POPULARITY
Categories
We're talking obsession, manipulation, unreliable narrators, morally questionable characters, and that ending. Come debate the theories, red flags, and the ending that had readers screaming, “WHAT DID I JUST READ?!” Books mentioned this episode: Verity by Colleen Hoover Girl Dinner by Olivia Blake The Vampire's Cult by Chet Harden Queens and Kings by Lucy Worsley Kiss Slay Replay by Rachel Harrison Daughter of Fortune by Isabel Allende Tempest by Victoria Aveyard The Stonewater Kingdom duology by Rachel Gillig Hotel Ruby by Suzanne Young The Lonely Hearts Hotel by Heather O'Neill Daughter of the Siren Queen by Tricia Levenseller The Ring and the Crown by Melissa de la Cruz Dividing Eden by Joell Charbonneau Play Nice by Rachel Harrison
Your Outlook account recovery will accept an authenticator code on its own. No password, no inbox, no phone number. Anyone holding that TOTP secret owns the account, and the second factor you bought to survive credential theft becomes the only thing in the way.Koen Kandelaars found one sitting in a PDF on a public help page at the NOS, the largest news organization in the Netherlands. He scanned a QR code out of an onboarding manual and had a real employee's second factor on his phone. Rob Maas, Field CTO at ON2IT, walks the full chain with the attacker himself: eleven vulnerabilities in the first responsible disclosure, a twelfth Koen estimates at 1 to 5 million euros, and the recovery flow nobody tested.Timestamps(00:00) - MFA was on. He got in anyway. (02:04) - Why the biggest news organization became the target (03:24) - Mapping the attack surface before touching anything (04:54) - Eleven findings in the first responsible disclosure (08:50) - The Media Cloud help page and the live TOTP QR code (11:19) - How the password reset removes your second factor (14:29) - The 1 to 5 million euro estimate, and what to fix Key Topics CoveredAttack surface discovery against a large public broadcasterResponsible disclosure done well: response time, remediation, and recognitionWhere the next generation of defenders comes from, and how they choose a sideRelated ON2IT Content & Referenced Resources:Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams
Brian and Aaron interview Gavriel Cohen, co-founder and CEO of Nanoco and creator of the open-source agent framework NanoClaw, about securing AI agents in enterprise environments. Cohen shares how he built NanoClaw after discovering major security and safety gaps while using agents for an AI native marketing agency, and how the project grew to over 30,000 GitHub stars and over half a million downloads. They discuss why Fortune 500s, financial institutions, universities, and government groups feel urgent pressure to adopt agents but are blocked by control, privacy, and security concerns. Cohen outlines a zero-trust approach using microVM isolation, no credentials inside agent environments, a policy-enforcing gateway with granular controls, audit logs, cost attribution, and human-in-the-loop approvals at key decision points.SHOW: 1062SHOW TRANSCRIPT: The Enterprise AI Show #1062 TranscriptSHOW VIDEO: https://youtu.be/h906EEQSRs8SHOW LINKS:NanoClaw on GitHubNanoCo homepageTechCrunch: The wild six weeks for NanoClaw's creator that led to a deal with DockerThe New Stack: Gavriel Cohen found his own code inside OpenClaw, so he walked awayOpenAI: The Hugging Face incident and the road aheadSHOW SPONSORS:Nasuni - Activate your data for AI and request a demoNordLayer - Use ENTERPRISE10 for 10% offGUEST BIO:Gavriel Cohen is co-founder and CEO of NanoCo, and creator of NanoClaw, the open-source agent harness he built as a small, auditable, secure alternative to OpenClaw. He spent a decade as a developer and team lead at Wix before building NanoClaw in a weekend, a project that has since drawn a Docker integration and an outside security review. He holds a BSc in Physics and Computer Science from Tel Aviv University.FEEDBACK?Email: show @ the enterprise ai show dot comBluesky: @TheEntAIShow.bsky.socialTwitter/X: @TheEntAIShowInstagram: @TheEntAIShow
In this insightful episode of The Brand Called You, Ashutosh Garg sits down with Dennis O'Shea, Founder and CEO of Mobile Mentor, a global leader in the Microsoft partner ecosystem.Recorded in Nashville, Tennessee, Dennis O'Shea shares more than 20 years of experience in technology and entrepreneurship, discussing the evolution of mobile technology, the crucial balance between security and productivity, and the impact of Gen Z on the workplace.Discover why 95% of AI deployments fail to deliver meaningful results, what separates successful AI strategies from experimentation, and why going passwordless should be a priority for organizations.Dennis O'Shea also explores the essentials of a Zero Trust cybersecurity model, how Gen Z can either propel or compromise an organization, and which skills professionals need to remain effective in an AI-first world.Whether you're a business leader, technologist, or simply curious about the future of work, this episode offers practical wisdom and leadership lessons for navigating the AI era.
The following article of the Professional Services industry is: 'Cybersecurity: Why Legacy Telnet and Zero Trust Flaws Persist' by Carlos Lozano, CEO, Rent A Hacker.
What can 25 years of protecting the President teach the cybersecurity world? In this episode, Raghu Nandakumara sits down with Hazel Cerra, Director of Digital Security Convergence at BlackCloak and a 25-year veteran special agent of the U.S. Secret Service, to explore what protective intelligence can teach cybersecurity about defending the human attack surface.Hazel draws on her path from investigating counterfeit and credit card fraud, to protecting President Clinton, to pioneering critical systems protection for presidential visits, sharing how she came to see the Secret Service's layered "zero fail" security model as a direct parallel to Zero Trust, and why understanding an adversary's motive, means, and opportunity is as critical in cyber as it is in physical protection.Raghu and Hazel discuss:How the Secret Service evaluates and prioritizes threats using motive, means, and opportunityWhy "zero fail" protection is the same discipline as Zero Trust securityHow cyber convergence changed physical protection, from hackable elevators to compromised camerasWhy executives' home networks have become the new "path of least resistance" for attackersBalancing security with usability, without creating unnecessary frictionHow deepfakes and AI impersonation are changing verification and executive riskHazel closes with a practical tip for spotting a deepfake on a video call, and a reminder that as executives become as visible as presidents once were, protecting them has to extend far beyond the corporate perimeter.Stay connected with our host Raghu on LinkedInFor more information about Illumio, check out our website at illumio.com
Roei Ganzarski is the President and Chief Executive Officer of Alitheon, the Bellevue, Washington company behind FeaturePrint, and he isn't a founder of it. He calls himself a mercenary CEO, which is the fourth time he's been brought into a group of mathematicians and physicists who built something remarkable and then wanted a different set of skills in the building. His degree is in economics and finance. He says the pleasure of the job is usually being the least smart person in the room, and his rule for the team is that they don't have to explain it to their mother, they have to explain it to him. What Alitheon does is biometrics for things. The argument starts with people. We used to identify a human with a badge or a passport, then governments worked out that a proxy can be lost, transferred, faked or manipulated, so they moved to fingerprints and irises instead. A twin can carry his brother's real driver's license into a real building, and the document is real and the person is real, and the link between them is the lie. Physical products are still stuck at the proxy stage. A barcode, or a hologram that reads as authentic mostly because it's shiny and the picture changes when you tilt it. The mechanism is worth hearing him explain. No machine can make the same thing twice, so design engineers publish a tolerance band, and everything inside that band passes quality control and looks identical and works identically. Alitheon's math reads the differences that are still there inside that band, and turns them into what they call a FeaturePrint. The fingerprint exists because the thing was manufactured, which means it can't be peeled off, swapped, or re-issued with the paperwork. He puts the odds of 2 products carrying the same manufacturing signature at one in six and a half trillion. It runs on off-the-shelf industrial cameras, there's no training phase, and he says there's no machine learning anywhere in it. His words are discrete mathematics. Then host Jon McLachlan, co-founder of YSecurity and Cyberbase.ai, puts his security hat on and asks about hardware tampering in transit, and Roei makes the argument this episode is titled after. Zero trust says verify everything connecting to your network. The cyber runs on hardware. And the hardware is trusted because a sticker says who made it and where. He's presented this to rooms of cybersecurity people who told him hardware isn't their problem. The 4 markets he sells into are all versions of one idea he calls high consequence items, which covers expensive goods like the gold bullion that goes into national banks, anything that goes in or on a body, and then transportation and defense parts where the consequence of getting it wrong is somebody getting hurt. The example that stays with you is the aircraft engine supplier caught in the United Kingdom selling real used parts with fake paperwork saying they were new. Fatigued parts that were supposed to be destroyed at end of life went into commercial aircraft, and nobody found it for 5 years, and it wasn't an accident that found it. Also in this one. Why a syringe that knows its own manufacturing date closes a loophole that the box can't. Why counterfeit and gray market are 2 different problems, and why a customer's own distributors are sometimes the people being caught. Why several customers won't publicize that they use this at all. Why Alitheon doesn't need to keep the images, or much data at all. The coin collector at the trade show whose question started the whole company. The day he had to tell roughly 40% of a team they were done, and why he did it himself instead of sending their managers. And the Friday all-hands he runs at every company he's joined, which starts with Arabic coffee he makes himself and the question of who made a really cool mistake this week. His ask for the audience is a bigger one than usual. He wants critical thinking back. In his framing the goal is to stop seeing a box at all, and specifically to stop handing the questioning to a large language model because it's easier than doing it yourself. Episode 103 of The Security Podcast of Silicon Valley. Brought to you by YSecurity, the security team that works next to yours. Your first 8 hours with 40+ security engineers are free at ysecurity.io/startups.
