NetSuite to help teams cut close time by 30 to 50%. You can reach Alex directly on LinkedIn or learn more at truewind.ai. About the hostMichael PalmerMichael Palmer is the host of The Successful Bookkeeper podcast and co-founder of Pure Bookkeeping and The Successful Bookkeeper. He started this work because of his father — a brilliant electrical contractor who worked twice as hard as he should have had to, because nobody on the financial side was in his corner. That gap is what The Successful Bookkeeper exists to close. His view: bookkeepers are the most undervalued force in small business — and every bookkeeper who builds a real business changes two families: theirs, and their clients'.
SynkLoader throws in the kitchen sink NIST flags multi-cloud sprawl ReliaQuest blocks a ShinyHunters swing Get the show notes here: https://cisoseries.com/cybersecurity-news-august-25-2026/ Huge thanks to our episode sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.
How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence community—about his path from military service, to Crowdstrike to founding Adlumin, which evolved from behavior analytics into SIEM/eXDR and ultimately an MDR service before being acquired by N-able in November 2024. They discuss how AI is transforming SOC operations by automating time-consuming work like incident summaries, enabling more customized investigations, and helping reduce alert fatigue while improving verdicts. Johnston explains how AI-driven attacks are compressing dwell time from weeks to minutes or hours, forcing defenders to match detection and response speed, and predicts increased AI-enabled vulnerability discovery will make patching and vulnerability management more critical. The conversation also covers MSPs becoming security providers, regulatory friction around AI, autonomous hacking headlines, and why hack-back by private companies risks collateral damage and liability. 00:00 Sponsor NordLayer 00:37 Weekend Show Intro 02:02 Robert Career Journey 03:08 Building Adlumin 05:50 AI Transforms SOC Work 08:56 AI Investigations Upgrade 11:23 Alert Fatigue and MDR 13:49 MSPs Become MSSPs 19:30 AI as Opportunity and Threat 21:13 Attack Speed Compression 22:54 Wins and Frustrations 26:59 Autonomous Hacking Reality 29:03 Hack Back Debate 32:43 Next 12 Months Forecast 34:28 Closing Thanks 35:22 Sponsor Message Return
Send us Fan MailBefore you head to the 2026 Southern Outdoor Classic, you want to check out this week's episode of Takin' it Outside! The SOC crew sits down to share all of the last minute details for the largest outdoor show around. Make plans to join us Saturday August 29th and Sunday August 30th at The Farm at 95. Head to southernoutdoorclassic.com for more info.You can find Takin it Outside on all major podcast platforms and on Youtube. Thanks to Joel Gillie Productions for his continued support of Takin it Outside.
This Week In Startups is made possible by: Vanta https://www.vanta.com/twist Agree https://agree.com YSecurity https://YSecurity.io/TWIST Today's show: Frontier AI models can ace PhD-level exams, but it's still bad at tracking down the product you want in the style that suits you. Onton's Zach Hudson tell us that the problem is that models are a black box. His solution? A neurosymbolic model, Ontology 1, that learns about your taste and preferred aesthetic over time, then produces product searches tailored specifically to you, rather than just using keywords and relevant tags. How do neurosymbolic models work, and how does Onton understand your prompts and favorite design trends? And why aren't the frontier labs working on neurosymbolic models of their own? Zach joins Jason and Lon to discuss. PLUS, following a record-smashing SpaceX IPO, Ashi Dissanayake of Spacium makes the case that the real bottleneck in space isn't launching rockets off the ground any more. It's refueling in orbit. Guests Zach Hudson on X: ****https://x.com/nosduhz Onton: https://onton.com/ Spacium: https://spaceium.com/ Spacium on X: https://x.com/SpaceiumInc Relevant Links Poolside's journey to AGI: https://poolside.ai/vision/purpose Startup Archive: Sam Altman on the Paul Graham advice that saved OpenAI: https://www.startuparchive.org/p/sam-altman-on-the-paul-graham-advice-that-saved-open-ai-always-make-an-api Kelly Wearstler: https://www.kellywearstler.com/ Ennis House: https://franklloydwright.org/site/ennis-house/ Los Feliz Living: Ennis House profile: https://www.losfelizliving.com/los-feliz-historic-homes/ennis-house-los-feliz-hcm-149 Indiewire: Ennis-inspired "The Studio" offices: https://www.indiewire.com/features/craft/the-studio-production-design-interview-seth-rogen-1235114365/ Monocle Magazine: https://monocle.com/ Spaceium on Y Combinator: https://www.ycombinator.com/companies/spaceium-inc Orbit Fab's RAFTI: https://www.orbitfab.com/rafti/ James Webb Space Telescope: https://science.nasa.gov/mission/webb/ Houzz: https://www.houzz.com/ Timestamps: 0:00 Zach Hudson joins: What is "neurosymbolic search" 4:03 Ontology 1 isn't a black box 6:31 Who is using Onton? 