Podcasts about zero trust

  • 965PODCASTS
  • 4,090EPISODES
  • 37mAVG DURATION
  • 1DAILY NEW EPISODE
  • Aug 25, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about zero trust

Show all podcasts related to zero trust

Latest podcast episodes about zero trust

Paul's Security Weekly
Applying Zero Trust Principles to Agents - Kieran Human - ASW #397

Paul's Security Weekly

Play Episode Listen Later Aug 25, 2026 66:40


Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface. Resources https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats This interview is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-397

Risky Business
Soap Box: Zero Trust(ish) Networks

Risky Business

Play Episode Listen Later Aug 14, 2026 29:04


In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture. Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049. Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible. Instead of trying to re-architect entire networks, maybe it's time we learned to apply Zero Trust principles selectively against risky assets. It's a better approach than the status quo, which involves liberal use of the “risk accepted” stamp. This episode is also available on YouTube Show notes

ITSPmagazine | Technology. Cybersecurity. Society
Agents Get Zero Trust, and the Network Becomes the Sensor | A Brand Briefing at Black Hat USA 2026 with David Hughes, SVP and GM of SASE and Security for Networking at HPE | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 14, 2026 15:48


Most people know HPE for servers, compute, and storage. David Hughes leads a pillar that gets less attention. He runs the SSE and security business inside HPE Networking, which he says accounts for about a third of the company now that HPE has merged with Juniper, and which organizes into four pillars: campus and branch, data center switching, routing infrastructure, and security. Recorded on location at Black Hat USA 2026, the conversation opens on a balancing act Hughes hears constantly. Customers want to push hard on AI adoption while staying protected and avoiding undue risk. The same tension runs between teams. Networking answers for performance and user experience. Security answers for protecting those users and the company's data. HPE's answer is to embed security thinking into the network itself, making it a sensor and an enforcement point for the security team. What happens when users are no longer only people? The identity question moves to devices, workloads, and agents. Hughes frames it as human and non-human identity, and his position is to take the ZTNA architecture that works for people and adapt it, starting with IoT devices, then workloads, then agents. Put an agent in a sandbox and it sees only the subset of resources it is supposed to reach. How do networking and security teams work from the same picture? Through shared visibility and agentic technology across the management layer. HPE is putting agentic technology into how it manages storage, compute, networks, and security products, then meshing those agents together so a wifi complaint that turns out to be a firewall policy change gets to root cause faster, with automatic remediation as the goal. Hughes also covers post-quantum cryptography, where HPE is moving across all product lines to introduce quantum resistant and quantum safe capabilities in hardware and software, with some launched this year and more coming through the following quarters. The deadline arrives earlier than most calendars suggest, because data harvested today can be decrypted later. Rounding it out: HPE Threat Labs, announced earlier in the year with Mounir Hahad's team from Juniper at its core, and AI focused capabilities on the next generation firewalls covering observability, role based governance over which services employees can use, and session level inspection of prompts and responses. Hughes closes with a direct invitation to CISOs who know HPE for compute and networking and have yet to meet the security team. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST David Hughes, SVP and GM of SASE and Security for Networking at HPE On LinkedIn: https://www.linkedin.com/in/david-hughes-42751636/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas HPE: https://www.hpe.com/ HPE Threat Labs: https://www.hpe.com/us/en/hpe-labs/threat-labs.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS david hughes, hpe, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, zero trust, ztna, non-human identity, agentic ai, ai security, post-quantum cryptography, network security, sase, sse, hpe threat labs, self-driving network, firewall governance, juniper, iot security, cross domain troubleshooting Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

PULS BIZNESU do słuchania
Czy powinniśmy bać się AI?

PULS BIZNESU do słuchania

Play Episode Listen Later Aug 14, 2026 31:13


Czy modele AI wyrwały się spod kontroli i same dokonują włamań do banków? Medialne nagłówki straszą atakami sztucznej inteligencji w czasie rzeczywistym, ale jaka jest rzeczywistość? W tym odcinku „PB Strefa Ekspertów” Piotr Konieczny z Niebezpiecznika brutalnie weryfikuje fakty i demitologizuje głośny model Mythos od Anthropic.W tym odcinku analizujemy:Fact-checking ataku na 20 mln funtów: Czy szefowie firm naprawdę przegrywają z deepfake'ami na żywo?Afera wokół modelu Mythos: Dlaczego amerykański FED zwołał szefów największych banków i co przestraszyło analityków?Podatności starych systemów: Jak łańcuchy technologiczne budowane przez 40 lat reagują na automatyczne skanowanie luk?Spokój w dobie paniki: Jak zasady Zero Trust i odpowiednia separacja środowisk IT chronią firmę przed atakami AI.Gościem wywiadu jest Piotr Konieczny, założyciel serwisu Niebezpiecznik.pl.

Enterprise Podcast Network – EPN
The Printer Blind Spot: Why Zero Trust Must Include Print Workflows

Enterprise Podcast Network – EPN

Play Episode Listen Later Aug 12, 2026 16:27


Kevin Pickhardt, Executive Chairman of Pharos, a company that provides cloud-native enterprise print management solutions that help organizations modernize print infrastructure, improve security, and support … Read more The post The Printer Blind Spot: Why Zero Trust Must Include Print Workflows appeared first on Top Entrepreneurs Podcast | Enterprise Podcast Network.

The Tech Blog Writer Podcast
AI Agent Security: Why Identity and Access Control Matter More Than Guardrails

The Tech Blog Writer Podcast

Play Episode Listen Later Aug 11, 2026 24:49


What happens when an AI agent is compromised, manipulated, or simply does something nobody expected, but already has permission to access your most sensitive systems? In this episode of Tech Talks Daily, I speak with Geoffrey Mattson, CEO of SecureAuth, about why securing enterprise AI requires businesses to think beyond protecting models and start paying much closer attention to identity, authorization, access control, and what AI agents are actually allowed to do. Geoffrey argues that AI agents present a different security challenge from traditional software. Conventional applications can be tested against relatively predictable behavior. AI models are far less deterministic, particularly when prompt injection, excessive permissions, unexpected behavior, and autonomous actions enter the equation. His advice is to assume an agent could behave unpredictably and control what happens when it attempts to access a database, execute a financial transaction, call an API, or interact with another business system. We discuss what this means as companies race to introduce agentic AI. Geoffrey shares examples of employees granting AI tools permissions without fully understanding what they have approved, along with agents gathering information that creates unexpected privacy and compliance problems. This creates a difficult challenge for CIOs and CISOs. Boards want AI adoption because of its potential competitive value, while employees increasingly depend on AI tools to do their jobs. Simply blocking agents is unlikely to work. Security teams instead need mechanisms that allow innovation while controlling what those agents can access. Geoffrey explains why Zero Trust becomes particularly relevant here. Rather than authenticating a user or agent once and assuming it remains trustworthy, enterprises need to continually evaluate whether an action should be permitted at that specific moment. This leads to the concept of continuous authorization. Geoffrey explains how identity security is moving from asking "Who are you?" toward understanding intent, behavior, context, and authority for individual actions. This becomes increasingly important when one AI agent can create sub-agents, which can then create additional agents and pass permissions down the chain. We also discuss why agentic AI is exposing years of accumulated security debt. Many of the underlying problems are familiar: excessive privileges, inconsistent access controls, incomplete Zero Trust implementations, and systems that trust identities for too long. AI agents amplify those weaknesses because they can operate at machine speed. Geoffrey describes this as combining the unpredictability of humans with the power of machines. For CIOs, CISOs, security architects, identity teams, and business leaders deploying agentic AI, this conversation offers practical questions to ask before connecting agents to enterprise resources. What can the agent access? What authority does it have? Can that authority be reduced as tasks are delegated? Is every important action evaluated independently? And can access be revoked immediately when behavior changes? The goal is not to prevent organizations from using AI agents. It is to create a security layer that gives developers and employees room to experiment while ensuring agents only have the authority they need at the moment they need it. As autonomous AI becomes part of the enterprise workforce, identity alone may no longer be enough. Businesses increasingly need to understand intent, control authority, and continuously decide whether the next action should be allowed.