You already had the threat intel. The IP was on your blocklist, the file hash was known bad. So why did your MDR only raise an alert instead of blocking it? Lieuwe Jan Koning, Co-founder & CTO at ON2IT, and colleague Nicholai Piagentini, Technical Enablement Engineer at ON2IT, make the case for preemptive cybersecurity: the shift from detect-and-clean-up to block-first, and what it means for the future of MDR.Timestamps:(00:00) - Preemptive cybersecurity: what it means for MDR (00:59) - Why detect-and-clean-up is not enough (the leaking tap) (01:42) - You knew the threat: block first (03:34) - Fusing the SOC and operations teams (05:57) - Speed, seconds, and AI versus AI (08:15) - Data freedom and vendor lock-in (10:33) - Dynamic policy without breaking change control Key Topics Covered:Preemptive cybersecurity as the Gartner-flagged direction, and why MDR has to move past detect-and-respondTurning known indicators of compromise into automated blocks at the endpoint, network, and cloudCollapsing the SOC and operational teams so detection and enforcement act as oneSub-second response, AI-driven attacks, and why MTTD and MTTR need to convergeData freedom and data sovereignty, and avoiding vendor cloud lock-inRelated ON2IT Content & Referenced Resources:Threat Talks website: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams
Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems. Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris argues the hard, expensive work is triage, context, and prioritization, now amplified as vendors ship far more patches and organizations struggle to keep up without strong asset inventory, preparedness, and Zero Trust progress. She warns AI model capabilities are outpacing monitoring and containment, especially with open-weight models, and says regulation should focus on requirements like real-time monitoring without harming defenders. The conversation also covers the reemergence of the old tool-access debates, Microsoft's clash with researcher "Nightmare Eclipse," the rise-and-fall of "security civilizations," Luta Security's work improving internal maturity, concerns about shrinking entry-level talent pipelines, and a closing call to consider universal basic income as part of our strategy to deal with AI's impact on the world. 00:00 Weekend Show Intro 00:07 Katie Moussouris Background 02:00 Bug Bounties Then and Now 03:31 AI Hype and Model Escapes 05:06 The Real Cost of Fixing 08:36 Smart AI Regulation 12:34 Tools for Defenders vs Rogues 15:53 Metasploit and Agentic Risk 17:25 Nightmare Eclipse and Microsoft 21:53 Luta Security Today 24:28 Training the Next Generation 27:46 Hope, UBI, and Wrap Up
As AI becomes part of everyday work, enterprises face a difficult challenge: how do you protect identities, devices, applications, and data without making employees less productive?In this episode of XTraw AI, Raghu Banda speaks with Denis O'Shea, Founder and CEO of Mobile Mentor, about the changing security landscape, Zero Trust, passwordless identity, cloud-native workplaces, and why employee experience has become a critical part of enterprise security.We also explore a provocative question: are employees really the weakest link—or are poorly designed technology experiences pushing them toward risky workarounds?In this episode, we discuss:Why traditional security controls are struggling in an AI-enabled, hybrid workplace and what “secure by design” should mean today.How Zero Trust, passwordless identity, and cloud-native endpoint management can improve both security and employee productivity.Why AI adoption is ultimately an employee-experience challenge, and what enterprises must get right to turn AI investments into meaningful business value.You can reach @ Denis O'SheaMy LinkedIn @ Raghu BandaWebsite @ XTrawAI
Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn't end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how? Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are the only way to defend against these sophisticated wire fraud attacks. Optiv: The One Partner to Advise, Deploy and Operate. That's Cybersecurity Simplified - Black Hat interview with John Hurley, Chief Revenue Officer of Optiv This segment will focus on Optiv's unmatched ability to advise, deploy and operate complete cybersecurity programs. With more than 6,000 clients and 450 technology partners, Optiv is the one clients trust to handle real-world cyber complexity, reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at https://securityweekly.com/optivbh. The Shift to Machine-Led Security: What's Next for Cyber Defense - Black Hat interview with Galina Antova, CEO and Co-Founder of Kai Artificial intelligence is fundamentally changing cybersecurity- not only by making attacks faster and more sophisticated, but also by forcing defenders to rethink how security operations are built. In this conversation, Kai CEO and co-founder Galina Antova discusses why the industry is moving toward machine-led security, what is preventing organizations from trusting autonomous AI, and what recent survey data from hundreds of CISOs reveals about where cybersecurity is headed next. To learn more about Kai, please visit: https://securityweekly.com/kaibh Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-463
Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn't end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how? Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are the only way to defend against these sophisticated wire fraud attacks. Optiv: The One Partner to Advise, Deploy and Operate. That's Cybersecurity Simplified - Black Hat interview with John Hurley, Chief Revenue Officer of Optiv This segment will focus on Optiv's unmatched ability to advise, deploy and operate complete cybersecurity programs. With more than 6,000 clients and 450 technology partners, Optiv is the one clients trust to handle real-world cyber complexity, reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at https://securityweekly.com/optivbh. The Shift to Machine-Led Security: What's Next for Cyber Defense - Black Hat interview with Galina Antova, CEO and Co-Founder of Kai Artificial intelligence is fundamentally changing cybersecurity- not only by making attacks faster and more sophisticated, but also by forcing defenders to rethink how security operations are built. In this conversation, Kai CEO and co-founder Galina Antova discusses why the industry is moving toward machine-led security, what is preventing organizations from trusting autonomous AI, and what recent survey data from hundreds of CISOs reveals about where cybersecurity is headed next. To learn more about Kai, please visit: https://securityweekly.com/kaibh Show Notes: https://securityweekly.com/bsw-463
Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn't end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how? Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are the only way to defend against these sophisticated wire fraud attacks. Optiv: The One Partner to Advise, Deploy and Operate. That's Cybersecurity Simplified - Black Hat interview with John Hurley, Chief Revenue Officer of Optiv This segment will focus on Optiv's unmatched ability to advise, deploy and operate complete cybersecurity programs. With more than 6,000 clients and 450 technology partners, Optiv is the one clients trust to handle real-world cyber complexity, reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at https://securityweekly.com/optivbh. The Shift to Machine-Led Security: What's Next for Cyber Defense - Black Hat interview with Galina Antova, CEO and Co-Founder of Kai Artificial intelligence is fundamentally changing cybersecurity- not only by making attacks faster and more sophisticated, but also by forcing defenders to rethink how security operations are built. In this conversation, Kai CEO and co-founder Galina Antova discusses why the industry is moving toward machine-led security, what is preventing organizations from trusting autonomous AI, and what recent survey data from hundreds of CISOs reveals about where cybersecurity is headed next. To learn more about Kai, please visit: https://securityweekly.com/kaibh Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-463
Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn't end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how? Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are the only way to defend against these sophisticated wire fraud attacks. Optiv: The One Partner to Advise, Deploy and Operate. That's Cybersecurity Simplified - Black Hat interview with John Hurley, Chief Revenue Officer of Optiv This segment will focus on Optiv's unmatched ability to advise, deploy and operate complete cybersecurity programs. With more than 6,000 clients and 450 technology partners, Optiv is the one clients trust to handle real-world cyber complexity, reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at https://securityweekly.com/optivbh. The Shift to Machine-Led Security: What's Next for Cyber Defense - Black Hat interview with Galina Antova, CEO and Co-Founder of Kai Artificial intelligence is fundamentally changing cybersecurity- not only by making attacks faster and more sophisticated, but also by forcing defenders to rethink how security operations are built. In this conversation, Kai CEO and co-founder Galina Antova discusses why the industry is moving toward machine-led security, what is preventing organizations from trusting autonomous AI, and what recent survey data from hundreds of CISOs reveals about where cybersecurity is headed next. To learn more about Kai, please visit: https://securityweekly.com/kaibh Show Notes: https://securityweekly.com/bsw-463
The new NIST Cybersecurity Framework 2.0 is out, and most teams still ask the same question: what do I do tomorrow? Lieuwe Jan Koning sits down with NIST's Amy Mahn and Daniel Elliott to turn the framework into a concrete next step. Governance is now its own function. Profiles tell you where you are and where you need to be. And the Quick Start Guides give a 15-page answer to a problem most people think needs 300 pages.If you run security with limited resources, this episode shows you where to start and why the whole thing is free.Timestamps00:00:00 The framework changed. What do you do tomorrow? 00:02:00 Why Govern became its own function 00:05:49 Profiles: current state, target state, gap analysis 00:08:08 Community profiles: sharing across a sector 00:10:29 Quick Start Guides and mappings to ISO 27001, SOC 2, HIPAA 00:14:24 No CISO? Where small businesses start 00:17:50 The future of CSF and how to contributeKey Topics CoveredWhy governance moved out of "Identify" and became its own function in CSF 2.0, and what that signals about cyber risk at board level.How organizational and community profiles turn the framework into a current-state, target-state, and gap analysis you can act on.Why CSF 2.0 stopped being a single PDF and became guides, spreadsheets, mappings, and search tools.How CSF maps to ISO 27001, SOC 2, and HIPAA so you report once instead of many times.Where a small business or an IT manager wearing every hat should actually begin.Related ON2IT Content & Referenced Resources: NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework NIST CSF Quick Start Guides: https://www.nist.gov/cyberframework/quick-start-guides National Cybersecurity Center of Excellence (NCCoE): https://www.nccoe.nist.gov/ NIST CSF contact: csf@nist.gov Threat Talks website: https://threat-talks.com/
We've got a repeat guest on the show today. Alex Dow is back. Co-founder of Mirai Security, and currently an enterprise security architect for a large financial firm, and honestly one of my favorite people to talk security with. Alex has done federal security work, and securing the actual Olympics, now then a security consulting firm.If you've been listening a while, you might remember Alex from way back in episode 11 and then again in episode 96.Today's round three, and we're going fully nerd-out mode on the OpenAI/Hugging Face hack. Walking through the signals and understanding how this type of attack was seen from a defensive side.The timeline visualization of the Hugging Face attack that Alex referenced.This episode is brought to you by Opsleader Pro. A place for MSP owners and managers to get the systems and tools they need to build a stable and growing MSP. Part group coaching, part peer group, everything you need to run a successful MSP. (00:00) - Welcome Back Alex Dow (00:50) - What Happened in the Hack (02:22) - Mythos and AI Hype (06:05) - Throughput Beats Creativity (08:04) - Sandbox Escape Explained (11:02) - Swarm Agents and Breadcrumbs (14:13) - Reward Hacking and Alignment (19:30) - Four Days Undetected (21:27) - Blue Team Limits and Guardrails (25:28) - Detecting AI in the Noise (30:50) - Using Your AI Against You (34:30) - Honeytokens and Deception (37:22) - Zero Trust as a Baseline (38:59) - AI Botnets and Key Theft (43:01) - Wrap Up and Takeaways
CyberPrinceton Podcast: Policy, Legislation, and RegulationsEpisode: 003Title: Chief Sovereign Security Scientist (CSCI) — Deconstructing the Declaration of Independence: Baseline Controls & System Intent Series: Policy, Legislation, and Regulations Host: Princeton Brooke, CISSP, PenTest+ CySA+ | Chief Security Scientist & Systems Engineer at Corporate CybersecurityEpisode OverviewWe are going live today for Episode 003.Building on my pre-engineering and scoping work in Episode 002, today I conclude my deep-dive analysis of the Declaration of Independence as a foundational enterprise specification for analyzing and authoring policy that addresses: enterprise governance, regulations, cybersecurity and privacy, critical infrastructure, national security and international relations. I also begin to assess the documents for their contribution in identifying the need for policy that shapes international relations, war powers, trade, commerce, labor relations, finance and accounting.Drawing from concepts in Sovereign Enterprise Security, I examine how the grievances, sovereign declarations, and foundational assertions of 1776 translate directly into technical system requirements. Using the Sovereign Enterprise Framework (SEFF) and SovSecOps, we will discuss and eventually demonstrate how to turn core legal intent into machine-readable Policy-as-Code (PaC), root trust boundaries, and automated regulatory processing logic—setting the stage for my architectural analysis of the U.S. Constitution in future episodes.__What I'm covering today and in the next couple of episodes:Declaration as System PID: Finalizing the Declaration of Independence as a formal Project Initiation Document and root security requirement baseline.Grievance Translation:Converting 18th-century operational failure modes (colonial grievances) into modern Zero Trust controls, access barriers, and threat models.Sovereign Root of Trust:Establishing identity, data sovereignty, and independent governance primitives before building the constitutional architecture.__Who Should Tune In:Systems & Enterprise Architects(Policy-as-Code & root system requirements)Cybersecurity & Defense Leaders (Zero Trust boundaries & sovereign security)GRC & Compliance Officers (Traceability & automated requirement engineering)Policy Researchers, Consultants & C-Suite Strategists(Computational law & institutional continuity)Bring your questions and edge cases to the live chat for interactive Q&A.
