Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • Mitigating attacks against AI-enabled Apps, Replacing the CIA triad, Enterprise News - David Brauchler - ESW #429
    Segment 1: David Brauchler on AI attacks and stopping them

    David Brauchler says AI red teaming has proven that eliminating prompt injection is a lost cause. And many developers inadvertently introduce serious threat vectors into their applications – risks they must later eliminate before they become ingrained across application stacks.

    NCC Group's AI security team has surveyed dozens of AI applications, exploited their most common risks, and discovered a set of practical architectural patterns and input validation strategies that completely mitigate natural language injection attacks. David's talk aimed at helping security pros and developers understand how to design/test complex agentic systems and how to model trust flows in agentic environments. He also provided information about what architectural decisions can mitigate prompt injection and other model manipulation risks, even when AI systems are exposed to untrusted sources of data.

    More about David's Black Hat talk:

    • Video of the talk and accompanying slides: https://www.nccgroup.com/research-blog/when-guardrails-arent-enough-reinventing-agentic-ai-security-with-architectural-controls/
    • Talk abstract: https://www.blackhat.com/us-25/briefings/schedule/#when-guardrails-arent-enough-reinventing-agentic-ai-security-with-architectural-controls-46112
    • Slide presentation only: https://i.blackhat.com/BH-USA-25/Presentations/USA-25-Brauchler-When-Guardrails-Arent-Enough.pdf

    Additional blogs by David about AI security:

    • Analyzing Secure AI Architectures: https://www.nccgroup.com/research-blog/analyzing-secure-ai-architectures/
    • Analyzing Secure AI Design Principles: https://www.nccgroup.com/research-blog/analyzing-secure-ai-design-principles/
    • Analyzing AI Application Threat Models: https://www.nccgroup.com/research-blog/analyzing-ai-application-threat-models/
    • Building Security‑First AI Applications: A Best Practices Guide for CISOs: https://www.nccgroup.com/building-security-first-ai-applications-a-best-practices-guide-for-cisos/
    • Building Trust by Design for Secure AI Applications: Tips for CISOs: https://www.nccgroup.com/building-trust-by-design-for-secure-ai-applications-tips-for-cisos/
    • AI and Cyber Security: New Vulnerabilities CISOs Must Address: https://www.nccgroup.com/ai-and-cyber-security-new-vulnerabilities-cisos-must-address/
    Segment 2: Should we replace the CIA triad?

    An op-ed on CSO Online made us think - should we consider the CIA triad 'dead' and replace it? We discuss the value and longevity of security frameworks, as well as the author's proposed replacement.

    Segment 3: The Weekly Enterprise News

    Finally, in the enterprise security news,

    1. Slow week for funding, older companies raising via debt financing
    2. A useful AI framework from the Cloud Security Alliance
    3. two interesting essays, one of which is wrong
    4. Folks are out here blasting unencrypted data to and from Satellites, while anyone can sniff and capture it
    5. getting hacked during a job interview
    6. LLM poisoning is far easier than previously thought
    7. F5 got breached
    8. Be careful when patching your Jeep ('s software)

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-429

    1 hr 39 min
  • New book from Dr. Anand Singh, why CISOs buy, and the latest news - Anand Singh - ESW #428
    Segment 1 - Interview with Dr. Anand Singh

    We're always thrilled to have authors join us to discuss their new book releases, and this week, it is Dr. Anand Singh. He seriously hustled to get his new book, Data Security in the Age of AI, out as soon as possible so that it could help folks dealing with securing AI rollouts right now! We'll discuss why he wrote it, how he got it done so quickly, and who needs to read it.

    Segment Resources:

    • Get the book on Amazon: Data Security in the Age of AI (available in Kindle and print)
    Segment 2 - Topic: The reasons why CISOs buy (and the things that don't matter to them)

    Val Tsanev, founder of ExecWeb, part of the CyberRisk Alliance family, posted shared some VERY spicy insights about how CISOs buy products. This elicited some passionate responses.

