
Sign up to save your podcasts
Or


Based on Podcast App listening data
Exaforce's Chief Security Evangelist, Aqsa, joins us to discuss the current state of the AI SOC and why it covers so much more than it did over 2 years ago, when our podcast first started covering this market. Exaforce also recently released AI Security and its ExaGo mobile app - we're very excited about the possibility of analyzing incidents at the grocery store!
This segment is sponsored by Exaforce. Visit https://securityweekly.com/exaforce to learn more about them!
Topic Segment - Regulating AIThe AI industry's sandbox escapes have had a big impact on everyone and unsurprisingly, there's a bill proposing to ban some AI products and pause the development of others.
It seems that, increasingly, as pro-AI and anti-AI groups become more polarized and divided, you could start an entire podcast that does nothing but fact-check both sides. We're an emotional species and it seems the more heated debate gets, the more folks on both sides are willing to straight-up fabricate things to help argue their points.
Today's focus is this YouTube video: https://www.youtube.com/watch?v=WXsTCJl7sU4
It's the most on-the-nose type of propaganda - straight up claiming the government is going to break into your house and take your GPUs and LLMs. Could the bill proposed by Bernie Sanders and Greg Casar be characterized as extreme? Sure, but it's nowhere near as extreme as the title of the video, "They're Banning AI Servers at Home" suggests.
The hardest things to swallow about the video:
Finally, in the enterprise security news,
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-479
RAM, Muse, CloudSyncD, Springsteen, Who Owns Your Software?, Persistence, Michael Jenkins, CTO of ThreatLocker, and More on this episode of the Security Weekly News.
Segment Resources: https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-621
First up we talk with Threatlocker CTO Michael Jenkins about threat actors use of AI and keeping the bad things out with Zero Trust. Then in the security news:
The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
Visit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-946
At a time when the traditional approach to enterprise vulnerability management is no longer effective, security leaders are turning to AI agents to help identify, validate, and contain zero-day threats. Learn how Google Cloud Security is building autonomous detection engineering to help your organization close the remediation gap, establish compensating controls to protect business assets, and outpace AI-powered adversaries.
Segment Resources:
https://services.google.com/fh/files/misc/monitoringandstoppingaipowered_threats.pdf https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents?e=48754805
This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlecloud to learn more about them!
In the leadership and communications segment, CISOs can no longer ignore the nation-state threat, AI Policies Won't Save You If You Can't See The Risk, The Invisible Work Draining Your Best Employees , and more!
Visit https://www.securityweekly.com/bsw for all the latest episodes!
Show Notes: https://securityweekly.com/bsw-467
Venus in Furs, Money Laundering, Agentic AI Hijinx, MCP, Thunderbastard, Aaran Leyland, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-620
Finding flaws with LLMs and agents is changing bug bounty programs. But it's not necessarily changing how orgs fix those flaws. Shlomie Liberow shares his experience across a decade of bounty programs and how they have changed for researchers and orgs. He explains why fixing the bug reported through a bug bounty is more about understanding interconnected systems than fixing a single piece of software. We discuss how orgs can be more effective at securing their environment and what role LLMs might have in evaluating controls. Plus, we look to the future of bug bounty programs and how researchers can still excel through curiosity and expertise on a topic rather than relying on scanners, prompts, and luck.
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-402
This week, we talk to Chris Crawley about his new book, The Value of Cybersecurity Operations. Chris has been training teams on security operations for years, but found that students often struggled to justify the importance of secops training and even the need for secops in general. This book was written to more broadly arm practitioners with the information they need to communicate why security operations are necessary to leadership.
The book is available in several forms: eBook, hardcover, softcover, and an audiobook read by Chris himself!
You can pick all versions up here: https://shop.montance.com/collections/all and Security Weekly listeners get 50% off with code sw-50!