In this episode of Reimagining Cyber, Tyler Moffitt talks with Robert Salzwedell about what happens when attackers get past the firewall — and why keeping them out is no longer enough.With cloud services, remote workers, SaaS applications and compromised credentials blurring the boundaries of the traditional network, organisations can no longer assume that someone is safe simply because they are already inside.Robert explains why organisations need to look beyond the perimeter, understand where their sensitive data lives, rethink how they trust identities, and use behaviour to spot suspicious activity. They also discuss Zero Trust, AI agents, continuous security validation and how organisations can limit the damage when an account or device is compromised.In this episode:Why the traditional network perimeter is no longer enoughWhat happens when attackers use legitimate identitiesWhy understanding your data is critical to securityHow Zero Trust can help limit access and reduce riskThe growing security challenge around AI and AI agentsWhy security needs to be continuously assessed and improvedPractical steps organisations can take to reduce their exposureA conversation about moving from simply trying to keep attackers out to making sure that, when they do get in, they can't get very far.As featured on Million Podcasts' Best 100 Cybersecurity Podcasts Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com
Podcast: CYBR.SEC.CAST (LS 25 · TOP 10% what is this?)Episode: Pulling Pranks with Roman ArutyunovPub date: 2026-08-19Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationIn this episode of CYBR.SEC.CAST, Michael and Sam sit down with Roman Arutyunov, Co-Founder and Chief Product Officer at Xage, to explore how cybersecurity must evolve in the age of agentic AI. Roman shares his journey from early cybersecurity work to protecting critical infrastructure and explains why Zero Trust is more important than ever as AI agents gain greater access to systems, data, and critical resources. Roman also covers practical ways organizations can implement Zero Trust without creating a complex patchwork of security tools - and why protecting interactions at every layer is becoming essential.This episode is sponsored by XageThings Mentioned:Xage - https://xage.com/Mirai Virus - https://en.wikipedia.org/wiki/Mirai_(malware)Agentic AI Is Pushing Zero Trust Into Its Next Phase - https://www.cybrsecmedia.com/agentic-ai-is-pushing-zero-trust-into-its-next-phase/Do you have a question for the hosts? Reach out to us at media@cscgroupllc.com In this episode:Host: Michael FarnumHost: Sam Van RyderGuest: Roman ArutyunovDirector: Bill BrennerProducer: Lauren AndrusMusic by: August HoneyKeep up with our Conferences and Events:LinkedInXFacebookInstagramTikTokCYBR.SEC.CON.OT.SEC.CON.CYBR.HAK.CON.Keep up with CYBR.SEC.Media:LinkedInXFacebookInstagramTikTokYouTubeLearn About CYBR.SEC.Careers Non-Profit EffortsCYBR.SEC.CareersSubscribe to the podcast: AppleSpotifyYouTubeListen to our other shows:CYBR.HAK.CASTCYBR.MindedCYBR.Signal Thank you to our Media Partners:CYBR.SEC.CON.Breaking Through in Cybersecurity MarketingCYBR.SEC.CON. and OT.SEC.CON. OGGN (Oil & Gas Global Network)UtilSecPacket PushersCYBR.SEC.CON. and CYBR.HAK.CON. BarCode PodcastCyber Distortion PodcastKill Chain RadioThe Phillip Wylie ShowVulnerable UThe podcast and artwork embedded on this page are from CYBR.SEC.Media, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface. Resources https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This interview is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-397
As AI reshapes the enterprise, security must evolve alongside it. Andrew Winkelmann, Global AI Security Lead, and Matt Lancaster, Accenture's AI & Data Lead, join Adam Geller, CPO at Zscaler, to explore zero trust, AI governance, and the strategies organizations need to operate securely at machine speed. From developer accountability to balancing innovation and risk, this episode delivers practical insights for leaders navigating the age of agentic AI.
Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface. Resources https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This interview is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/asw-397
Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface. Resources https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This interview is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-397
Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface. Resources https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This interview is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/asw-397
In this episode of Tank Talks, host Matt Cohen sits down with Karl Holmqvist, co-founder and CEO of Lastwall, a FedRAMP-certified identity security platform built for the highest-risk use cases. Karl has been deep in cybersecurity since the 1990s, with early experience building critical infrastructure, including Canada's first high-speed mobile data network, and a recent focus on identity security at the forefront of making systems quantum-resilient. In this conversation, they explore the evolution of Lastwall from early behavioral biometrics and cognitive signals to today's hybrid post-quantum cryptography.They also dig into the journey to FedRAMP approval and what it really takes to sell to the hardest customers on the planet, from the DOD's Innovation Unit to critical infrastructure operators globally. Karl shares his view on why hybrid cryptography is the only responsible path right now, the magnified risk of the AI agent era, and his strongly held belief that when it comes to quantum resiliency, you're either going to be too early or too late.Whether you're a founder navigating a path into regulated markets, a security leader thinking about the agentic AI era, or just curious about what it takes to protect critical infrastructure, Karl delivers a grounded, technical, and occasionally unsettling look at where identity security is headed.–A big thanks to our sponsor, Moomoo CanadaThis is the kind of tooling that used to live on a Bloomberg terminal, but now it is on your phone, just a few taps away. They offer real-time data, full options chains, and an AI assistant that actually explains trading strategies.Moomoo is the perfect place for people who want to take their money seriously. Open an account today at moomoo.caGrowing Up in Dubai During the Gulf War (03:50)* Karl's childhood in Dubai as an expat during the Gulf War* Visiting the USS Nimitz and seeing 5,000 people living on an aircraft carrier* How jets overhead and allied ships shaped his early view of technology and defense* The BBS era and the thrill of finding information that wasn't available to everyoneFrom Mobile Data Skepticism to Building Canada's First High-Speed Network (05:31)* Why people thought mobile internet was “the stupidest thing” in the early 2000s* Building a data-only carrier when no one believed you'd want internet everywhere* The Nokia Communicator as his favorite tech gadget and early glimpse of mobile data* Connecting critical infrastructure and discovering default credentials left wide openThe Wake-Up Call: Wastewater Plants and Unsecured Dams (12:58)* Finding a wastewater flow control valve dangling on the internet with admin/admin credentials* The “air-gapped” power plant where an engineer plugged his BlackBerry in to charge* How Shodan and friends revealed dams and power facilities publicly accessible* The founding of Lastwall: “Hackers will be everywhere. We've got to do something.”From Behavioral Biometrics to Quantum Resilience (19:11)* Why 85% of hacks still use valid stolen credentials, the same as the 1990s* Early experiments with keyboard dynamics, mouse movements, and cognitive biometrics* Tracking Peter Shor's algorithm since university and the IBM factorization of 15 in 2001* The 2017 to 2018 decision to embed quantum resiliency natively into LastwallSelling to the Pentagon: DIU and the “Hard Mode First” Strategy (26:07)* Landing the first major deployment with the U.S. Department of Defense Innovation Unit* How DIU pioneered procurement that matches innovation cycles, months instead of years* The advice from Carbon Black founders: build the regulated stack first* Why defense tech used to shut VC doors and how times have changedFedRAMP, Canada, and the Case for Harmonization (33:25)* FedRAMP as the gold standard: do compliance once, reuse everywhere* The Canadian challenge: every agency doing its own security review* Why Canada should base its program on NIST 800 and harmonize with the U.S.* The reality of the integrated North American power grid and shared defenseAI Agents and the Blast Radius of Credential Theft (37:44)* Why 50 to 100 agents per human in 2 to 3 years will magnify damage exponentially* The OpenClaw lesson: agents do what agents do, not what you expect* The “YOLO” approach to AI deployment and why enterprises aren't calling enough* Advice for founders: sandbox first, don't connect your whole drive, go slowlyThe $60M Series A Extension and the Path Forward (43:13)* Raising BDC Capital's Strong North Fund led by Major General (Ret.) Peter Dawe* The milestone of FedRAMP certification and opening the floodgates to U.S. agencies* Deploying in disconnected environments: field containers for critical infrastructure* Why defense is ultimately about protecting the economyAbout Karl HolmqvistKarl Holmqvist is co-founder and CEO of Lastwall, an identity-as-a-service platform built on Zero Trust principles and public key infrastructure, hardened with post-quantum cryptographic resilience. Lastwall serves the U.S. Department of Defense and a growing number of civilian government agencies and critical infrastructure operators. Karl has been a cybersecurity enthusiast since the 1990s, with a background spanning telecommunications infrastructure (including building one of Canada's first high-speed mobile data networks), renewable energy infrastructure across the Middle East, North Africa, and Southern Europe, and international investing. He studied at Mount Allison University and is based in Vancouver, BC.Connect with Karl Holmqvist on LinkedIn: https://www.linkedin.com/in/karlholmqvist/Visit Lastwall's website: https://www.lastwall.com/Connect with Matt Cohen on LinkedIn: https://ca.linkedin.com/in/matt-cohen1Visit the Ripple Ventures website: https://www.rippleventures.com/ This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit tanktalks.substack.com
According to Greg Touhill, the first CISO of the United States, complexity is the bane of IT security. Today, that lesson remains especially relevant. In this week's episode of Feds At The Edge, several thought leaders share how agencies can reduce complexity, integrate legacy systems, balance usability with security, and build a Zero Trust environment that continues to improve over time. Robert Skinner of Skinner's Strategic Solutions, explores the power of reducing system complexity and data flows to unlock clearer analytics. David Klink of Leidos explains the challenge agencies face when they try to "shoehorn legacy identity methods" into modern enterprise compliance. Continuous monitoring and tools that identify systems operating outside enterprise Identity, Credential, and Access Management requirements can help bridge that gap. Tune in on your favorite podcast platform to hear practical, actionable ideas for managing out-of-compliance infrastructure, maintaining continuous evaluation, and driving modern security compliance without sacrificing user experience.