    There are many interesting insights, but the biggest and most interesting is that 76% of CISOs choose products that presents the least risk to them, personally. Career safety trumps product performance, it would seem.

    Segment 3 - News

    In the enterprise security news,

    1. Shifting Zero
    2. Cyber insurance, unlike cyber crime, doesn't pay
    3. New AI security categories are popping up to serve Agentic and MCP servers
    4. how tech companies measure AI impact
    5. first malicious MCP server in the wild
    6. is your computer mouse listening to you?
    7. The Korean government did not follow the backup rule of three
    8. Think you've seen the absolute worst idea for a mobile app? Wait until you hear about Neon.
    9. We have no less than three squirrel stories involving bullets, lasers, and greasy snacks

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-428

    1 hr 44 min
  • AI & IAM: Where Security Gets Superhuman (Or Supremely Stuck) - Dor Fledel, Alexander Makarov, Aaron Parecki, Heather Ceylan, Matt Immler, Nitin Raina - ESW #427

    At Oktane 2025, leaders from across the security ecosystem shared how identity has become the new front line in protecting today's AI-driven enterprises. As SaaS adoption accelerates and AI agents proliferate, organizations face an explosion of human and non-human identities—and with it, growing risks like misconfigured access, orphaned accounts, and identity-based attacks.

    In this special Enterprise Security Weekly episode, we bring together insights from top experts:

    • Dor Fledel (Okta) explains how teams can gain visibility into AI agents, uncover risks, and enforce appropriate access controls.
    • Alexander Makarov (Adyen) shares how a global fintech unified and streamlined identity with Okta, improving both security and employee experience across 200+ countries.
    • Aaron Parecki (Okta) highlights the importance of open standards—like IPSIE, MCP, and A2A—for building secure, interoperable AI ecosystems and centralized control over AI-driven interactions.
    • Heather Ceylan (Box) discusses how Box embeds AI into workflows to enhance data protection, even for highly regulated industries.
    • Matt Immler (Okta) offers lessons from the field on strengthening defenses with behavioral monitoring, automation, and a security-first culture to counter attackers who now "log in" instead of hacking in.
    • Nitin Raina (Thoughtworks) warns about AI-driven social engineering—from deepfakes to multi-channel phishing—and shares practical strategies like phishing-resistant MFA, zero-trust architecture, and better employee training.

    From open standards to privileged access management and AI-powered defense, these Oktane 2025 conversations explore how identity-driven strategies are shaping the future of enterprise security.

    Segment Resources: https://www.okta.com/newsroom/articles/old-security-challenges--new-ai-risks--managing-authorization-in https://www.okta.com/newsroom/press-releases/okta-introduces-cross-app-access-to-help-secure-ai-agents-in-the/ https://www.okta.com/blog/ai/securing-the-ai-agent-ecosystem/ https://www.okta.com/customers/adyen/ https://www.okta.com/newsroom/?sort=featured&filters=okta%3Acategories%2Fidentity-security https://www.okta.com/customers/thoughtworks/

    This segment is sponsored by Oktane by Okta. Visit https://securityweekly.com/oktane to learn more about them!

    Show Notes: https://securityweekly.com/esw-427

    1 hr 35 min
  • Live interviews from Oktane 2025: threats, AI in apps, and AI in cybersecurity tools - Brett Winterford, Shiv Ramji, Damon McDougald - ESW #426

    How identity security can keep pace with the evolving threat landscape, with Brett Winterford

    Today's threat landscape has never been more complex. Malicious actors are leveraging tools like generative AI to develop more creative social engineering attacks that can have serious ramifications for businesses. Brett Winterford, VP of Okta Threat Intelligence, shares findings from his team's most recent investigations, as well as recommendations for organizations looking to strengthen their defenses.