Threat Talks - Your Gateway to Cybersecurity Insights
HackShield: Raising the Next Generation of Cyber Heroes

Threat Talks - Your Gateway to Cybersecurity Insights

Play Episode Listen Later Aug 11, 2026 19:05


The hacker who will attack your organization in five years is in school right now, and nobody is teaching that kid what to do online. HackShield is trying to change that. Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Tim Murck, co-founder of HackShield, on why security awareness training for adults keeps failing, and what a game built for seven to twelve year olds can teach every CISO about human risk. If your plan is to train 2,000 people to never click the wrong link, this is the episode that explains why you have already lost, and what to do instead.

Be Real Show
#467 - Scott Alldridge gets REAL about Cybersecurity in an AI World

Be Real Show

Play Episode Listen Later Aug 10, 2026 29:32


"We cannot solve our problems with the same thinking we used when we created them." – Albert Einstein Scott Alldridge is a tech-forward C-Suite Executive, Board Director, Amazon Best Seller Author and exceptional Problem Solver with deep experience in AI, cybersecurity, data governance and risk management spanning a broad array of industries. He is a transformational leader adept at driving organizational change, mitigating financial and reputation risk and formulating high-impact tech strategies that lead to significant value creation. ______ CYBERSECURITY SME. Scott's work is grounded in Zero Trust – a cyber-tech operations discipline for highly regulated environments. He has led and advised organizations operating under NIST CSF, NIST 800-53, NIST 800-171, CMMC and ISO 27001. Scott's experience also includes HIPAA, PCI DSS, SOX, GLBA, SOC 2, state privacy laws and cyber insurance requirements. In each engagement, Scott's primary goal is to support organizations by strengthening security, ensuring compliance and improving performance – without compromising business efficiency. ENGAGED BOARD MEMBER. Scott helps companies build future-ready infrastructures and leverage technology to strengthen organizational agility and drive profitable growth. He brings a unique blend of business acumen and technical proficiency to his roles as CEO, Advisor and Independent Board Director. Scott's board-level advisory experience includes strategic guidance on a variety of topics including digital transformation, cybersecurity governance, business strategy, portfolio growth and AI. PRAGMATIC LEADER. Scott builds accountable, cross-functional teams that deliver spot-on, data-driven results for their organization, clients and stakeholders. Guided by a shared set of "Mission, Vision and Values", Scott mentors emerging leaders to execute assignments with clarity and autonomy. As testament to his effective leadership style, Scott's core team has remained with him for more than 15 years. https://ipservices.com/ ______ EXPERIENCE and EXPERTISE Small Cap · Mid-cap · SMB · Startups · PE · Digital Transformation • Change Management · AI · IT Roadmaps · Cybersecurity · Continuous Improvement · Agile Methodology · SaaS · ERP Systems Cloud Services · IT Infrastructures · Growth Strategies · Risk Mitigation Business Development M&A Due Diligence • Acquisition Integration • Vendor Negotiations Audit Compliance • NIST • CMMC • GLP • SOX • Gramm-Leach-Bliley Act

Jim Colbert Show:  The Goods
JCS: ThreatLocker CEO Danny Jenkins 8/10/2026

Jim Colbert Show: The Goods

Play Episode Listen Later Aug 10, 2026 19:38


Danny Jenkins, CEO and Co-founder of ThreatLocker, a global cybersecurity company, shares the latest cyber threats facing the world today, including when 'Zero Trust' is necessary, AI gents hacking other AI companies, and more.

Monde Numérique - Jérôme Colombain
Des IA hors de contrôle attaquent plusieurs entreprises (

Monde Numérique - Jérôme Colombain

Play Episode Listen Later Aug 8, 2026 49:42


Les incidents impliquant des agents IA se multiplient • Washington veut renforcer la surveillance des modèles les plus puissants • Le futur ChatGPT résout des problèmes mathématiques inédits • Google intègre Gemini dans Maps • Les résumés IA de Google Search énervent les internautes français • Les lecteurs préfèrent les livres écrits par IA.Avec Bruno Guglielminetti (Mon Carnet)Les agents IA franchissent la ligne rougeLes incidents impliquant des modèles d'OpenAI, Anthropic et Meta se multiplient après plusieurs expérimentations ayant débouché sur de véritables tentatives d'intrusion informatique. Nous revenons sur ces cas spectaculaires rendus possibles par des défauts de sécurité au niveau d'un opérateur tiers. Washington veut encadrer les modèles les plus puissantsFace à la multiplication des incidents, l'administration américaine prépare un renforcement des contrôles sur les modèles d'IA les plus avancés. Les laboratoires devront fournir davantage d'informations techniques avant le déploiement de leurs modèles, tandis que les solutions ouvertes pourraient bénéficier d'un traitement différent.Un nouveau modèle d'OpenAI résout des problèmes mathématiques insolublesLe futur modèle Astra d'OpenAI serait capable de résoudre plusieurs problèmes mathématiques réputés insolubles depuis des décennies. Une démonstration qui illustre les progrès spectaculaires des modèles spécialisés et relance le débat sur leur impact pour la recherche scientifique.Microsoft mise sur le « Zero Trust » pour sécuriser l'IAMicrosoft propose une nouvelle approche de confinement inspirée du modèle de cybersécurité « Zero Trust ». L'objectif est de limiter les risques liés aux agents autonomes en considérant chaque interaction comme potentiellement suspecte.Apple débordé par les faux signalements générés par l'IALa plateforme de chasse aux bugs d'Apple a été saturée par des milliers de signalements erronés produits par des IA spécialisées en cybersécurité. L'entreprise a dû instaurer des quotas afin de préserver le travail des équipes humaines chargées de vérifier chaque alerte.Google Earth retire une fonction IA détournéeUne nouvelle fonction de génération visuelle dans Google Earth a rapidement été utilisée pour fabriquer de fausses scènes de guerre, de catastrophes ou de crises humanitaires. Google l'a retirée en urgence afin de limiter les risques de désinformation.Google Maps accueille un véritable agent IADans plus de 160 pays, Google Maps intègre désormais un agent conversationnel capable de rechercher un restaurant, réserver une table ou réaliser diverses actions à la voix pendant la navigation. Une évolution qui rapproche l'assistant IA de véritables capacités d'action.Les médias veulent dissuader d'utiliser les résumés IA de Google Le déploiement des réponses générées par IA dans Google Search provoque une vive réaction chez certains médias, qui expliquent comment désactiver cette fonctionnalité. Influencés, les internautes réagissent négativement à cette innovation. Les lecteurs préfèrent les histoires écrites par IAUne étude surprenante révèle que les lecteurs trouvent les nouvelles générées sont plus facile à lire. Les lecteurs ont un à priori favorable pour les auteurs humains mais en réalité ils plébiscitent les écrits par IA lors d'un test à l'aveugle. Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