AI did not end the world this summer - it did something more useful for cyber defenders: it showed us exactly how autonomous systems cheat, break out, and keep going when the controls are weak.Dr. Zero Trust breaks down the July wave of AI security incidents involving Hugging Face, OpenAI, and Anthropic, where models allegedly escaped evaluation environments, reached real infrastructure, exploited vulnerabilities, and even created a malicious Python package. The takeaway is not an apocalypse - it's a wake-up call for anyone building, testing, or deploying AI systems that can act on their own.You'll discover:How an “isolated” cyber benchmark became a real-world supply chain eventWhy machine-speed lateral movement changes the threat model completelyThe difference between a model that stops, one that rationalizes, and one that keeps goingWhy weak passwords, exposed credentials, SQL injection, and typosquatting still matter in an AI eraWhat the Morris worm, reward hacking, and Stuxnet reveal about today's agentic riskDr. Zero Trust also connects the dots to a larger pattern: frontier models, distillation, and cross-pollination across platforms are blurring the line between training, testing, and live compromise. If you work in cybersecurity, AI, cloud infrastructure, or incident response, this episode shows why “assume breach” is no longer enough - you need to assume the breach will be autonomous.Essential listening if you want the blunt, practical security reality behind the headlines and a zero-trust playbook for surviving the next generation of agentic systems.
By Doug Green Nearly 85% of healthcare organizations experience network or security disruptions that can affect patient care and privacy, while two-thirds of healthcare IT teams say they are strained or constantly firefighting, according to new research released by Nile. The findings are part of Nile's new report, “The State of Networking, Security & AI in Healthcare,” based on responses from more than 300 IT leaders, C-level executives, and network and security practitioners worldwide. In a Technology Reseller News podcast, I spoke with Shashi Kiran, CMO of Nile, about what the findings reveal about healthcare networking and why the problem goes beyond cybersecurity tools to the underlying architecture. Healthcare networks now connect hospitals, outpatient facilities, imaging centers, remote locations and large numbers of medical and IoT devices. Many of those devices cannot simply be patched or equipped with traditional security agents, yet they may operate alongside critical systems such as electronic health records. That complexity has consequences. According to Nile, 38% of healthcare organizations experience network or security disruptions at least weekly. Cybersecurity threats and ransomware ranked as the top network challenge at 27%, ahead of staffing shortages and lack of expertise at 23%. Kiran argues that adding more staff alone will not solve the problem. About 66% of healthcare IT teams described themselves as strained or firefighting, while only 18% said they were comfortably managing network operations. “Most often people think that it's throw more resources at the problem,” Kiran says. “More often than not, that's not the case.” Zero Trust and the Containment Gap Only 38% of organizations surveyed report partial or full Zero Trust implementation, while 26% are aware of Zero Trust but have no concrete plans to implement it. The research also found that only 20% of respondents are confident their networks can contain a cyber incident across medical, IoT, clinician and guest devices. Sixty-one percent are not confident or only slightly confident. Kiran says the challenge is creating a consistent security posture across environments that may include conventional IT, operational technology and medical devices managed by different teams. “Zero Trust is not a protocol or a feature,” he says. “It's really a holistic posture that you need to have on an end-to-end basis.” He also points to the complexity of legacy infrastructure, describing some environments as a “Frankenstein architecture” assembled over time from different systems, vendors and operational processes. That complexity can make troubleshooting more difficult and itself become a security problem. AI and NaaS The report also shows strong interest in new operating models. Sixty-four percent of healthcare organizations surveyed are open to adopting Network-as-a-Service to simplify operations and strengthen security, while 20% of more mature organizations now view AI-driven automation as essential to running their networks. Nile argues that combining Zero Trust, automation and networking into the infrastructure itself can help healthcare IT organizations move from constant firefighting toward more proactive operations. For Kiran, that shift ultimately comes back to healthcare's core mission. “In healthcare, the network is the lifeblood of patient care — when it falters, both patient care and patient privacy are put at risk,” he said in announcing the research. The takeaway is that networking, security and patient care are increasingly interconnected. As healthcare organizations enter their next infrastructure refresh cycle, Nile believes the opportunity is not simply to replace old equipment, but to rethink an architecture that has become too complex to operate and secure effectively. The full “The State of Networking, Security & AI in Healthcare” report is available from Nile.
Federal Tech Podcast: Listen and learn how successful companies get federal contracts
John Gilroy and Danelle Osworth discuss Delinea's privileged access management (PAM) solutions on the Federal Tech Podcast. Delinea's unique selling points include delivering just-in-time access, a hybrid platform for on-premises and cloud environments, and continuous verification of identities. During the interview, Ginelle has an insightful comment about Zero Trust and the federal government. She looks at Zero Trust as an opportunity for the government to take cybersecurity steps in the right direction. The key concept is to begin the Zero Trust journey, not necessarily where they begin. Oswroth goes on to say that identity security is the foundation for everything in cyber. In the future, standing privilege will feel as outdated as passwords on a sticky note. But today's threat is unyielding. This means that an identity solution must be able to continuously monitor access as well as credentials. Osworth emphasizes the importance of zero trust principles and the practical application of identity management. Delinea's platform supports 99.995% uptime and encrypted vaulting for machine and AI identities. They highlight the need for continuous authentication and authorization to manage the influx of non-human identities. The conversation also touches on the challenges of balancing security with innovation in the federal government.
AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July developments. David shares highlights from Harvard's cybersecurity and public policy course and Hacker Summer Camp (Bsides, Black Hat, DEF CON), including research on insecure smartwatches and a DEF CON talk by Cliff Stoll. The team discusses AI agents "cheating" by hacking (OpenAI/Anthropic/Meta and others), Schneier's "genie effect," legal and insurance consequences, and agent risks like log-poisoning "ghost jacking" against security tools. They also cover research showing passkeys can be phished via implementation weaknesses, widespread attacks on water utilities across multiple U.S. states and Quebec, and a Russian campaign targeting public Wi‑Fi. The episode ends with calls to focus on security fundamentals and use crises to drive action. 00:00 Sponsor NordLayer 00:37 Weekend Month Review 01:40 Harvard to Hacker Camp 03:25 DEF CON Highlights 06:20 Delta Flight Pineapple 08:20 AI Agents Gone Rogue 15:09 Genie Effect Explained 21:43 Accountability and Regulation 25:13 Ghostjacking Security Logs 28:04 Back to Fundamentals 29:27 Zero Trust vs Agents 31:10 Passkeys Aren't Proof 32:39 Phishing Forever Reality 33:48 Water Utilities Under Attack 37:22 Why Water Is Fragile 41:50 Stop Exposing OT Online 43:02 Tabletop Uninsurable Chaos 49:34 Public Wi-Fi Still Risky 51:08 Media Picks and Wrap-Up 53:02 Never Waste a Crisis 55:13 Sponsor NordLayer
In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture. Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049. Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible. Instead of trying to re-architect entire networks, maybe it's time we learned to apply Zero Trust principles selectively against risky assets. It's a better approach than the status quo, which involves liberal use of the “risk accepted” stamp. This episode is also available on YouTube Show notes
Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security. Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team. What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach. How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal. Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later. Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST David Hughes, SVP and GM of SASE and Security for Networking at HPE On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com/ HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Read the full stories at CISOSeries.com This week's Department of Know is hosted by Sarah Lane, with guests Peter Gregory, author of over 50 books on cybersecurity, and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Kevin Pickhardt, Executive Chairman of Pharos, a company that provides cloud-native enterprise print management solutions that help organizations modernize print infrastructure, improve security, and support … Read more The post The Printer Blind Spot: Why Zero Trust Must Include Print Workflows appeared first on Top Entrepreneurs Podcast | Enterprise Podcast Network.
What happens when an AI agent is compromised, manipulated, or simply does something nobody expected, but already has permission to access your most sensitive systems? In this episode of Tech Talks Daily, I speak with Geoffrey Mattson, CEO of SecureAuth, about why securing enterprise AI requires businesses to think beyond protecting models and start paying much closer attention to identity, authorization, access control, and what AI agents are actually allowed to do. Geoffrey argues that AI agents present a different security challenge from traditional software. Conventional applications can be tested against relatively predictable behavior. AI models are far less deterministic, particularly when prompt injection, excessive permissions, unexpected behavior, and autonomous actions enter the equation. His advice is to assume an agent could behave unpredictably and control what happens when it attempts to access a database, execute a financial transaction, call an API, or interact with another business system. We discuss what this means as companies race to introduce agentic AI. Geoffrey shares examples of employees granting AI tools permissions without fully understanding what they have approved, along with agents gathering information that creates unexpected privacy and compliance problems. This creates a difficult challenge for CIOs and CISOs. Boards want AI adoption because of its potential competitive value, while employees increasingly depend on AI tools to do their jobs. Simply blocking agents is unlikely to work. Security teams instead need mechanisms that allow innovation while controlling what those agents can access. Geoffrey explains why Zero Trust becomes particularly relevant here. Rather than authenticating a user or agent once and assuming it remains trustworthy, enterprises need to continually evaluate whether an action should be permitted at that specific moment. This leads to the concept of continuous authorization. Geoffrey explains how identity security is moving from asking "Who are you?" toward understanding intent, behavior, context, and authority for individual actions. This becomes increasingly important when one AI agent can create sub-agents, which can then create additional agents and pass permissions down the chain. We also discuss why agentic AI is exposing years of accumulated security debt. Many of the underlying problems are familiar: excessive privileges, inconsistent access controls, incomplete Zero Trust implementations, and systems that trust identities for too long. AI agents amplify those weaknesses because they can operate at machine speed. Geoffrey describes this as combining the unpredictability of humans with the power of machines. For CIOs, CISOs, security architects, identity teams, and business leaders deploying agentic AI, this conversation offers practical questions to ask before connecting agents to enterprise resources. What can the agent access? What authority does it have? Can that authority be reduced as tasks are delegated? Is every important action evaluated independently? And can access be revoked immediately when behavior changes? The goal is not to prevent organizations from using AI agents. It is to create a security layer that gives developers and employees room to experiment while ensuring agents only have the authority they need at the moment they need it. As autonomous AI becomes part of the enterprise workforce, identity alone may no longer be enough. Businesses increasingly need to understand intent, control authority, and continuously decide whether the next action should be allowed.
"We cannot solve our problems with the same thinking we used when we created them." – Albert Einstein Scott Alldridge is a tech-forward C-Suite Executive, Board Director, Amazon Best Seller Author and exceptional Problem Solver with deep experience in AI, cybersecurity, data governance and risk management spanning a broad array of industries. He is a transformational leader adept at driving organizational change, mitigating financial and reputation risk and formulating high-impact tech strategies that lead to significant value creation. ______ CYBERSECURITY SME. Scott's work is grounded in Zero Trust – a cyber-tech operations discipline for highly regulated environments. He has led and advised organizations operating under NIST CSF, NIST 800-53, NIST 800-171, CMMC and ISO 27001. Scott's experience also includes HIPAA, PCI DSS, SOX, GLBA, SOC 2, state privacy laws and cyber insurance requirements. In each engagement, Scott's primary goal is to support organizations by strengthening security, ensuring compliance and improving performance – without compromising business efficiency. ENGAGED BOARD MEMBER. Scott helps companies build future-ready infrastructures and leverage technology to strengthen organizational agility and drive profitable growth. He brings a unique blend of business acumen and technical proficiency to his roles as CEO, Advisor and Independent Board Director. Scott's board-level advisory experience includes strategic guidance on a variety of topics including digital transformation, cybersecurity governance, business strategy, portfolio growth and AI. PRAGMATIC LEADER. Scott builds accountable, cross-functional teams that deliver spot-on, data-driven results for their organization, clients and stakeholders. Guided by a shared set of "Mission, Vision and Values", Scott mentors emerging leaders to execute assignments with clarity and autonomy. As testament to his effective leadership style, Scott's core team has remained with him for more than 15 years. https://ipservices.com/ ______ EXPERIENCE and EXPERTISE Small Cap · Mid-cap · SMB · Startups · PE · Digital Transformation • Change Management · AI · IT Roadmaps · Cybersecurity · Continuous Improvement · Agile Methodology · SaaS · ERP Systems Cloud Services · IT Infrastructures · Growth Strategies · Risk Mitigation Business Development M&A Due Diligence • Acquisition Integration • Vendor Negotiations Audit Compliance • NIST • CMMC • GLP • SOX • Gramm-Leach-Bliley Act
Danny Jenkins, CEO and Co-founder of ThreatLocker, a global cybersecurity company, shares the latest cyber threats facing the world today, including when 'Zero Trust' is necessary, AI gents hacking other AI companies, and more.
