
Sign up to save your podcasts
Or


Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript.
TranscriptToday’s cyber and AI risk landscape is evolving at an unprecedented pace. We’re seeing not just more attacks, but smarter, faster, and more automated threats—driven by the same artificial intelligence that’s transforming business operations worldwide. The lines between attacker and defender are blurring, as both sides leverage AI to outmaneuver each other. This is no longer a theoretical arms race; it’s playing out in real time, with immediate implications for every organization, regardless of size or sector.
Let’s start with one of the most significant developments in recent memory: the confirmed use of artificial intelligence to create zero-day exploits in the wild. Google and other sources have validated that criminals are now using AI to automate the discovery and weaponization of new vulnerabilities—zero-days that have never been seen before. This marks a fundamental shift in the threat landscape. In the past, finding a zero-day required specialized expertise, patience, and luck. Now, AI can systematically probe software, identify weaknesses, and generate exploit code at a scale and speed that simply wasn’t possible before.
For security leaders, this means the old playbook for vulnerability management is no longer enough. Traditional cycles—identify, patch, repeat—are being outpaced by adversaries who can unleash new exploits faster than defenders can respond. The implication is clear: organizations must invest in AI-driven detection and response tools, not just to keep up, but to avoid falling dangerously behind. This isn’t about replacing human expertise; it’s about augmenting it with automation that can match the scale and speed of modern attacks.
While AI-generated zero-days grab headlines, the day-to-day reality of cyber defense remains rooted in the basics—like patch management. This month, Microsoft, Fortinet, and Ivanti collectively released patches for over 120 vulnerabilities. No zero-days were reported in this cycle, but the sheer volume and severity of these flaws highlight a persistent truth: unpatched systems remain one of the most common entry points for attackers. Security teams should treat these updates as urgent, especially for internet-facing assets and critical infrastructure. Rapid patching reduces the window of exposure, but it’s only part of the equation.
Even in well-patched environments, attackers are finding new ways in. Take the BitUnlocker downgrade attack, for example. Researchers have demonstrated that Windows 11 disk encryption—BitLocker—can be bypassed in under five minutes by exploiting downgrade vulnerabilities. If an attacker gains physical access to a device, or can leverage certain remote management flaws, encrypted data can be exposed. For organizations relying on BitLocker, it’s time to review deployment configurations, monitor for related advisories, and consider additional layers of protection for sensitive endpoints.
Supply chain risk is another area that’s drawing increasing scrutiny. The recent emergence of the Mini Shai-Hulud worm is a case in point. This worm has compromised several widely used open-source packages, including TanStack, Mistral AI, and Guardrails AI. The implications are serious: any application or AI model that depends on these packages could be at risk of downstream compromise. It’s a reminder that your security is only as strong as the weakest link in your software supply chain. Security leaders should take stock of their dependencies, monitor for indicators of compromise, and build security controls into their development pipelines.
Let’s talk about the human element—specifically, the challenge of identity and credential governance. A new report finds that 74% of UK businesses suffered at least three identity breaches in the past year. The main culp
By Mike HouschDaily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript.
TranscriptToday’s cyber and AI risk landscape is evolving at an unprecedented pace. We’re seeing not just more attacks, but smarter, faster, and more automated threats—driven by the same artificial intelligence that’s transforming business operations worldwide. The lines between attacker and defender are blurring, as both sides leverage AI to outmaneuver each other. This is no longer a theoretical arms race; it’s playing out in real time, with immediate implications for every organization, regardless of size or sector.
Let’s start with one of the most significant developments in recent memory: the confirmed use of artificial intelligence to create zero-day exploits in the wild. Google and other sources have validated that criminals are now using AI to automate the discovery and weaponization of new vulnerabilities—zero-days that have never been seen before. This marks a fundamental shift in the threat landscape. In the past, finding a zero-day required specialized expertise, patience, and luck. Now, AI can systematically probe software, identify weaknesses, and generate exploit code at a scale and speed that simply wasn’t possible before.
For security leaders, this means the old playbook for vulnerability management is no longer enough. Traditional cycles—identify, patch, repeat—are being outpaced by adversaries who can unleash new exploits faster than defenders can respond. The implication is clear: organizations must invest in AI-driven detection and response tools, not just to keep up, but to avoid falling dangerously behind. This isn’t about replacing human expertise; it’s about augmenting it with automation that can match the scale and speed of modern attacks.
While AI-generated zero-days grab headlines, the day-to-day reality of cyber defense remains rooted in the basics—like patch management. This month, Microsoft, Fortinet, and Ivanti collectively released patches for over 120 vulnerabilities. No zero-days were reported in this cycle, but the sheer volume and severity of these flaws highlight a persistent truth: unpatched systems remain one of the most common entry points for attackers. Security teams should treat these updates as urgent, especially for internet-facing assets and critical infrastructure. Rapid patching reduces the window of exposure, but it’s only part of the equation.
Even in well-patched environments, attackers are finding new ways in. Take the BitUnlocker downgrade attack, for example. Researchers have demonstrated that Windows 11 disk encryption—BitLocker—can be bypassed in under five minutes by exploiting downgrade vulnerabilities. If an attacker gains physical access to a device, or can leverage certain remote management flaws, encrypted data can be exposed. For organizations relying on BitLocker, it’s time to review deployment configurations, monitor for related advisories, and consider additional layers of protection for sensitive endpoints.
Supply chain risk is another area that’s drawing increasing scrutiny. The recent emergence of the Mini Shai-Hulud worm is a case in point. This worm has compromised several widely used open-source packages, including TanStack, Mistral AI, and Guardrails AI. The implications are serious: any application or AI model that depends on these packages could be at risk of downstream compromise. It’s a reminder that your security is only as strong as the weakest link in your software supply chain. Security leaders should take stock of their dependencies, monitor for indicators of compromise, and build security controls into their development pipelines.
Let’s talk about the human element—specifically, the challenge of identity and credential governance. A new report finds that 74% of UK businesses suffered at least three identity breaches in the past year. The main culp