No Password Required
No Password Required: Next Gen - Ep. 3 - Kieran Human

No Password Required

Play Episode Listen Later Aug 3, 2026 7:06


No Password Required: Next Gen - Ep. 3 - Kieran Human How Lead Cybersecurity Engineers Actually Think  In this episode of No Password Required: Next Gen, Yazzel interviews Kieran Human, Lead Cybersecurity Engineer at ThreatLocker. From research to working directly with ThreatLocker's CEO on new security initiatives, Kieran gives an inside look at what it's really like to work on the front lines of cybersecurity. Kieran stands out as a cybersecurity professional by hares why curiosity, strong communication, and understanding the bigger picture are just as valuable as technical skills. He also reflects on one of his proudest career moments, writing a compliance white paper that earned praise from ThreatLocker's CEO Danny Jenkins, and explains how that experience reinforced the importance of research, writing, and always looking for ways to improve. Kieran also explains why Zero Trust security is becoming essential, teaches viewers a few cybersecurity terms that are guaranteed to impress at dinner, and even reveals why the Terminator would be his ultimate cybersecurity teammate!  Whether you're exploring a career in cyber or looking for practical advice from someone working in the field every day, this episode is packed with insights for the next generation of cybersecurity professionals. Presented by ThreatLocker Supported by DerScanner Follow Kieran on Linked in here: https://www.linkedin.com/in/kieran-human-5495ab170/  Chapter List: 00:00 Introduction to Cybersecurity and Career Path 02:54 Key Skills and Qualities for Success in Cybersecurity 06:07 Impact of AI and Zero Trust in Cybersecurity 06:56 Fun Insights and Closing Thoughts  

The Tech Blog Writer Podcast
AI-Powered Cyberattacks Are Coming for Your Printers. Is Your Business Ready?

The Tech Blog Writer Podcast

Play Episode Listen Later Aug 1, 2026 32:04


When organizations review their cybersecurity posture, printers are rarely the first systems that come to mind. Yet they often account for around 20% of network endpoints while receiving, storing, processing, and transmitting sensitive business information every day. In this episode of Tech Talks Daily, I welcome back Jim LaRoe, CEO of Symphion, to discuss why printers and other connected IoT devices have become one of the most overlooked areas of enterprise cybersecurity and why AI-powered attacks are raising the stakes for organizations that continue to ignore them. Jim explains how many businesses continue to treat printers as simple office equipment rather than Linux-based network devices with privileged access to email systems, file servers, identity services, and critical business workflows. Because responsibility for these devices often sits between procurement, managed print providers, IT operations, and security teams, they can easily fall outside normal cybersecurity processes. We discuss how the threat landscape has changed over the past year as AI enables attackers to automate reconnaissance, credential theft, lateral movement, and ransomware deployment. Jim explains why organizations adopting Zero Trust principles also need to rethink how they secure and manage connected endpoints that have traditionally been overlooked. The conversation also explores certificate lifecycle management, cyber hygiene, firmware management, endpoint visibility, and why unsupported devices can introduce unnecessary risk into modern enterprise environments. For organizations managing hundreds or even thousands of printers across multiple locations, Jim explains why protecting these endpoints does not need to create additional operational burden. Instead, security should become an ongoing operational program that continuously monitors devices, detects configuration drift, applies security controls, and helps organizations maintain compliance without disrupting critical business workflows. We also discuss the governance challenge many organizations face. Before companies can reduce risk, someone needs to own it. That means establishing accountability, assigning budget, understanding which devices exist across the business, and recognizing that printers and IoT devices deserve the same attention as servers, laptops, and other managed endpoints. If you're responsible for cybersecurity, IT infrastructure, risk management, or digital transformation, this episode offers practical advice on protecting forgotten endpoints, strengthening Zero Trust strategies, improving endpoint visibility, and reducing the hidden risks that AI-powered attackers are increasingly looking to exploit. Sometimes the biggest cybersecurity vulnerability isn't the system you forgot to patch. It's the one you forgot was connected in the first place.

The Tech Blog Writer Podcast
How Saviynt Zuma Secures AI Agents With Zero Trust

The Tech Blog Writer Podcast

Play Episode Listen Later Jul 29, 2026 34:43


How can businesses secure AI agents that read sensitive information, update systems and communicate with other agents on behalf of employees? In this episode of Tech Talks Daily, I speak with Sachin Nayyar, founder and CEO of Saviynt, about AI agent identity security and the controls businesses need before autonomous systems enter production. Saviynt manages over 100 million identities for over 700 customers. Sachin explains how enterprise identity has expanded beyond employees to include partners, applications, machines and autonomous AI agents. An AI agent creates a different access problem because it is both an identity and an application. It can receive permissions, access information and perform actions, but its behavior can also be governed through software while it is being developed and while it is operating. Sachin uses an HR copilot to demonstrate why context matters. Two employees can ask the same question about salaries but should receive different answers based on their roles, locations and applicable policies. Those decisions must be evaluated while the request is being processed without creating delays that make the system unusable. The risk grows when an agent crosses from one technology environment into another. An agent built within Microsoft may need to access Salesforce, ServiceNow, Jira or another external system. Sachin warns businesses never to solve this problem by giving an agent a permanent administrative account. We discuss Zuma, Saviynt's identity security platform for AI agents and non-human identities. Sachin describes a four-part framework beginning with agent discovery and a central registry. Every agent should then receive one accountable human owner, temporary access for its assigned task and policy enforcement while it acts. Ownership becomes especially important when an employee leaves. Saviynt's approach begins an automated reassignment process and blocks actions if an agent attempts to operate without a current owner. The relevant security team can then investigate before allowing further activity. Sachin also explains why identity controls should enter the development process rather than being added after deployment. Saviynt is working with LangChain and other agent development platforms to make identity policies available while AI agents are being built. The conversation also covers Saviynt's partnership with Zscaler. Zscaler provides inline enforcement, while Saviynt contributes identity information about the agent, its owner, existing permissions and expected behavior. Sachin closes with an optimistic argument. Because businesses can place security controls into the code and enforce them while agents act, AI workloads may eventually become better governed than traditional human access. Could every AI agent inside your business be traced to one accountable owner, one approved purpose and a limited set of temporary permissions? Please share your thoughts with me.