Zero Trust for IT professionals — what it actually is, minus the vendor hype. NIST SP 800-207 in plain language, the six myths worth clearing up, and why your AD, MFA, and endpoint work already counts as a head start.Zero Trust is simultaneously the most oversold phrase in cybersecurity and one of the most useful ideas in it. If you already run infrastructure — sysadmin, network, cloud, ops — this breaks down the architecture using the systems you administer every day, then shows you where to actually start.No product pitch. No fear-mongering. Just the reasoning a blue team defender uses, explained simply.━━━━━━━━━━━━━━━━━━━━CHAPTERS━━━━━━━━━━━━━━━━━━━━0:00 The most oversold phrase in cybersecurity0:35 The moat dried up: why the perimeter stopped mattering1:45 What Zero Trust actually is (never trust, always verify)3:00 Where the term came from: Kindervag & Forrester, 20104:00 The architecture in plain English: NIST SP 800-2075:45 What Zero Trust is NOT: 6 myths7:15 A tale of two networks: the same attack, two outcomes9:15 Why IT pros are already halfway there10:15 How to actually start: Inventory → Threats → Controls → Scale11:15 The real shift (and where to go next)━━━━━━━━━━━━━━━━━━━━READ THE FULL BREAKDOWN━━━━━━━━━━━━━━━━━━━━Every source linked, written for reference:https://blueteam-academy.com/blog/zero-trust-it-professionals/━━━━━━━━━━━━━━━━━━━━GO DEEPER━━━━━━━━━━━━━━━━━━━━The decision process behind this video — Inventory → Threats → Controls → Scale — is what we teach. Learn to reason through any environment, not memorize tools:https://www2.blueteam-academy.com/from-it-to-cybersecurity/Get Keep IT Safe — practical defensive security breakdowns for IT professionals, in your inbox:https://www2.blueteam-academy.com/keep-it-safe-signup━━━━━━━━━━━━━━━━━━━━SOURCES━━━━━━━━━━━━━━━━━━━━- NIST SP 800-207, Zero Trust Architecture (2020): https://csrc.nist.gov/pubs/sp/800/207/final- NIST SP 1800-35, Implementing a Zero Trust Architecture (2025): https://csrc.nist.gov/pubs/sp/1800/35/final- CISA Zero Trust Maturity Model 2.0: https://www.cisa.gov/zero-trust-maturity-model- Forrester — "No More Chewy Centers," John Kindervag (2010)━━━━━━━━━━━━━━━━━━━━CONNECT━━━━━━━━━━━━━━━━━━━━LinkedIn: https://www.linkedin.com/showcase/blue-team-academyInstagram: https://www.instagram.com/blueteamacadX: https://x.com/BlueTeamAcadCybersecurity is not rocket science.#ZeroTrust #CyberSecurity #BlueTeam
Les incidents impliquant des agents IA se multiplient • Washington veut renforcer la surveillance des modèles les plus puissants • Le futur ChatGPT résout des problèmes mathématiques inédits • Google intègre Gemini dans Maps • Les résumés IA de Google Search énervent les internautes français • Les lecteurs préfèrent les livres écrits par IA.Avec Bruno Guglielminetti (Mon Carnet)Les agents IA franchissent la ligne rougeLes incidents impliquant des modèles d'OpenAI, Anthropic et Meta se multiplient après plusieurs expérimentations ayant débouché sur de véritables tentatives d'intrusion informatique. Nous revenons sur ces cas spectaculaires rendus possibles par des défauts de sécurité au niveau d'un opérateur tiers. Washington veut encadrer les modèles les plus puissantsFace à la multiplication des incidents, l'administration américaine prépare un renforcement des contrôles sur les modèles d'IA les plus avancés. Les laboratoires devront fournir davantage d'informations techniques avant le déploiement de leurs modèles, tandis que les solutions ouvertes pourraient bénéficier d'un traitement différent.Un nouveau modèle d'OpenAI résout des problèmes mathématiques insolublesLe futur modèle Astra d'OpenAI serait capable de résoudre plusieurs problèmes mathématiques réputés insolubles depuis des décennies. Une démonstration qui illustre les progrès spectaculaires des modèles spécialisés et relance le débat sur leur impact pour la recherche scientifique.Microsoft mise sur le « Zero Trust » pour sécuriser l'IAMicrosoft propose une nouvelle approche de confinement inspirée du modèle de cybersécurité « Zero Trust ». L'objectif est de limiter les risques liés aux agents autonomes en considérant chaque interaction comme potentiellement suspecte.Apple débordé par les faux signalements générés par l'IALa plateforme de chasse aux bugs d'Apple a été saturée par des milliers de signalements erronés produits par des IA spécialisées en cybersécurité. L'entreprise a dû instaurer des quotas afin de préserver le travail des équipes humaines chargées de vérifier chaque alerte.Google Earth retire une fonction IA détournéeUne nouvelle fonction de génération visuelle dans Google Earth a rapidement été utilisée pour fabriquer de fausses scènes de guerre, de catastrophes ou de crises humanitaires. Google l'a retirée en urgence afin de limiter les risques de désinformation.Google Maps accueille un véritable agent IADans plus de 160 pays, Google Maps intègre désormais un agent conversationnel capable de rechercher un restaurant, réserver une table ou réaliser diverses actions à la voix pendant la navigation. Une évolution qui rapproche l'assistant IA de véritables capacités d'action.Les médias veulent dissuader d'utiliser les résumés IA de Google Le déploiement des réponses générées par IA dans Google Search provoque une vive réaction chez certains médias, qui expliquent comment désactiver cette fonctionnalité. Influencés, les internautes réagissent négativement à cette innovation. Les lecteurs préfèrent les histoires écrites par IAUne étude surprenante révèle que les lecteurs trouvent les nouvelles générées sont plus facile à lire. Les lecteurs ont un à priori favorable pour les auteurs humains mais en réalité ils plébiscitent les écrits par IA lors d'un test à l'aveugle. Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
No Password Required: Next Gen - Ep. 3 - Kieran Human How Lead Cybersecurity Engineers Actually Think In this episode of No Password Required: Next Gen, Yazzel interviews Kieran Human, Lead Cybersecurity Engineer at ThreatLocker. From research to working directly with ThreatLocker's CEO on new security initiatives, Kieran gives an inside look at what it's really like to work on the front lines of cybersecurity. Kieran stands out as a cybersecurity professional by hares why curiosity, strong communication, and understanding the bigger picture are just as valuable as technical skills. He also reflects on one of his proudest career moments, writing a compliance white paper that earned praise from ThreatLocker's CEO Danny Jenkins, and explains how that experience reinforced the importance of research, writing, and always looking for ways to improve. Kieran also explains why Zero Trust security is becoming essential, teaches viewers a few cybersecurity terms that are guaranteed to impress at dinner, and even reveals why the Terminator would be his ultimate cybersecurity teammate! Whether you're exploring a career in cyber or looking for practical advice from someone working in the field every day, this episode is packed with insights for the next generation of cybersecurity professionals. Presented by ThreatLocker Supported by DerScanner Follow Kieran on Linked in here: https://www.linkedin.com/in/kieran-human-5495ab170/ Chapter List: 00:00 Introduction to Cybersecurity and Career Path 02:54 Key Skills and Qualities for Success in Cybersecurity 06:07 Impact of AI and Zero Trust in Cybersecurity 06:56 Fun Insights and Closing Thoughts
When organizations review their cybersecurity posture, printers are rarely the first systems that come to mind. Yet they often account for around 20% of network endpoints while receiving, storing, processing, and transmitting sensitive business information every day. In this episode of Tech Talks Daily, I welcome back Jim LaRoe, CEO of Symphion, to discuss why printers and other connected IoT devices have become one of the most overlooked areas of enterprise cybersecurity and why AI-powered attacks are raising the stakes for organizations that continue to ignore them. Jim explains how many businesses continue to treat printers as simple office equipment rather than Linux-based network devices with privileged access to email systems, file servers, identity services, and critical business workflows. Because responsibility for these devices often sits between procurement, managed print providers, IT operations, and security teams, they can easily fall outside normal cybersecurity processes. We discuss how the threat landscape has changed over the past year as AI enables attackers to automate reconnaissance, credential theft, lateral movement, and ransomware deployment. Jim explains why organizations adopting Zero Trust principles also need to rethink how they secure and manage connected endpoints that have traditionally been overlooked. The conversation also explores certificate lifecycle management, cyber hygiene, firmware management, endpoint visibility, and why unsupported devices can introduce unnecessary risk into modern enterprise environments. For organizations managing hundreds or even thousands of printers across multiple locations, Jim explains why protecting these endpoints does not need to create additional operational burden. Instead, security should become an ongoing operational program that continuously monitors devices, detects configuration drift, applies security controls, and helps organizations maintain compliance without disrupting critical business workflows. We also discuss the governance challenge many organizations face. Before companies can reduce risk, someone needs to own it. That means establishing accountability, assigning budget, understanding which devices exist across the business, and recognizing that printers and IoT devices deserve the same attention as servers, laptops, and other managed endpoints. If you're responsible for cybersecurity, IT infrastructure, risk management, or digital transformation, this episode offers practical advice on protecting forgotten endpoints, strengthening Zero Trust strategies, improving endpoint visibility, and reducing the hidden risks that AI-powered attackers are increasingly looking to exploit. Sometimes the biggest cybersecurity vulnerability isn't the system you forgot to patch. It's the one you forgot was connected in the first place.