    Segment Resources

    • https://www.okta.com/newsroom/articles/okta-threat-intelligence-exposes-genai-s-role-in-dprk-it-scams/
    • https://www.okta.com/newsroom/articles/okta-observes-v0-ai-tool-used-to-build-phishing-sites/
    • https://sec.okta.com/articles/uncloakingvoidproxy/

    How to navigate app development in the AI era with Shiv Ramji

    As AI reshapes how applications are built and consumed, developers and engineering leaders face a new set of challenges: enabling innovation while maintaining security. In this interview, Auth0 President Shiv Ramji will discuss the shifting landscape of application development in the AI era. He'll discuss the shift toward developing AI agents that are secure by design and standards-first so they can thrive within an interconnected web of applications and systems.

    How AI agents are reshaping cybersecurity from the inside out with Damon McDougald

    AI is being harnessed to transform cybersecurity operations—from automating routine tasks to closing skills gaps and accelerating incident response. Damon McDougald, Global Security Services Lead at Accenture, shares how agents can cut through alert fatigue and proactively defend against threats at scale. Damon also outlines the identity risks these agents introduce—and what cybersecurity leaders must do now to secure their access and maintain control in an increasingly autonomous environment.

    All three segments are sponsored by Oktane by Okta. Visit https://securityweekly.com/oktane to learn more!

    Show Notes: https://securityweekly.com/esw-426

    1 hr 36 min
  • Disruption is Coming for the Vulnerability Management Market - Tod Beardsley - ESW #425
    Interview with Tod Beardsley

    This interview is sponsored by runZero.

    Legacy vulnerability management (VM) hasn't innovated alongside of attackers, and it shows. Let's talk about the state of VM.

    Check out https://securityweekly.com/runzero to learn more!

    Topic Segment: NPM Incidents

    In this week's topic segment, we're discussing all the NPM supply chain attacks from the past 3 weeks.

    I recently published a roundup of these incidents over on my Substack.

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. funding and acquisitions are going crazy
    2. an exciting new canarytoken
    3. banks have a more sedate approach to agentic
    4. MCP security
    5. the future Subprime Code crash of 2028
    6. is security worried about the wrong risks?
    7. botnets are back in the headlines
    8. some bs research
    9. journalists getting duped by AI
    10. Animal crossing villagers are organizing against Tom Nook

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-425

    1 hr 48 min
  • Forrester's AEGIS Framework, the weekly news, and interviews with Fortra and Island - Jeff Pollard, Rohit Dhamankar, Michael Leland - ESW #424
    Segment 1 - Interview with Jeff Pollard

    Introducing Forrester's AEGIS Framework: Agentic AI Enterprise Guardrails For Information Security

    For this episode's interview, we're talking to Forrester analyst Jeff Pollard. I'm pulling this segment's description directly from the report's executive summary, which I think says it best:

    As AI agents and agentic AI are introduced to the enterprise, they present new challenges for CISOs. Traditional cybersecurity architectures were designed for organizations built around people. Agentic AI destroys that notion. In the near future, organizations will build for goal-oriented, ephemeral, scalable, dynamic agents where unpredictable emergent behaviors are incentivized to accomplish objectives. This change won't be as simple or as straightforward as mobile and cloud — and that's bad news for security leaders who in some cases still find themselves challenged by cloud security.

    Segment 2 - Weekly News

    Then, in the enterprise security news,

    1. there's funding and acquisitions, but we're not going to talk about them
    2. AI's gonna call the cops on you
    3. and everyone's losing money on it
    4. and Anthropic agreed to pay for all the copyright infringement they did when training models
    5. and Otter.ai got sued for recording millions of conversations without consent
    6. Burger King got embarrassed and their lawyers didn't like it
    7. NPM package mayhem
    8. certificate authority hijinks
    9. AI darwin awards

    All that and more, on this episode of Enterprise Security Weekly.

    Segment 3 - Executive Interviews from Black Hat 2025

    Interview with Rohit Dhamankar from Fortra

    Live from Black Hat 2025 in Las Vegas, Matt Alderman sits down with Rohit Dhamankar, VP of Product Strategy at Fortra, to dive deep into the evolving world of offensive security. From red teaming and pen testing to the rise of AI-powered threat simulation and continuous penetration testing, this conversation is a must-watch for CISOs, security architects, and compliance pros navigating today's dynamic threat landscape.