Compromising Positions - A Cyber Security Podcast

In this episode, we continue our How Technology Ruined Your Life mini-series with "F" Is For FAKE, exploring how artificial intelligence is transforming not only what we see online, but what we believe to be true.From convincing deepfake videos and cloned voices to AI-generated news, fake witnesses, and synthetic social media content, we examine how generative AI is eroding our ability to distinguish reality from fabrication. As humans become increasingly unable to reliably identify AI-generated media, what happens when evidence itself can no longer be trusted?Drawing on the latest research into deepfakes, misinformation, disinformation, and content authenticity, we explore how synthetic media is reshaping cybersecurity, politics, journalism, and society. We discuss why humans are now little better than chance at spotting AI-generated content, the limitations of current verification standards such as C2PA, and why the future of trust may depend less on detecting fakes than proving what is real.We also examine the growing cybersecurity implications of AI-generated deception, from multimillion-dollar CEO impersonation scams and voice cloning attacks to insider threats, identity fraud, authentication failures, and the growing challenge of securing organisations in a world where seeing is no longer believing. If persuasion was the first battlefield of AI, synthetic reality may be the next.In This Episode, We Discuss:The Rise of Synthetic Reality: How deepfakes, AI-generated images, cloned voices, fabricated news reports, and synthetic media are changing the way we consume information, and why "seeing is believing" is rapidly becoming obsolete.Misinformation, Disinformation & The Trust Crisis: The critical differences between misinformation, disinformation, and malinformation, how false narratives spread across social media, and why convincing fakes can continue influencing people even after they have been debunked.Deepfakes Meet Cybersecurity: How AI-powered impersonation is accelerating social engineering attacks through CEO fraud, business email compromise, voice cloning, fake job applicants, identity spoofing, and increasingly sophisticated phishing campaigns that exploit human trust rather than technical vulnerabilities.Can We Still Verify Reality? Why emerging content authenticity standards such as C2PA represent an important step forward, but remain imperfect, and what organisations can do today through stronger verification processes, layered authentication, Zero Trust principles, multi-person approvals, and security awareness to defend against the next generation of AI-enabled deception.Show NotesSpecial thanks to our episode sponsor, Leeds based AI Consultancy specialising in AI Ethics, Security and Transformation NorthStar Intelligence- From Ideas to Impact. AI that works for peopleAI-Generated Misinformation: A Case Study on Emerging Trends in Fact-Checking Practices Across Brazil, Germany, and the United Kingdom byRegina Cazzamatta and Aynur SarisakalogluAI-Slop and Political Propaganda: The Role of AI-Generated Content in Memes and Influence Campaigns by Eduard-Claudiu Gross and Alicia J.M. ColsonAI Slop and the Information Ecosystem by Jenn Weedon et al.As Good as A Coin Toss: Human detection of AI-generated Images, Videos, Audio and Audiovisual Stimuli by Di Cooke et al.Verifying Provenance of Digital Media: Why the C2PA Specifications Fall Short by Enis Golaszewski et al.Beliefs and Sharing Intentions of Human- and AI-Generated Fake News: Evidence from 27 European Countries by Adam Stefkovics and Gere DomotorDeepfakes and the epistemic apocalypse by Joshua Habgood-CooteHow Spammers and Scammers Leverage AI-Generated Images on Facebook for Audience Growth by Renee DiResta and Josh A. GoldsteinAlso, check out our sister podcast Tech Film Noir!

Autonomous IT
Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22

Autonomous IT

Play Episode Listen Later Jul 22, 2026 17:58


Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.In this episode of Secure IT, host Jason Kikta is joined by Mark Cooper, CEO and founder of PKI Solutions, to unpack why PKI is so critical to identity, authentication, and trust, and what happens when it fails.They explore how certificates enable passwordless authentication, secure TLS connections, IoT devices, endpoints, and enterprise systems, while also examining why misconfigured or poorly monitored PKI environments often become an attacker's fastest path to privilege escalation. From certificate expirations and operational outages to real-world breach scenarios and pen test failures, this conversation maps the full PKI risk spectrum.Jason and Mark also challenge a common assumption in cybersecurity: that recovery equals resilience. Instead, they argue that true resilience means staying secure and operational, even during misconfiguration, failure, or attack.Whether you're new to PKI or responsible for running it, this episode will change how you think about identity infrastructure, resilience, and trust.Topics covered:- What PKI is and why most organizations already depend on it- Certificates, passwordless authentication, and digital identity- How PKI misconfigurations enable high-impact attacks- Why recovery is the weakest form of resilience- The hidden operational and security risks of foundational systems

Darknet Diaries
177: National Public Data

Darknet Diaries

Play Episode Listen Later Jul 21, 2026 47:49


This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.This show is sponsored by Sentry.IO. Sentry wants to help you monitor your environment for problems. They do error tracking, stack tracing, debugging, all so that your developers can diagnose, fix, and optimize the performance of their code. This makes it so developers ship more reliable code faster. Learn more at sentry.io.View all active sponsors.SourcesFull list of sources on the show page: https://darknetdiaries.com/episode/177/

KuppingerCole Analysts
Analyst Chat #308: Beyond SASE - What a Real Zero Trust Platform Looks Like

KuppingerCole Analysts

Play Episode Listen Later Jul 20, 2026 42:44


Zero trust has a label problem. After more than a decade, the term has been stretched, diluted, and attached to products that don't come close to delivering what zero trust actually promises. In this episode, Matthias sits down with Alexei Balaganski, lead analyst at KuppingerCole Analysts, to share the findings from six months of research and reveal which vendors actually built a real Zero Trust Platform. Key Topics: ✅ Why zero trust is a strategy, not a product — and what that means for procurement✅ The four non-negotiable requirements for a real Zero Trust Platform✅ What separates a genuine platform from a collection of tools with a zero trust label✅ NHIs, AI agents, and data protection as the new frontiers of zero trust architecture✅ Three critical questions every RFP for a ZTP should include

Cyber Security Headlines
The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back

Cyber Security Headlines

Play Episode Listen Later Jul 17, 2026 42:58


"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/  This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines.  Because security works best when innovation and control move together.

Cyber Security Headlines
ClickLock's kill loops, TELEPUZ ClickFix tricks, 1Password's agentic login

Cyber Security Headlines

Play Episode Listen Later Jul 17, 2026 8:43


ClickLock stealer uses kill loops to force password entry TELEPUZ malware uses ClickFix to steal data and run commands 1Password's new Agentic Mode lets Claude log into accounts Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

Cyber Security Headlines
Zoom's wake-up call, zero-day SonicWall patch, 23andMe's growing breach bill

Cyber Security Headlines

Play Episode Listen Later Jul 16, 2026 8:45


Zoom's account takeover wake-up call Two zero-days, one urgent SonicWall patch 23andMe's breach bill keeps growing Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

The Segment: A Zero Trust Leadership Podcast
AI Doesn't Break Security. It Exposes It. | Jason Garbis

The Segment: A Zero Trust Leadership Podcast

Play Episode Listen Later Jul 15, 2026 45:50


Most security breakthroughs don't come from new technology, they come from finally getting the basics right. As AI accelerates both attacks and the pace of vulnerability disclosure, the organizations that fare best aren't the ones chasing the next big thing, but the ones with the visibility, governance, and segmentation to absorb the shock. In this episode, Raghu Nandakumara sits down with Jason Garbis, founder and CEO of Number Line Security and co-chair of the Zero Trust Working Group at the Cloud Security Alliance, to explore what Zero Trust looks like when threats evolve at machine speed. Jason draws on his path from early software-defined perimeter work to leading Zero Trust strategy at the Cloud Security Alliance, sharing why "right-sizing" a Zero Trust initiative matters more than chasing sweeping transformation, and why even a well-built security capability fails without genuine buy-in from the business.  The conversation then turns to AI's effect on the threat landscape: the surge of vulnerabilities and patches enterprises now have to absorb, the widening gap between attacker speed and defender response, and why segmentation remains one of the most effective ways to shrink the blast radius of an attack. Raghu and Jason discuss: How to right-size a Zero Trust initiative for an organization's actual readiness Why "build it and they will come" doesn't work for security adoption Tying Zero Trust investments to business priorities like AI adoption, M&A, and compliance What's genuinely new — and what isn't — about securing AI systems and agents How accelerating vulnerability disclosures are reshaping patch management Why segmentation reduces blast radius even when patching can't keep pace A simple analogy for explaining zero trust to non-security stakeholders Jason closes with his go-to way of explaining Zero Trust to non-technical stakeholders: an analogy involving brakes, oil, and seat belts that reframes security as a shared responsibility rather than a roadblock. Resources Mentioned: Zero Trust Security and Enterprise Guide   Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com