The Evolving Exploitation of Trust with Josh Davies, Security Strategist at FortraFortra Intelligence and Research Experts (FIRE) is Fortra's emergent threat intelligence identity, created to unify research teams across multiple security disciplines and share intelligence with the wider threat intelligence community. FIRE co-ordinator and security strategist Josh Davies joins us to share insights from original FIRE research like Calphishing, Mirage2FA, RatPressto phishkit and heavily obfuscated campaigns that evade defences. While also digging into trends from big data analysis within phishing, fraud, social engineering and credential theft.
Segment Resources:
This segment is sponsored by Fortra. Access FIRE Research here: https://securityweekly.com/fortrabh
Why Agentic AI Security Requires a Defense-In-Depth Strategy with Kaushik Shanadi, CTO and Co-Founder of Helmet SecurityMany organizations are approaching agentic AI security by stitching together individual controls, assuming that identity, network, endpoint, or application security alone is enough. Each address only one part of the problem. As AI agents become more autonomous, move across systems, and take actions on behalf of users, organizations need a true defense-in-depth strategy that combines every layer of the security stack. Kaushik can discuss how each security layer provides a different piece of the puzzle and how individually, none of the controls are sufficient. But together, they create the layered governance needed to securely deploy agentic AI.
For more information about Helmet Security, please visit https://securityweekly.com/helmetbh
Above Security on Why Legacy Tools Don’t Cut It for Modern Insider Risk with Tricia Howard, Head of Marketing at Above SecurityAs organizations rush to adopt agentic AI, agents are often given broad access to critical business systems and sensitive data. Legacy insider risk management tools weren't built for this, and organizations have spent years on insider risk posturing and investments that leave security teams inundated with false positives while the real risk slips through undetected. In this segment, Tricia Howard draws on her decade in cybersecurity, including years watching user and entity behavior analytics (UEBA) overpromise and underdeliver, to unpack why understanding human – and now AI – intent is the missing piece.
Segment Resources:
To learn more about Above Security and insider risk management in the era of agentic AI, visit: https://securityweekly.com/abovebh
The Identity Crisis Your Security Team Didn't See Coming: Governing AI Agents with Darren Guccione, CEO and Co-Founder of Keeper SecurityAI agents outnumber human identities in enterprise environments, and traditional security software was never built to govern them. 89% of cybersecurity decision-makers recently surveyed by Keeper Security said that AI adoption has made identity management harder.
In this Black Hat USA conversation with Cyber Risk TV, Darren Guccione, CEO and Co-Founder of Keeper Security, shares a practical framework for extending identity governance to non-human identities and AI agents before the access gap becomes a breach.
Segment Resources:
To learn more about Keeper Security, visit: https://securityweekly.com/keeperbh
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-478
Ear mite butterfly effects, Chuds, Agentic AI galore, CISA, Shiny Hunters, FreeBSD, Ghost Accounts, Pervs, Josh Marpet, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-619
In the security news this week:
Visit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-945
As businesses race to embrace AI, security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. How do you balance the benefits of AI with the Risks of AI?
Evan McHenry, Chief Information Security Officer at Robinhood Markets, joins Business Security Weekly to discuss how to practically implement and secure AI in the enterprise. Evan will share his lessons learned over the last 18 months, including how to communicate with the Board, why you should own Enterprise Architecture and embrace IT, and why you don't have time to argue with your CFO. If you're struggling to balance the benefits of AI with the Risks of AI, this interview is for you.
In the leadership and communications segment, Security spending is growing — except for the typical CISO, What Leaders Need to Know About AI and Psychological Safety, The Cyber Gap, and more!
Visit https://www.securityweekly.com/bsw for all the latest episodes!
Show Notes: https://securityweekly.com/bsw-466
From the publisher's feed
Ranked by our users in the last 21 days

32,056 Listeners

30,692 Listeners

7,626 Listeners

193 Listeners

2,012 Listeners

504 Listeners

375 Listeners

653 Listeners

1,029 Listeners

17 Listeners

421 Listeners

8,062 Listeners

960 Listeners

180 Listeners

138 Listeners