9:36 Vanta - Get $1000 off your SOC 2 at https://www.vanta.com/twist 11:35 Could neurosymbolic models reach AGI? 13:19 Jason loves Wright's Ennis House 17:03 The shape of AI companies is changing 19:28 Agree.com - Stop chasing invoices and automate your entire contract-to-cash stack. Go to https://agree.com and tell them Jason sent you to get 50% off for life! 22:32 UGC as a data moat 26:03 The Dead Internet Theory 28:13 Ashi Dissanayake of Spacium joins 29:52 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 31:50 Storables vs. cryogenics: the zero-boil-off breakthrough 34:11 All kinds of propulsion requires refueling 36:09 Getting more value from LEO to GEO 38:28 Moving at rocket speed 44:54 Why demand is so acute 49:37 The investing climate for space, post-SpaceX Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp Follow Lon: X: https://x.com/lons Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis Check out all our partner offers: https://partners.launch.co/ Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland Check out Jason's suite of newsletters: https://substack.com/@calacanis Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com
Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing. Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates. Impactful Moments 00:00 - Introduction 02:05 - The rewind: how SOAR promised to save the SOC in 2015 03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer 05:30 - What cybersecurity looked like before AI at enterprise scale 07:00 - The "humans first" strategy behind Adobe's AI investigator 09:30 - Why careless context management is the biggest pitfall in agent design 14:45 - Solving the speed problem: is it tooling, process, or people? 17:10 - From monolith to microservices: rebuilding the platform for scale 24:05 - What actually makes an AI agent's "persona" work 26:00 - John's prediction for the SOC three years from now 28:50 - The three skills every security practitioner needs for 2026 32:10 - Final verdict: is AI SOC really different, or SOAR with new branding? Links Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/ If you're a researcher ready to make an impact, check out the announcement about Adobe's new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Check out Adobe's Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail Learn more about Adobe: https://www.adobe.com/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/
Skype of Cthulhu presents a Call of Cthulhu scenario. Moonchild by Paul Fricker. October, 2013 Springfield, Massachusetts The classmates all pursue different leads while some meet with the man at the center of the mystery. Dramatis Persone: Edwin as the Keeper Randall as Ray West, IT Professional Gary as Maggi Stern, Retail Manager Meredith as Alicia Jucio, Antiques Dealer Steve as Melinda Moody, Journalist Max as Erik Wilson, Accountant Jim as John Vinocur, Nurse Download Subcription Options Podcast statistics
What actually changed for the AI SOC this year? Bill Peterson, Senior Director of Product Marketing at Sumo Logic, says it reached the point of getting into production, where a year or so ago the same conversation was about what was coming. Marco Ciappelli puts the count of companies carrying AI SOC in the name at 43, and Bill Peterson says that number strikes him as low. The market is maturing, and Sumo Logic announced its own set of AI SOC products and solutions during the week. The second thing is what a security audience does with it. Hands-on practitioners want to touch it, see it, feel it, and Sumo Logic ran live demos of its products on site. When a technical audience puts hands on a keyboard and tries something, Bill Peterson expects them to take it back to work with them. Production first, then enablement of the practitioners. The third is the pace behind all of it. Most security vendors are SaaS companies running CI/CD and shipping continuously, so three and six month roadmaps and delivery are the norm now and the 12 to 18 month roadmap is gone. Some customers are what Sumo Logic internally calls AI shy, accepting they have to get there while taking a slow and reasoned approach, and Bill Peterson treats that as normal for any technology. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Bill Peterson, Senior Director of Product Marketing at Sumo Logic On LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic Dojo AI: https://www.sumologic.com/solutions/dojo-ai Sumo Logic Dojo AI agent announcements at Black Hat USA 2026, including general availability of the SOC Analyst Agent: https://www.prnewswire.com/news-releases/sumo-logics-new-dojo-ai-agents-investigate-and-resolve-security--cloud-operations-issues-at-machine-speed-302839720.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, AI SOC, agentic AI, security operations, Dojo AI, SOC analyst agent, product marketing, CI/CD release cycles, AI adoption, human in the loop, security operations center, market maturity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Skype of Cthulhu presents a Call of Cthulhu scenario. Moonchild by Paul Fricker. October, 2013 Springfield, Massachusetts Other revelations come forward from another members of the college occult club and the group investigates their old leader's current life. Dramatis Persone: Edwin as the Keeper Randall as Ray West, IT Professional Gary as Maggi Stern, Retail Manager Meredith as Alicia Jucio, Antiques Dealer Steve as Melinda Moody, Journalist Max as Erik Wilson, Accountant Jim as John Vinocur, Nurse Download Subcription Options Podcast statistics
Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a “mouthpad”? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-472
Stewart Alsop sits down with Juan Verhook, founder of Tender Market, for a second conversation that ranges from the mechanics of European public tenders to the future of how we organize digital information. They cover how Tender Market helps smaller companies work around barriers like SOC 2 and ISO certification requirements, the surprising scale of public procurement (roughly 20% of GDP), and how AI and machine learning are reshaping the bidding process. From there the conversation opens up into bigger territory: the changing tolerance for being wrong in an AI-saturated information landscape, how language and culture shape perception, the reverse Turing test and the challenge of verifying human versus AI identity online, and Juan's daily workflow running eight or nine MCP servers through Claude Code. They close out talking about whether the folder and file system will survive the shift to AI-native interfaces, tying back to Stewart's own Stewart Squared episodes on the history of the PC. You can visit Tender Market at tendermarket.eu.Timestamps05:00 — Tender Market's origin story and how they help smaller companies work around SOC 2 and ISO certificate barriers.10:00 — Public procurement and its scale, roughly 20% of GDP, plus a look at public-private partnerships.15:00 — Local LLMs on a plane with no Wi-Fi, and comparing local model performance to frontier models.20:00 — Supply versus demand in AI infrastructure and whether hyperscaler token efficiency is quietly improving.25:00 — Whether AI will replace knowledge work tasks, and the shifting reality of what lawyers and other professionals actually do.30:00 — Reverse Turing test, digital identity verification, and the idea of a "pre-AI internet."35:00 — Model poisoning, RLHF, and the difference between pretraining and post-training.40:00 — Interleaved tool calling and how Tender Market ties pricing to task deliverables instead of billable hours.45:00 — RAG versus fine-tuning, prompt engineering, and when context windows actually matter.50:00 — Deterministic programming versus probabilistic agents, and when to build custom tools versus buy existing ones.55:00 — Juan's daily MCP stack (Supabase, GitHub, Calendly, CRM), and whether the folder-and-file system will survive the shift to AI-native interfaces.Key InsightsCertification requirements aren't dead ends—they're routing problems. When smaller companies got rejected from tenders for lacking SOC 2 or ISO certificates, Juan didn't turn them away. He found that EU procurement rules allow bidding as a consortium or subcontracting to a certified partner, turning a disqualifier into a workaround that builds trust with clients.Public procurement is a massive, underexamined market. Roughly 20% of GDP flows through public purchasing of private-sector goods and services, yet most people have no visibility into how tenders work or how governments post and award these contracts.Being wrong has become more socially acceptable. Juan traced this shift to the falling cost of information: in the Stack Overflow era, giving a wrong answer was costly, but now that answers are instant and abundant, both mistakes and corrections happen faster, changing how people learn and communicate.Task-based pricing beats hourly billing for AI-era services. Rather than charging per hour, Tender Market prices around the deliverable, winning a tender, which avoids the perverse incentive of hourly billing to be inefficient and instead rewards actually solving the client's problem.RAG and fine-tuning solve different problems. RAG helps a model reference large documents without hitting context limits, while fine-tuning changes a model's internal weights so it learns new behavior or style. Juan noted that true RAG use cases needing thousands of pages of context are rarer than the hype suggests.Deterministic code should replace repeated LLM calls once a pattern is found. Stewart described his own workflow: solve a task with an LLM a handful of times, then convert the repeated pattern into deterministic software so tokens are no longer spent on it, freeing the model for genuinely new problems.AI agents are never truly autonomous. Both hosts agreed that no matter how many steps an agent chains together, a human operator always initiates the first prompt, meaning accountability and intent trace back to a person even in multi-agent systems.