Cyber Security Headlines
CMMC Phase II suspended, tracking troops in Iran, defenders turn to context bombing

Cyber Security Headlines

Play Episode Listen Later Jul 15, 2026 7:59


Pentagon suspends CMMC Phase II requirements US troop location data under attack in Iran "Context Bombing" flips the script on prompt injections Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/  Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

Feds At The Edge by FedInsider
Ep. 257 The Importance of Zero Trust Architecture

Feds At The Edge by FedInsider

Play Episode Listen Later Jul 15, 2026 60:28


Identity is central to Zero Trust, making it one of the most attractive targets for cyber attackers. While multi-factor authentication has long been a reliable way to ensure identity, traditional MFA has critical gaps.    This week on Feds At the Edge, Mark Brennan from the New Jersey Department of Health, and YubiKey's Jeff Frederick, explore how phishing-resistant cryptography and hardware security keys provide stronger protection against modern identity-based threats while improving the user experience. The panel also examines why hardware-backed authentication is recognized in NIST SP 800-63 Revision 4 as a highly secure approach to cryptographic MFA and shares practical guidance for implementation, including starting with a phased rollout, engaging executive leadership early, and continuously refining the program to build user confidence and support long-term Zero Trust success.  Tune in on your favorite podcast platform to discover how hardware-backed authentication can help agencies reduce identity-based attacks, strengthen security, and simplify the path to phishing-resistant MFA    

Cyber Security Headlines
Russia's router access routes, MemGhost haunts AI memory, DHS alert got waved off twice

Cyber Security Headlines

Play Episode Listen Later Jul 14, 2026 7:24


Russia's router access routes MemGhost haunts AI memory DHS alert got waved off… twice Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

Cyber Security Headlines
Multifunction Windows backdoor, NSA revives TAO, urgent ShareFile warning

Cyber Security Headlines

Play Episode Listen Later Jul 13, 2026 8:20


Windows backdoor stuffs multiple wipers and ransomware code into a single package NSA brings back Tailored Access Operations name for elite hacking unit Progress urges ShareFile customers to shut down storage zone controllers  Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

Business, Brains & the Bottom Line
Ep. 156: Ready to Recover Series: Part 2: Why Identity Has Become IT's Biggest Challenge

Business, Brains & the Bottom Line

Play Episode Listen Later Jul 9, 2026 20:33


Managing modern IT infrastructure isn't just about servers and networks anymore; it's about identity.In Part 2 of this five-part series, Paul sits down with Joe Ross, Joe Galvan, Terry Murray, John Parker, and Stephen Sepulveda. Joe Ross takes listeners inside the complexity of supporting more than 400 business units across 180 domains, three cloud platforms, and five Microsoft tenants. As organizations embrace hybrid and multi-cloud environments, identity has become the new security perimeter, and one compromised account can have enterprise-wide consequences.Joe shares why identity management has become one of the toughest challenges facing IT leaders today, discusses lessons learned from high-profile outages like the CrowdStrike incident, and explains why resilience is about more than just recovering systems; it's about maintaining trust, access, and business continuity.Whether you're leading IT operations, cybersecurity, or digital transformation, this episode offers practical insights into navigating today's increasingly complex technology landscape.In this episode, you'll learn:Why identity is the foundation of modern cybersecurityThe challenges of managing large-scale hybrid and multi-cloud environmentsLessons learned from major industry outages and disruptionsHow complexity creates risk—and what IT leaders can do about itStrategies for building a more resilient enterprise

HPE Tech Talk
Faster attacks, smarter defence, and the necessity of Zero Trust: cybersecurity in the age of AI | Jaye Tillson

HPE Tech Talk

Play Episode Listen Later Jul 9, 2026 19:26


Zero Trust has transitioned from buzzword to basic necessity. As AI has transformed the cybersecurity landscape, becoming a tool for both attack and defence, organisations are being forced to rethink how thy protect themselves, their users, and their networks. Technology Now welcomes back friend of the show Jaye Tillson, CTO Security and HPE Distinguished Technologist to discuss:• The impact of AI on cyber threats as well as cybersecurity• How Zero Trust can contain breeches if they cannot be prevented entirely• Why limited access is more important than ever in a distributed network

Darknet Diaries
176: NSL

Darknet Diaries

Play Episode Listen Later Jul 7, 2026 66:41 Transcription Available


One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn't right about this letter. It seemed to violate the constitution. So he set out to change the law.Learn more about Nicks work at calyxinstitute.org and phreeli.com.Check out Cindy's book Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance (https://amzn.to/4gXuK2J).SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.View all active sponsors.Sources https://www.democracynow.org/2010/8/11/gagged_for_6_years_nick_merrill https://globalfreedomofexpression.columbia.edu/cases/u-s-nicholas-merrill-v-loretta-e-lynch-14-cv-9763-vm/ https://clearinghouse.net/case/12966/ https://www.theguardian.com/law/2015/dec/06/fbi-national-security-letter-gag-order-nick-merrill https://www.aclu.org/documents/national-security-letters https://www.eff.org/cases/re-matter-2011-national-security-letter Cindy's Book: Privacy's Defender: My Thirty-Year Fight Against Digital Surveillance

CISO-Security Vendor Relationship Podcast
What Part of Zero Trust Does Your Exception Not Understand?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 7, 2026 37:46


All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series, and Andy Ellis, principal of Duha. Joining is Patti Degnan, operating partner, Andreessen Horowitz. In this episode: Identity built for one person at a time Patching can't outrun the exploit timeline The exception hiding inside zero trust A revenue question nobody's answered yet A huge thanks to our sponsor, ThreatLocker ThreatLocker delivers Zero Trust Network Access and Zero Trust Cloud Access that verifies both user and device before granting access to specific applications. No broad access, nothing exposed, and no reliance on credentials alone. It's a smarter way to control access and reduce risk. Learn more at ThreatLocker.com/CISO.

Hybrid Identity Protection Podcast
The Entra ID Recovery Gap with Tim Wolf and Tim Springston, Semperis

