Security Weekly Podcast Network (Video)
Security Weekly Productions
0
The Security Weekly Podcast Network is a comprehensive cybersecurity podcast feed featuring shows like Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. It covers hacking techniques, vulnerabilities, industry trends, and expert interviews for cybersecurity professionals and tech enthusiasts.
Episodet
-
Followership, CyberSecurity Leadership, and Judgement as a Defining Skill - Kenyada Meadows - BSW #465 16.09.2026 57minThe overwhelming majority of people, across the full span of their professional lives, operate without formal authority over the domains in which they work (i.e., leadership). Yet followership has almost no sustained literature, no targeted development, and no rigorous framework of its own. If you're not a leader, what does a follower look like? Kenyada Meadows, CEO & Founder at The Executive Parent Company, joins Business Security Weekly to discuss his book, The PASSENGER Seat, which outlines a framework for followership. Kenyada will outline the nine disciplines of the framework across three dimensions, including: (P) Principled Anchoring — Holds values explicitly and specifically enough to guide behavior under pressure; knows the limit line before reaching it. (A) Accountability — Communicates upward honestly, documents concerns before decisions are made, and owns errors without deflection. (S) Self-Mastery — Invests deliberately in work, home, and inner domains, so identity — and ethical agency — isn't hostage to institutional threat. (S) Systems Thinking — Reads the institution analytically — what produces the patterns observed, and where honest information is being filtered. (E) Emerging Risk Management — Functions as an early-warning system for risks that formal frameworks haven't yet named. (N) Negotiation — Translates insight and values into institutional impact through credibility, framing, coalition, and timing. -(G) Guardianship — Protects what the institution stands for over time, especially when no one is watching. (E) Enablement — Ensures influence strengthens collective capacity rather than merely advancing individual position. (R) Results-Driven Influence — Binds the other eight disciplines toward outcomes that are genuinely better — not merely visible. In the leadership and communications segment, Stop playing with the CISO role. Fix cybersecurity leadership, What CIO-CISO alignment looks like when it's working, Why judgment is emerging as cybersecurity's defining skill, and more! Show Notes: https://securityweekly.com/bsw-465 -
RoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More - SWN #616 15.09.2026 32minRoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More on the Security Weekly News. Show Notes: https://securityweekly.com/swn-616 -
The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400 15.09.2026 52minWhile agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jason Cortlund break down how threat actors leverage LLMs as a force multiplier to accelerate mobile app attacks. Then we discuss actionable defense strategies, from viewing agents as an active adversary to leveraging server-side threat telemetry, attestation, and layered defense strategies combined with polymorphic code releases. This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them! Show Notes: https://securityweekly.com/asw-400 -
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476 14.09.2026 1h 40minInterview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-476 -
9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615 11.09.2026 34minTwenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on. Then we get to work. Shift-left didn't fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request — so the earliest trust boundary isn't your first commit any more, it's the moment an agent gets context and authority. Most of us haven't moved our controls with it. Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every layer built to look too boring to escalate. When your analyst closes that alert as adware, they may have just closed three separate compromises. Google's threat tracker: a credential-harvesting campaign built and run in under six hours, with Markdown files as attacker playbooks. And malware carrying prompt-injection text designed to make your LLM scanner refuse to look at it — because a refusal that reads as "clean" is a free pass. A CVSS 10 in Gemini CLI that never touched the model. No prompt, no injection, no tool call. The attacker just turned up before the sandbox did. The first ever Take It Down Act sentencing — handled carefully, with what you actually do if someone tells you something, and a proper shout-out to Dale, the Cyber Safety Guy, whose work every parent with a teenager online should have bookmarked. Two hundred and sixty-three million dollars walks out of a Bitcoin sidechain and then walks back in. Nobody stole the keys. They just convinced the system to sign a lie. Anthropic's 154-page threat report. And an alignment lead who puts extinction odds above ten percent. All that, plus Josh Marpet's take, on Security Weekly News #615. Show Notes: https://securityweekly.com/swn-615 -
It's More Secure When It's Disabled - PSW #943 10.09.2026 2h 2minIn the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Show Notes: https://securityweekly.com/psw-943 -
Security Money: The Index Explodes, as the History of AI Teaches Us About Investments - John Willis - BSW #464 09.09.2026 53minAI is all the hype, but we're currently stuck at the bottom of the 'J' curve. Wild enthusiasm has given way to the reality of costs, benefits, and risks. What's next for AI and companies looking to capitalize on the AI trends? John Willis, author, researcher, and technology industry veteran, joins Business Security Weekly to discuss AI's impact on fundraising. John explores what the history of AI can teach us about the current moment, including how to separate genuine technological transformation from hype and better understand where AI may take us next. Next, it's time for Security Money. The Index is exploding upwards as the markets continue to climb. Both the Index and the NASDAQ, hit all time highs. The Business Security Weekly crew breaks down funding, acquisitions, and performance of both the public and private markets. The Security Weekly 24 Index is made up of the following pure play public security companies: SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc Show Notes: https://securityweekly.com/bsw-464 -
Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland - SWN #614 08.09.2026 35minCybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland, and More on the Security Weekly News. Show Notes: https://securityweekly.com/swn-614 -