    Learn why regulatory bodies worldwide are now embedding offensive security requirements into frameworks like PCI DSS 4.0, and how organizations can adopt scalable strategies—even with limited red team resources. Rohit breaks down the nuances of purple teaming, AI-assisted red teaming, and the role of BAS platforms in enhancing defense postures.

    Whether you're building in-house capabilities or leveraging external partners, this interview reveals key insights on security maturity, strategic outsourcing, and the future of cyber offense and defense convergence.

    This segment is sponsored by Fortra. Visit https://securityweekly.com/fortrabh to learn more!

    Interview with Michael Leland from Island

    At BlackHat 2025 in Las Vegas, Matt Alderman sits down with Michael Leland, VP Field CTO at Island, to tackle one of cybersecurity's most urgent realities: compromised credentials aren't a possibility — they're a guarantee. From deepfakes to phishing and malicious browser plug-ins, attackers aren't "breaking in" anymore… they're logging in.

    Michael reveals how organizations can protect stolen credentials from being used, why the browser is now the second weakest link in enterprise security, and how Island's enterprise browser can enforce multi-factor authentication at critical moments, block unsanctioned logins in real time, and control risky extensions with live risk scoring of 230,000+ Chrome plug-ins.

    Key takeaways:

    • Why credential compromise is inevitable — and how to stop credential use
    • How presentation layer DLP prevents data leaks inside and outside apps
    • Real-time blocking of phishing logins and unsanctioned SaaS access
    • Plug-in risk scoring, version pinning, and selective extension control
    • Enabling BYOD securely — even after a catastrophic laptop loss
    • Why many users never go back to Chrome, Edge, or Safari after switching

    Segment Resources:

    • https://www.island.io/blog/how-the-enterprise-browser-neutralizes-the-risks-of-compromised-credentials

    This segment is sponsored by Island. Visit https://securityweekly.com/islandbh to learn more!

    Show Notes: https://securityweekly.com/esw-424

    1 hr 41 min
  • Ransomware, Agentic AI, and Supply Chain Risks: Insights from Black Hat 2025 - Theresa Lanowitz, Yuval Wollman, Mickey Bresman, J.J. Guy, Jason Passwaters, HD Moore, Jawahar "Jawa" Sivasankaran - ESW #423

    Doug White sits down with Theresa Lanowitz, Chief Evangelist at LevelBlue, for a powerful and timely conversation about one of cybersecurity's most pressing threats: the software supply chain. Theresa shares fresh insights from LevelBlue's global research involving 1,500 cybersecurity professionals across 16 countries. Together, they unpack the real-world risks of software acquisition in the API economy, the explosive growth of AI-generated code, and the rise of "vibe coding"—and how these trends are silently expanding the attack surface for organizations everywhere.

    Visit https://securityweekly.com/levelbluebh to download the Data Accelerator: Software Supply Chain and Cybersecurity as well as all of LevelBlue's research.

    In this interview, Yuval Wollman, President of CyberProof, unpacks how AI agents are not only expanding the attack surface—but reshaping the entire cyber threat landscape. Discover how ransomware-as-a-service platforms like Funksec and Dragonforce are operating with enterprise-level precision. Learn about the role of agentic AI, geopolitical cyber warfare, and why today's hackers offer better customer support than airlines.

    This segment is sponsored by CyberProof. Visit https://securityweekly.com/cyberproofbh to learn more about them!

    Doug White and Mickey Bresman, CEO of Semperis, dive deep into a conversation on the evolution of ransomware and the alarming rise of cyber extortion tactics. From the early days of encryption-only attacks to today's ransomware-as-a-service operations and hybrid threats blending digital and physical intimidation, this interview unpacks the growing sophistication of organized cybercrime. Mickey shares firsthand insights from Semperis' recent ransomware report, including a chilling real-world example where a photo of a child was used to threaten an IT professional — illustrating how far threat actors are willing to go.