Hybrid Identity Protection Podcast

Play Episode Listen Later Jul 7, 2026 54:18


This episode features Tim Wolf, Senior Solutions Architect at Semperis, and Tim Springston, Principal Product Manager for Recovery Solutions at Semperis.Tim Wolf spent years as a Microsoft Premier Field Engineer helping enterprise customers architect identity solutions at scale. Tim Springston brings 25 years in identity and security and served as Microsoft's product manager for Azure AD recoverability, including direct involvement in building the Entra ID shared responsibility model documentation.In this episode, they walk through what the shared responsibility model actually means for Entra tenant data, how token-based attacks sidestep phishing-resistant authentication, and what happens when a threat actor hard-deletes objects and locks you out.They examine where Microsoft's new Entra ID Identity Resilience Recovery feature stops short, and why planning your recovery before anything goes wrong is the only call to action that matters.Guest BiosTim Wolf Tim Wolf is a Senior Solution Architect at Semperis. Tim's mission is protecting identities. Currently at Semperis, Tim ensures the resilience of Active Directory and Entra ID. Their background includes years as a Microsoft PFE, implementing Zero Trust and modern Authentication like Fido at an enterprise scale. Tim is an active speaker at multiple conferences, advocating for secure and automated identity architectures.Tim Springston Tim Springston is Principal Product Manager for recovery solutions at Semperis. He has over 25 years' identity and security experience with education, government, and Fortune 500 organizations from around the world. In his 25 years at Microsoft, he led services and support for Active Directory and later for Microsoft's cloud identity platform as it evolved from Windows Azure AD to Azure AD. At Microsoft, he was a recurring speaker at internal TechReady conferences and external events. Prior to Semperis, Tim was Microsoft's product manager for Azure AD (now Entra ID) recoverability and Sophos' IAM product manager for the Sophos Central cybersecurity platform.Guest Quotes  “The first step in resiliency is not just having a backup plan or a backup tool or capabilities to put things back. You need to know what's important to your organization. If you know what's important, you know what to put back, you know when it's broken.” - Tim Springston “If Entra ID is going down... This is business critical today. You're not available to sign in to Teams, to SharePoint, to Salesforce, to your business critical application.  So to really understand Entra ID is business critical.” - Tim WolfTime stamps 0:40 Meet Tim Wolf and Tim Springston 2:32 The Microsoft Shared Responsibility Model for Entra ID 6:22 How Entra ID Tenants Are Being Attacked 8:45 Token-Based Attacks Explained 12:26 What Happens When a Threat Actor Takes Over Your Tenant 19:05 Microsoft's New Entra ID Recovery Solution 25:24 The Difference Between Accidents and Adversaries 28:54 Semperis' Disaster Recovery for Entra Tenant 39:27 Hard Delete and Tenant Cloning Limits 45:30 Resiliency Playbooks and Testing 49:58 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world's leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Tim Wolf on LinkedInConnect with Tim Springston on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about Semperis

TechSperience
Episode 147: Ripple Security Logic for Protecting the Interconnected Healthcare Ecosystem

TechSperience

Play Episode Listen Later Jul 6, 2026 29:49


Healthcare organizations face growing pressure to modernize clinical systems while defending against increasingly sophisticated cyber threats. In this episode, host Kim Coombes is joined by Connection Security Center of Excellence experts John Chirrillo and Rob Di Girolamo to discuss Ripple Security Logic, a framework for understanding and managing risk across today's highly connected healthcare environments. The conversation explores the interconnected relationships between endpoints, medical devices, networks, cloud platforms, identities, and clinical workflows. Hear from our experts as they discuss how XDR-powered observability, Zero Trust principles, AI-driven analytics, and resilience-focused strategies can help healthcare organizations reduce risk, strengthen threat detection, and support better patient outcomes. Moderator: Kimberlee Coombes, Security Solution Architect, Connection Guest: John Chirillo, Principal Security Architect, Connection Guest: Rob Di Girolamo, Senior Security Architect, Connection Show Notes (0:00) - Welcome and episode overview: Healthcare cybersecurity and Ripple Security (1:02) - How Ripple Security changes organizational thinking about cybersecurity (2:00) - Interconnected ecosystem of healthcare data and devices (2:57) - Visualizing ripple effects on patient care and organizational risks (3:27) - The number of connected devices per hospital bed (4:26) - Growth of attack surface with connected medical devices (5:24) - Importance of endpoint security and XDR's role in healthcare (6:22) - How XDR correlates telemetry for threat detection (7:20) - The critical role of observability versus simple data collection (8:45) - Distinguishing noise from signals using context-aware observability (10:10) - Significance of XDR in managing healthcare's vast device ecosystem (11:37) - Visibility challenges in healthcare networks and XDR's benefits (13:01) - Faster detection and response through integrated telemetry (14:50) - The importance of east-west traffic monitoring and network segmentation (17:37) - Redefining perimeter security in a remote and cloud-enabled world (20:03) - Combating alert fatigue with AI-driven analytics (21:55) - Security considerations for cloud adoption in healthcare (25:08) - Impact of breaches and costs on healthcare organizations (26:04) - Building resilience as a core component of cybersecurity strategy (28:24) - Aligning security with business resilience and clinical continuity (29:21) - Final thoughts: Trust, resilience, and proactive cybersecurity planning

DrZeroTrust
Zero Trust for Hiring

DrZeroTrust

Play Episode Listen Later Jul 6, 2026 34:20


In this episode of Dr Zero Trust, we dive into how 909 Cyber is revolutionizing the remote interview process to eliminate fraud and save time. Discover the innovative solutions that are changing the game for employers and job seekers alike.Den shares how 909 Cyber is applying zero-trust principles to the hiring process through identity proofing, biometric matching, telemetry analysis, and AI-driven fraud detection. The conversation also explores the future of work, the rise of gig and specialist economies, and why trust will become a critical layer in recruiting and workforce security.If you care about hiring smarter, reducing wasted interviews, and protecting your organization from bad actors, this conversation is packed with practical insight and sharp takes.Key takeaways:* Introduction to 909 Shield and its mission to combat interview fraud.* The importance of identity proofing and biometric matching in hiring.* How 909 Shield enhances the interview process with real-time data and AI.* The impact of remote work on hiring practices and the gig economy.* Insights on the future of work and the rise of specialist roles.Timestamps:00:00 Introduction02:12 Meet Den Jones, CEO of 909 Cyber03:35 The problem of interview fraud06:22 How 909 Shield works08:46 The role of AI in hiring10:23 Addressing deep fakes in interviews12:20 The importance of trust in hiring15:01 The gig economy and its futureWhat's your biggest challenge with remote hiring? Drop it in the comments!Subscribe for weekly insights on cybersecurity and hiring trends!#ZeroTrust #Cybersecurity #RemoteHiring

Feds At The Edge by FedInsider
Ep. 255 Responding to Ransomware

Feds At The Edge by FedInsider

Play Episode Listen Later Jul 2, 2026 59:05


Ransomware has become a far more serious threat to government than many organizations realize, and it's no longer just about paying a ransom.   This week on Feds At the Edge, cybersecurity experts explore what agencies can do to strengthen their defenses, including adopting Zero Trust principles, improving network segmentation, and planning for recovery before an attack occurs.  Cesar Gamez from City of Roseville, CA explains how ransomware attacks have evolved, from encrypting files for financial gain to tactics that threaten to expose sensitive data or target victims' customers if demands aren't met.   And Travis Rosiek of Rubrik Public Sector, introduces an even more alarming trend: "wiper" attacks. Unlike traditional ransomware, these attacks - often associated with nation-state actors - are designed to permanently destroy or corrupt data, leaving organizations with nothing to recover even if they were willing to pay.   Tune in on your favorite podcast platform as our guests also examine the security challenges of hybrid and cloud environments and explain why collaboration and information sharing are essential to staying ahead of increasingly sophisticated cyber threats.         