How can businesses secure AI agents that read sensitive information, update systems and communicate with other agents on behalf of employees? In this episode of Tech Talks Daily, I speak with Sachin Nayyar, founder and CEO of Saviynt, about AI agent identity security and the controls businesses need before autonomous systems enter production. Saviynt manages over 100 million identities for over 700 customers. Sachin explains how enterprise identity has expanded beyond employees to include partners, applications, machines and autonomous AI agents. An AI agent creates a different access problem because it is both an identity and an application. It can receive permissions, access information and perform actions, but its behavior can also be governed through software while it is being developed and while it is operating. Sachin uses an HR copilot to demonstrate why context matters. Two employees can ask the same question about salaries but should receive different answers based on their roles, locations and applicable policies. Those decisions must be evaluated while the request is being processed without creating delays that make the system unusable. The risk grows when an agent crosses from one technology environment into another. An agent built within Microsoft may need to access Salesforce, ServiceNow, Jira or another external system. Sachin warns businesses never to solve this problem by giving an agent a permanent administrative account. We discuss Zuma, Saviynt's identity security platform for AI agents and non-human identities. Sachin describes a four-part framework beginning with agent discovery and a central registry. Every agent should then receive one accountable human owner, temporary access for its assigned task and policy enforcement while it acts. Ownership becomes especially important when an employee leaves. Saviynt's approach begins an automated reassignment process and blocks actions if an agent attempts to operate without a current owner. The relevant security team can then investigate before allowing further activity. Sachin also explains why identity controls should enter the development process rather than being added after deployment. Saviynt is working with LangChain and other agent development platforms to make identity policies available while AI agents are being built. The conversation also covers Saviynt's partnership with Zscaler. Zscaler provides inline enforcement, while Saviynt contributes identity information about the agent, its owner, existing permissions and expected behavior. Sachin closes with an optimistic argument. Because businesses can place security controls into the code and enforce them while agents act, AI workloads may eventually become better governed than traditional human access. Could every AI agent inside your business be traced to one accountable owner, one approved purpose and a limited set of temporary permissions? Please share your thoughts with me.
Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.In this episode of Secure IT, host Jason Kikta is joined by Mark Cooper, CEO and founder of PKI Solutions, to unpack why PKI is so critical to identity, authentication, and trust, and what happens when it fails.They explore how certificates enable passwordless authentication, secure TLS connections, IoT devices, endpoints, and enterprise systems, while also examining why misconfigured or poorly monitored PKI environments often become an attacker's fastest path to privilege escalation. From certificate expirations and operational outages to real-world breach scenarios and pen test failures, this conversation maps the full PKI risk spectrum.Jason and Mark also challenge a common assumption in cybersecurity: that recovery equals resilience. Instead, they argue that true resilience means staying secure and operational, even during misconfiguration, failure, or attack.Whether you're new to PKI or responsible for running it, this episode will change how you think about identity infrastructure, resilience, and trust.Topics covered:- What PKI is and why most organizations already depend on it- Certificates, passwordless authentication, and digital identity- How PKI misconfigurations enable high-impact attacks- Why recovery is the weakest form of resilience- The hidden operational and security risks of foundational systems
This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.This show is sponsored by Sentry.IO. Sentry wants to help you monitor your environment for problems. They do error tracking, stack tracing, debugging, all so that your developers can diagnose, fix, and optimize the performance of their code. This makes it so developers ship more reliable code faster. Learn more at sentry.io.View all active sponsors.SourcesFull list of sources on the show page: https://darknetdiaries.com/episode/177/
ClickLock stealer uses kill loops to force password entry TELEPUZ malware uses ClickFix to steal data and run commands 1Password's new Agentic Mode lets Claude log into accounts Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/ This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Most security breakthroughs don't come from new technology, they come from finally getting the basics right. As AI accelerates both attacks and the pace of vulnerability disclosure, the organizations that fare best aren't the ones chasing the next big thing, but the ones with the visibility, governance, and segmentation to absorb the shock. In this episode, Raghu Nandakumara sits down with Jason Garbis, founder and CEO of Number Line Security and co-chair of the Zero Trust Working Group at the Cloud Security Alliance, to explore what Zero Trust looks like when threats evolve at machine speed. Jason draws on his path from early software-defined perimeter work to leading Zero Trust strategy at the Cloud Security Alliance, sharing why "right-sizing" a Zero Trust initiative matters more than chasing sweeping transformation, and why even a well-built security capability fails without genuine buy-in from the business. The conversation then turns to AI's effect on the threat landscape: the surge of vulnerabilities and patches enterprises now have to absorb, the widening gap between attacker speed and defender response, and why segmentation remains one of the most effective ways to shrink the blast radius of an attack. Raghu and Jason discuss: How to right-size a Zero Trust initiative for an organization's actual readiness Why "build it and they will come" doesn't work for security adoption Tying Zero Trust investments to business priorities like AI adoption, M&A, and compliance What's genuinely new — and what isn't — about securing AI systems and agents How accelerating vulnerability disclosures are reshaping patch management Why segmentation reduces blast radius even when patching can't keep pace A simple analogy for explaining zero trust to non-security stakeholders Jason closes with his go-to way of explaining Zero Trust to non-technical stakeholders: an analogy involving brakes, oil, and seat belts that reframes security as a shared responsibility rather than a roadblock. Resources Mentioned: Zero Trust Security and Enterprise Guide Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com
One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn't right about this letter. It seemed to violate the constitution. So he set out to change the law.Learn more about Nicks work at calyxinstitute.org and phreeli.com.Check out Cindy's book Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance (https://amzn.to/4gXuK2J).SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.View all active sponsors.Sources https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/ https://clearinghouse.net/case/12966/ https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill https://www.aclu.org/documents/national-security-letters https://www.eff.org/cases/re-matter-2011-national-security-letter Cindy's Book: Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance
All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining is Patti Degnan, operating partner, Andreessen Horowitz. In this episode: Identity built for one person at a time Patching can't outrun the exploit timeline The exception hiding inside zero trust A revenue question nobody's answered yet A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.
It started with a fake car listing on eBay.What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cryptocurrency for someone else. Millions of dollars siphoned from victims who had no idea.This is the story of Bayrob and the three men from Romanian who were behind it. And the long, strange road that led American investigators to their door.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that's built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This episode is sponsored by Chainguard. Chainguard builds container images the right way — minimal, hardened, and built from source every single day. We're talking images with zero known CVEs, designed from the ground up for production. No bloat. No mystery packages. No 2 a.m. patching marathons because some transitive dependency lit up your dashboard. Stop patching images that are insecure. Start shipping clean. Head to chainguard.dev to see how secure your software supply chain can really be.