    This segment is sponsored by Semperis. Visit https://securityweekly.com/semperisbh to download the 2025 Global Ransomware Report!

    Matt Alderman sits down with J.J. Guy, CEO & Co-Founder of Sevco Security, to unpack a 20-year industry failure finally being addressed: the disconnect between asset inventory, vulnerability visibility, and true cyber risk understanding. From the roots of CASM (Cyber Asset Attack Surface Management) to the convergence with CTE (Continuous Threat Exposure), JJ shares how Sevco is tackling today's fragmented environments — spanning cloud, on-prem, mobile, and containers — with a data-first approach.

    Would you like to see the Sevco platform in action? You can take a self-guided tour at https://securityweekly.com/sevcobh

    Doug White sits down with Intel 471 CEO Jason Passwaters for an eye-opening conversation on how cybercrime has evolved into a professional, profit-driven ecosystem. From ransomware-as-a-service to agentic AI, this interview pulls back the curtain on the real-world intel enterprises need to defend against today's most dangerous digital threats. Jason shares how threat actors are using business models that rival legitimate startups — complete with support teams and customer service — while enterprise security teams face shrinking budgets and expanding attack surfaces.

    This segment is sponsored by Intel471. Visit https://securityweekly.com/intel471bh to learn more about them!

    CyberRisk TV sits down with HD Moore, CEO & Co-Founder of runZero, for a conversation on why vulnerability management is still failing enterprises — and what needs to change now. This interview dives deep into the real-world challenges facing security teams today: tool overload, missing assets, unauthenticated exposures, and the illusion of visibility. HD reveals how attackers are exploiting blind spots faster than defenders can react — and why unauthenticated discovery is the secret weapon defenders need.

    Try runZero free! Get started at https://securityweekly.com/runzerobh

    Jackie McGuire sits down with Jawahar Sivasankaran, President at Cyware, for an unmissable deep dive into the future of Cyber Threat Intelligence (CTI), agentic AI, and open-source security innovation. With nearly three decades of experience spanning hands-on engineering, go-to-market leadership, and cutting-edge product strategy, Jawahar shares insider insights on how CTI is evolving from fragmented alerts to unified, automated threat intelligence platforms.

    To explore Cyware's new Intelligence Suite, CTI automation capabilities, and open-source AI integration protocol, visit https://securityweekly.com/cywarebh.

    Show Notes: https://securityweekly.com/esw-423

    2 hr 7 min
  • Dave Lewis talks M&A due diligence, TBD topic, the weekly news - Dave Lewis - ESW #422
    Interview with Dave Lewis on Security's Role in M&A Due Diligence

    In this episode, Dave Lewis from 1Password discusses the critical importance of security in mergers and acquisitions, from due diligence through integration. He explores common pitfalls, essential security assessments, and practical strategies for security leaders to protect organizational value throughout the M&A process.

    Topic: The Challenge of Breach Transparency

    Every industry concerned with safety has a process for publishing the details of accidents, incidents, and failures. Cybersecurity has yet to reach this milestone, and hiding the details of failures is holding us back. This talk will argue for the need for breach details to go public, and share strategies for finding and using some little-known sources of detailed breach data.

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. A funding, a few acquisitions, and an IPO for the first time in forever!
    2. Attackers are really actually starting to use AI now
    3. Some researcher spent all of August poking holes in all the AI tools
    4. Someone got Microsoft Copilot to be an accomplice in a coverup
    5. Microsoft is making a big change in Azure that will probably break some stuff
    6. No, Flipper Zero can't help you steal your car (just the stuff in it)
    7. Domain names are free to register now, maybe?
    8. Disgruntled former employee goes to jail
    9. AI tricked into doing more bad things

    All that and more, on this episode of Enterprise Security Weekly.

    This segment is sponsored by 1Password. Visit https://securityweekly.com/1password to learn more about them!