Microsoft Mechanics Podcast
Zero Trust security for AI agents

Microsoft Mechanics Podcast

Play Episode Listen Later Jul 2, 2026 10:37


Apply Zero Trust controls to every AI agent in your environment across identity, tool usage, and data access. Extend Conditional Access in Microsoft Entra to evaluate every agent authorization request in real time against the same risk signals as human users. Assign each agent its own managed identity with Entra Agent ID and scope permissions with Access Packages. Govern your MCP catalog as a software supply chain — unapproved tools don't run, and approved servers lock behind Azure API Management. Log every agent tool call, API access, and data lookup into Microsoft Sentinel for continuous anomaly detection. Purview Insider Risk Management auto-assigns risk levels so you can investigate fast or revoke access entirely. DLP and sensitivity labels in Microsoft Purview restrict what agents can reach and auto-inherit to everything they generate, and Data Access Governance maps exactly what each agent can access before a prompt fires.  Jeremy Chapman, Microsoft 365 Director, shares how to put these controls into practice across every managed, self-hosted, and shadow agent in your estate. ► QUICK LINKS: 00:00 - How AI changes Zero Trust 01:20 - Zero Trust principles 02:27 - How to apply Zero Trust principles 03:40 - Conditional Access for Agent Identities 04:59 - Entra Agent ID + Access Packages 06:07 - Runtime Observability 06:58 - DLP, Sensitivity Labels + Data Access Governance 07:47 - MCP catalog 08:36 - AI apps & experiences 09:24 - Wrap up ► Link References  Watch the rest of this series at https://aka.ms/ZTMechanics For additional resources, check out https://aka.ms/GoZeroTrust ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics

Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Ep 331 Autonomous AI and Observability in Federal IT

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Play Episode Listen Later Jun 30, 2026 24:18


In this episode of the Federal Tech Podcast, John Gilroy interviews Justin Fessler, Vice President of Public Sector at LogicMonitor, about the growing role of autonomous AI and observability in federal government IT operations. Fessler explains that autonomous AI is not about replacing people but about automating repetitive operational tasks, correlating complex system events, and helping IT teams make faster, better-informed decisions. Rather than allowing AI to operate without oversight, LogicMonitor focuses on keeping humans "in the loop" while AI handles time-consuming analysis and routine remediation. A central theme is the importance of complete visibility across increasingly complex federal environments. LogicMonitor's agentless monitoring technology discovers devices, cloud resources, applications, and shadow IT without requiring software agents on every endpoint. This broad visibility enables agencies to identify unmanaged assets, reduce blind spots, optimize cloud costs, and strengthen security. The discussion also highlights observability's critical role in Zero Trust. Fessler notes that agencies cannot secure or verify assets they cannot see. By discovering everything connected to the network—including servers, cloud services, IoT devices, cameras, badge readers, and physical infrastructure—LogicMonitor helps agencies build a stronger Zero Trust foundation. Gilroy and Fessler examine the challenges of managing hybrid and multi-cloud environments, emphasizing that agencies require a single operational view regardless of where workloads reside. LogicMonitor integrates information across cloud providers and third-party platforms, including ServiceNow, Splunk, Dynatrace, Datadog, and IBM Watsonx, enabling AI-driven event correlation and faster incident response. The conversation concludes with the future of autonomous IT. Fessler predicts increased automation, AI-assisted self-healing infrastructure, and significantly reduced mean time to identify and resolve incidents. Rather than replacing IT professionals, autonomous AI will eliminate repetitive work, allowing skilled personnel to focus on higher-value mission objectives while improving operational resilience, reducing alert fatigue, and delivering better digital services to citizens.         For more information, visit www.logicmonitor.com/solutions/federal-government.

Cyber Security Headlines
The Department of Know: SearchLeak, Check Point zero-day, and pulling the plug on Fable

Cyber Security Headlines

Play Episode Listen Later Jun 19, 2026 53:54


This week's Department of Know is hosted by Rich Stroffolino, with guests Arif Hameed, CISO, C&R Software; Adam Palmer, CISO, First Hawaiian Bank; Jon Collins, Field CTO, GigaOm; and Jack Leidecker, EVP, CSO, Gainsight. Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk?   That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.   ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.   That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

Cyber Security Headlines
Police clean WordPress sites, Klue OAuth breach, Warner's CISA warnings

Cyber Security Headlines

Play Episode Listen Later Jun 19, 2026 9:28


Police clean ups SocGholish-infected sites tied to Evil Corp Klue OAuth breach linked to Icarus Salesforce data theft attacks Warner warns of CISA cuts, staffing gaps in letter to acting chief  Get the show notes here: https://cisoseries.com/cybersecurity-news-police-clean-wordpress-sites-klue-oauth-breach-warners-cisa-warnings/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.  

Telecom Reseller
Versa Networks on Zero Trust MCP and the Hidden Risk of Agentic AI, Podcast

Telecom Reseller

Play Episode Listen Later Jun 19, 2026


By Doug Green “Governance is absolutely necessary. It's no longer optional.” In this episode of the Technology Reseller News podcast, Doug Green speaks with Rajesh Kari, Senior Director of Products and Solutions at Versa Networks, about the emerging security challenges created as agentic AI moves into live network and security operations. Kari says Versa Networks is a leader in SASE, offering a unified platform that brings together networking, security and operations across enterprise infrastructure. As AI becomes more embedded in operations, Versa is focused on a new zero trust challenge: controlling not only users and devices, but also the hidden AI-driven sub-actions that can touch production systems. Kari explains that agentic AI is different from traditional AI because it can take action on behalf of users. Rather than simply answering a prompt or returning information, an agent may break a task into sub-queries, call APIs, use credentials, access systems and make changes inside the infrastructure. Those hidden sub-queries can create risk if organizations cannot see, validate and govern what the agent is doing. “People build agents. They know what the objective of the agents are,” Kari says. “But under the hood, what the agent actually deploys, which APIs it accesses, and what kinds of authorization and authentication it leverages can be unknown.” The podcast explores how this creates new exposure for enterprises, MSPs and channel partners. If an AI agent gains access to credentials or production systems, organizations need constant verification, validation and governance around each action. Kari says agentic AI can also hallucinate or generate unnecessary sub-queries, creating additional security and operational risk. Versa is addressing this through Versa Verbo and its Zero Trust MCP architecture. Verbo is designed to help network practitioners gain visibility, management and analytics through natural language interactions. Instead of searching through hundreds of alerts or dashboards, operators can ask questions about outages, performance issues, configuration changes, security incidents and branch health. The Zero Trust MCP architecture extends that capability by applying governance and access control to AI-driven actions. Kari says this enables AI models and agents to query Versa infrastructure securely, while maintaining controls around authentication, authorization, APIs and operational workflows. For MSPs and channel partners, Kari sees an important opportunity. Many organizations want to deploy AI quickly but do not have the internal capability to build governance infrastructure around it. Partners that develop practices around policy architecture, deployment, ongoing governance and human-in-the-loop approval can help customers adopt agentic AI more safely. Kari says AI operations copilots are becoming standard in SASE and network platforms. Network teams, infrastructure managers and executives increasingly want to use natural language to understand the health of their infrastructure instead of relying only on dashboards. But as those tools become more powerful, governance becomes the deciding factor in adoption. “If the agent has gained access into certain files or visuals which has violated any particular compliance standards, it becomes the responsibility of the organization to prove it,” Kari says. For Versa, the message is clear: agentic AI can simplify operations and accelerate decision-making, but it must be governed from the beginning. Zero trust principles need to be built into every AI agent connection. Learn more at www.versa-networks.com  

Cyber Security Headlines
Anthropic tells G7 to cooperate, Fortinet VPN leak exposes credentials, Crypto Clipper abuses reviews

Cyber Security Headlines

Play Episode Listen Later Jun 18, 2026 7:33


Anthropic tells G7 to cooperate Fortinet VPN leak exposes credentials Crypto Clipper abuses reviews, narrators, and comments Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-tells-g7-to-cooperate-fortinet-vpn-leak-exposes-credentials-crypto-clipper-abuses-reviews/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.  

This Week in Tech (Audio)
TWiT 1087: Evil is the Root of All Money - Could Local AI Laptops Compete With Data Center Giants?