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen - ASW #399 08.09.2026 1h 9minWe showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called "AgentBaiting," in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption. Segment Resources: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware For more information about Island's research, please visit https://securityweekly.com/islandbh After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5 Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection. This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them! The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it. This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them! Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production. Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster. This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them! Show Notes: https://securityweekly.com/asw-399 -
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475 07.09.2026 1h 45minInterview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-475 -
Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet... - SWN #613 04.09.2026 37minWireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-613 -
Linux Threat Hunting - PSW #942 03.09.2026 2h 12minFirst up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Show Notes: https://securityweekly.com/psw-942 -
Preventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and Kai - Todd Sorrel, John Hurley, Galina Antova - BSW #463 02.09.2026 1hWire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn't end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how? Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are the only way to defend against these sophisticated wire fraud attacks. Optiv: The One Partner to Advise, Deploy and Operate. That's Cybersecurity Simplified - Black Hat interview with John Hurley, Chief Revenue Officer of Optiv This segment will focus on Optiv's unmatched ability to advise, deploy and operate complete cybersecurity programs. With more than 6,000 clients and 450 technology partners, Optiv is the one clients trust to handle real-world cyber complexity, reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at https://securityweekly.com/optivbh. The Shift to Machine-Led Security: What's Next for Cyber Defense - Black Hat interview with Galina Antova, CEO and Co-Founder of Kai Artificial intelligence is fundamentally changing cybersecurity- not only by making attacks faster and more sophisticated, but also by forcing defenders to rethink how security operations are built. In this conversation, Kai CEO and co-founder Galina Antova discusses why the industry is moving toward machine-led security, what is preventing organizations from trusting autonomous AI, and what recent survey data from hundreds of CISOs reveals about where cybersecurity is headed next. To learn more about Kai, please visit: https://securityweekly.com/kaibh Show Notes: https://securityweekly.com/bsw-463 -
Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612 01.09.2026 33minVictorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News. Show Notes: https://securityweekly.com/swn-612 -
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Nidhi Aggarwal, Gil Geron, Braden Russell - ASW #398 01.09.2026 1h 8minAppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable. Segment Resources https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt Vulnerability discovery and remediation gap in the AI era AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice. Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation. Segment Resources: https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/ https://orca.security/platform/ai-appgen-security/ This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them! Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch. Segment Resources: https://www.bugcrowd.com/products/pathseeker/ https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/ https://www.bugcrowd.com/products/platform https://www.bugcrowd.com/products/ai-powered-security-intelligence/ Apply for early access at https://securityweekly.com/bugcrowdbh Show Notes: https://securityweekly.com/asw-398 -
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, John Hultquist, Ronan Murphy, Ellen Boehm, Frank Vukovits - ESW #474 31.08.2026 1h 36minInterview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh. Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out! Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS Black Hat Interview 1 - Google Cloud Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense. Segment Resources: https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more! Black Hat Interview 2 - Forcepoint Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety. Segment Resources: https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more! Black Hat Interview 3 - Keyfactor From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments. Segment Resources: https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/ https://www.keyfactor.com/education-center/what-is-trust-infrastructure/ https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1 This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more! Black Hat Interview 4 - Delinea Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session. This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more! Show Notes: https://securityweekly.com/esw-474 -
Mythos Writes the Exploit. Atlas Writes the Response. - Harman Kaur - SWN #611 28.08.2026 41minMost enterprise AI today is a conversation — it summarizes, suggests, recommends. Harman unpacks what changes when AI actually executes across endpoints, and the governance problem that creates. Where does the human stay in the loop, and where do they get out of the way? This segment is sponsored by Tanium. Visit https://securityweekly.com/tanium to learn more about them! Show Notes: https://securityweekly.com/swn-611 -
Hacking All The Devices, with AI? - Rob Allen - PSW #941 27.08.2026 2h 6minRob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Show Notes: https://securityweekly.com/psw-941 -
Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Dan Bowden, Leslie Nielsen, Brett Stone-Gross - BSW #462 26.08.2026 1h 7minThe threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios? Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report. Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat. Segment Resources: Mimecast's new whitepaper Securing The Agentic Enterprise: https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05 Mimecast's landing page for thought leadership resources: https://www.workprotected.com/ Mimecast's State of Human Risk Report: https://www.mimecast.com/resources/ebooks/state-of-human-risk/ Mimecast's Threat Intelligence Hub: https://www.mimecast.com/threat-intelligence-hub/ For more information about Mimecast please visit: https://securityweekly.com/mimecastbh Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization. This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next. This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Show Notes: https://securityweekly.com/bsw-462 -
Fibonacci, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's, Aaran Leyland - SWN #610 25.08.2026 35minFibonacci and the Unhappy Number, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's battery, Aaran Leyland, and More on the Security Weekly News. Show Notes: https://securityweekly.com/swn-610
I/E popullarizuar në
Ky podkast shfaqet edhe në listat e podkasteve të këtyre shteteve.