    Show Notes: https://securityweekly.com/esw-422

    1 hr 47 min
  • Oktane Preview with Harish Peri, Invisible Prompt Attacks, and the weekly news! - Harish Peri - ESW #421
    Interview with Harish Peri from Okta

    Oktane Preview: building frameworks to secure our Agentic AI future

    Like it or not, Agentic AI and protocols like MCP and A2A are getting pushed as the glue to take business process automation to the next level. Giving agents the power and access they need to accomplish these lofty goals is going to be challenging, from a security perspective.

    How do put AI agents in the position to perform broad tasks autonomously without granting them all the privileges? How do we avoid making AI agents a gold mine for attackers - the first place they stop once they hack into our companies? These are some examples of the questions Okta aims to answer at this year's Oktane event, and we aim to kick off the conversations a little early - with this interview!

    Segment Resources:

    • Check out securityweekly.com/oktane for all our live coverage during the event this year!
    • More information about the event and how you can attend can be found here: https://www.okta.com/oktane/
    • AI at Work 2025: Securing the AI-powered workforce
    Topic - Indirect Prompt Injection Getting Out of Hand

    Reports of indirect prompt injection issues have been around for a while. Of particular note was Michael Bargury's Living off Microsoft Copilot presentation from Black Hat USA 2024. Simply sending an email to a Copilot user could make bad stuff happen.

    Now, at Black Hat 2025, we've got more: the ability to plunder any data resource connected to ChatGPT (they call these integrations "Connectors") from Tamir Ishay Sharbat at Zenity Labs. The research is titled AgentFlayer: ChatGPT Connectors 0click Attack.

    Looks like Google Jules is also vulnerable to what the Embrace the Red blog is calling invisible prompts. Sourcegraph's Amp Code is also vulnerable to the same attack, which encodes instructions to make them invisible.

    What's really going to ruffle feathers is the fact that all these companies know this stuff is possible, but don't seem to be able to figure out how to prevent it. Ideally, we'd want to be able to distinguish between intended instruction and instructions injected via attachments or some other means outside of the prompt box. I guess that's easier said than done?

    News

    Finally, in the enterprise security news,

    1. Drones are coming for you… to help?
    2. One of the most powerful botnets ever goes down
    3. Phishing training is still pointless
    4. Microsoft sets an alarm on its phone for 8 years from now to do post-quantum stuff
    5. vulns galore in commercial ZTNA apps
    6. GenAI projects are struggling to make it to production
    7. Adblockers could be made illegal - in Germany
    8. Windows is getting native Agentic support
    9. Automating bug discovery AND remediation?
    10. Public service announcement: time is running out for Windows 10

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-421

    1 hr 50 min
  • Rethinking risk based vulnerability management, Black Hat expo insights, and the news - Snehal Antani - ESW #420
    Interview with Snehal Antani - Rethinking Risk-Based Vulnerability Management

    Vulnerability management is broken. Organizations basically use math to turn a crappy list into a slightly less crappy list, and the hardest part of the job as a CIO is deciding what NOT to fix. There has to be a better way, and there is...

    Segment Resources:

    • https://horizon3.ai/intelligence/blogs/vulnerability-management-is-broken-there-is-a-better-way/

    This segment is sponsored by Horizon3.ai. Visit https://securityweekly.com/horizon3 to learn more about them!

    Topic - Andy Ellis's Black Hat Expo Experience

    Andy Ellis visited every booth at Black Hat. Every. Single. One. He wrote up what he learned and we discuss his findings!

    https://www.duha.co/state-of-security-vendors-blackhat-2025/

    News

    Finally, in the enterprise security news,

    1. Tons of handy new and free tools!
    2. is cybersecurity really at the latter stages of consolidation?
    3. new books
    4. is our obsession with risk quantification hurting our credibility?
    5. AI trends
    6. is there an impending AI layoff-pocalypse?
    7. we explain the kids' favorite new term: Clanker

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-420

    1 hr 56 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…