This Week in Tech (Audio)

Play Episode Listen Later Jun 8, 2026 163:53


An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit

This Week in Tech (Video HI)
TWiT 1087: Evil is the Root of All Money - Could Local AI Laptops Compete With Data Center Giants?

This Week in Tech (Video HI)

Play Episode Listen Later Jun 8, 2026 163:53


An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit

All TWiT.tv Shows (MP3)
This Week in Tech 1087: Evil is the Root of All Money

All TWiT.tv Shows (MP3)

Play Episode Listen Later Jun 8, 2026 163:53 Transcription Available


An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit

Paul's Security Weekly
The State of AI in SecOps, the Unintended Consequences of Vulnmaxxing, and the News - Filip Stojkovski - ESW #462

Paul's Security Weekly

Play Episode Listen Later Jun 8, 2026 97:51


Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked project. We also discuss how most of the market has traditionally been focused on the "middle" of the process, which is effectively alert management. Where the conversation really gets interesting is shifting left to discuss building better quality detections. Segment Resources: Be sure to check out SecOps Unpacked - it has more than just vendor information: there are articles, frameworks, podcast episodes, research, and articles/thought leadership Topic: The Unintended Consequences of Vulnmaxxing We discuss my latest blog post where I share a theory that perhaps Project Glasswing is a clever exclusive freemium tier, where Anthropic is hoping to ensnare the world's largest producers of software into using its most expensive model to fix their code for the foreseeable future, creating a much needed new revenue stream for the AI giant with a Trillion dollar valuation. There are some potential unintended consequences that come along with an expensive vulnerability discovery/remediation process that threatens to raise the security poverty line and leave less wealthy companies behind. The Weekly Enterprise News Finally, in the enterprise security news, If you were starting a cybersecurity company today, which category would you pick? layoffs funding the White House AI executive order OpenAI's frontier governance framework Anthropic's Zero Trust for AI agents guide IBM's vulnmaxxing efforts RICO as a service for job seekers Instagram had possibly the most embarrassing hack ever All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-462

Radio Leo (Audio)
This Week in Tech 1087: Evil is the Root of All Money

Radio Leo (Audio)

Play Episode Listen Later Jun 8, 2026 163:53 Transcription Available


An astronomical amount of money is being poured into AI and data centers as tech giants fight for dominance, but is this fueling the next big tech bubble or just the price of staying in the game? Get the panel's opinions on wild IPO valuations, global power grabs, Build 2026, NVIDIA GTC Taipei, and even successful YouTuber movies! SpaceX IPO to Be Largest Ever at $135 Share Price Utah residents sue officials over Kevin O'Leary data center plan When AI builds itself NVIDIA announces RTX Spark as 'the most efficient PC chip ever built' Major Homebuilder To Test Placing Mini Data Centers in Suburban Backyards Microsoft Build 2026: The 7 biggest announcements What to Expect at Apple's WWDC 2026: iOS 27, New Siri and AI Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Trump Signs Executive Order Seeking Oversight of A.I. Models Trump: U.S. stake in AI giants "could be a beautiful thing" Cable lobby warns of chaos if FCC doesn't relax ban on foreign routers Google ordered to put clearer links in AI search and let UK publishers opt out AT&T and Verizon lose Supreme Court case over fines for selling location data YouTubers Win the Box Office, Goodbye Gatekeepers, The YouTube Bar YouTube overtakes Netflix in average daily viewing around the world Host: Leo Laporte Guests: Joey de Villa, Jeff Jarvis, and Fr. Robert Ballecer, SJ Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: expressvpn.com/twit ZipRecruiter.com/twit canary.tools/twit - use code: TWIT Melissa.com/twit helixsleep.com/twit

Packet Pushers - Heavy Networking
HN830: Tailscale CEO on WireGuard, Zero Trust, and Securing AI (Sponsored)

Packet Pushers - Heavy Networking

Play Episode Listen Later Jun 5, 2026 56:39


If you think Tailscale is just a VPN for the home lab, think again. On today's sponsored episode Ethan and Drew are joined by Tailscale CEO Avery Pennarun. Avery explains how the company has evolved into an enterprise-grade connectivity and security platform. He also dives into Tailscale Aperture, their new AI gateway designed to bring... Read more »

Packet Pushers - Full Podcast Feed
HN830: Tailscale CEO on WireGuard, Zero Trust, and Securing AI (Sponsored)

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jun 5, 2026 56:39


If you think Tailscale is just a VPN for the home lab, think again. On today's sponsored episode Ethan and Drew are joined by Tailscale CEO Avery Pennarun. Avery explains how the company has evolved into an enterprise-grade connectivity and security platform. He also dives into Tailscale Aperture, their new AI gateway designed to bring... Read more »

Packet Pushers - Fat Pipe
HN830: Tailscale CEO on WireGuard, Zero Trust, and Securing AI (Sponsored)

Packet Pushers - Fat Pipe

Play Episode Listen Later Jun 5, 2026 56:39


If you think Tailscale is just a VPN for the home lab, think again. On today's sponsored episode Ethan and Drew are joined by Tailscale CEO Avery Pennarun. Avery explains how the company has evolved into an enterprise-grade connectivity and security platform. He also dives into Tailscale Aperture, their new AI gateway designed to bring... Read more »

Darknet Diaries
175: Bayrob

Darknet Diaries

Play Episode Listen Later Jun 2, 2026 96:35


It started with a fake car listing on eBay.What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cryptocurrency for someone else. Millions of dollars siphoned from victims who had no idea.This is the story of Bayrob and the three men from Romanian who were behind it. And the long, strange road that led American investigators to their door.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that's built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This episode is sponsored by Chainguard. Chainguard builds container images the right way — minimal, hardened, and built from source every single day. We're talking images with zero known CVEs, designed from the ground up for production. No bloat. No mystery packages. No 2 a.m. patching marathons because some transitive dependency lit up your dashboard. Stop patching images that are insecure. Start shipping clean. Head to chainguard.dev to see how secure your software supply chain can really be.

The John Batchelor Show
S8 Ep945: (10) Francis Rose explores the security risks of electronic health records, explaining how nation-states like China seek bulk data for espionage and how the government utilizes "zero trust" technology to deter sophisticated machine-spe

The John Batchelor Show

Play Episode Listen Later May 30, 2026 5:53


(10) Francis Rose explores the security risks of electronic health records, explaining how nation-states like China seek bulk data for espionage and how the government utilizes "zero trust" technology to deter sophisticated machine-speed hacks.1913 GETTYSBURG

Darknet Diaries
174: Pacific Rim

Darknet Diaries

Play Episode Listen Later May 5, 2026 90:54


For six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to properly secure their firewalls.Was it ethical? Was it effective? They disrupted nine zero-day attacks, exposed who was hacking them, and forced the hackers to change tactics. But at what cost?You have to listen to one of the most audacious corporate cyber defenses ever conducted.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that's built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com.Support for this show comes from Drata. Drata is the trust management platform that uses AI-driven automation to modernize governance, risk, and compliance, helping thousands of businesses stay audit-ready and scale securely. Learn more at drata.com/darknetdiaries.Sources https://news.sophos.com/en-us/2024/10/31/pacific-rim-timeline/ https://www.justice.gov/archives/opa/pr/seven-hackers-associated-chinese-government-charged-computer-intrusions-targeting-perceived https://www.fbi.gov/wanted/cyber/guan-tianfeng