Brian Dye, Chief Executive Officer at Corelight, spends Black Hat USA 2026 asking every organization he talks to the same question. What are you doing with AI in the SOC? A year ago, he says, teams thought it was a good idea but were wary of it, and people knew LLMs could produce things without being sure what to do with them. Now he is talking with organizations building their own agents for incident response and for threat hunting, and running their own quality control on the output rather than taking it on faith. What decides how far an agentic SOC workflow can go? The data does. Brian Dye describes a three-legged stool where the model and the agents are only two of the legs. The third is the data going into the workflow, and without the right data the agents hit a headroom of logic. He credits three changes for the shift. Agentic development decomposes an investigation into smaller chunks that can be trusted individually. Time in the saddle has made teams better at separating claims from reality. And organizations now ask the workflow itself what it could not answer and what data it wishes it had. Why does a week like this one matter to product development? Corelight works on translating the network into the right fuel for AI, which means understanding the architecture each customer is building toward, whether that is an in-house SOC, a third party SOC, or a workflow running through their own SOAR or SIEM. Brian Dye also describes the Black Hat NOC as a room where the work looks different. Most security teams look for a needle in a haystack. The NOC team is finding the sharp needle in a stack of dull needles, separating illicit activity from the legitimate malware analysis training running on the same network, while using the room as a multi-vendor playground for new integrations and workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Brian Dye, Chief Executive Officer at Corelight On LinkedIn: https://www.linkedin.com/in/brdye/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Corelight: https://corelight.com Corelight blog: https://corelight.com/blog Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS brian dye, corelight, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic ai, ai in the soc, security operations center, network detection and response, threat hunting, incident response, black hat noc, soar, siem, network evidence, agentic workflows Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Skype of Cthulhu presents a Call of Cthulhu scenario. This is Our Home by Jim Phillips. December 14, 1976 Staten Island, New York City, New York The residents complete research at the local university while Mr. Romero continues to peer into the past. Dramatis Persone: Jim as the Keeper of Arcane Lore Randall as Frank Romero, Electrical Engineer Rachel as Marsha Janelle, Waitress Steve as Trae Grier, Gas Station Attendant Edwin as Kevin Mazer, Chemistry Teacher Gary as Peter Michale, Ex Pro Quarterback Sean as Kirk Griffin, Actor Download Subcription Options Podcast statistics
What does it take to go from astrophysics to running operations at one of the fastest-growing AI companies in the world?In this Fan Favorite episode, Cameron Herold sits down with Victoria Weller, former Chief of Staff and now Lead of Operations at ElevenLabs, to revisit one of the show's most fascinating conversations. Victoria's path is rare: astrophysics, space medicine, quantum encryption, and Palantir, before landing at the AI voice company reshaping how the world listens.She breaks down what a Chief of Staff really does at an early-stage startup, how she cleared SOC 2 compliance in seven weeks, and why ElevenLabs grew so fast. They also get into voice cloning, deepfake safeguards, and surprising use cases across hospitals, transit, and accessibility.Whether you want a COO seat or you are building functions from nothing, Victoria's story is a masterclass in figuring it out fast. Listen now.Sponsored by:Redirect Health - Affordable healthcare benefits designed to make traditional insurance optional, with 24/7 access to primary care and Rx support that helps businesses reduce costs while keeping employees covered.Learn more: http://www.redirectcoo.com/Timestamped Highlights[00:00:44] – The ElevenLabs mission, and why an EPUB can become an instant audiobook[00:02:55] – Munich to Edinburgh to Berlin to New York: a career across four countries[00:04:06] – What actually happens to an astronaut's blood in zero gravity[00:07:54] – Lasers, quantum encryption, and the pivot toward tech[00:13:06] – Cameron asks the big ones: aliens, and are we living in a simulation?[00:19:12] – What ElevenLabs is really building, explained simply[00:20:50] – How context lets an AI voice sound genuinely sad or genuinely happy[00:28:12] – The accessibility use cases the team never saw coming[00:31:03] – Cloning a late loved one's voice, and the compliance behind it[00:33:16] – Stopping deepfake voice scams: watermarks and the AI Speech Classifier[00:38:31] – What a Chief of Staff actually does, and why it feels like a SWAT team[00:40:32] – Does a great Chief of Staff work themselves out of a job?[00:47:07] – The advice Victoria would give her 21-year-old selfAbout the GuestVictoria Weller is the former Chief of Staff and now the Lead of Operations at ElevenLabs, the AI voice company behind lifelike text-to-speech and voice cloning, where she owns internal operations, compliance, and hiring. She cleared the company's SOC 2 process in seven weeks. Before ElevenLabs she was a reliability engineer at Palantir Technologies in New York and London. Her background spans astrophysics at the University of Edinburgh, space-medicine research in Berlin, and a master's in applied physics from Columbia University.