
Sign up to save your podcasts
Or


Based on Podcast App listening data
The Secret Word is Meow, Red Agent, GitHub, evoooo1bot, Hatman, DecryptAds, Copilot, Aaran Leyland, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-608
All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to operators. This type of work is especially useful to orgs that deal with petabytes of data and thousands of systems. And, as Kiran notes, it's important to keep that scale from blowing up your budget or turning triage into a procession of false positives.
Ideally, this kind of threat intel that's paying attention to attack trends and searching internal systems for evidence of compromise also turns into proactive defenses. We talk about some of the ways to engage developers to improve security visibility into their services and harden their designs against common attacks.
After that discussion we're running two sponsored interviews from Black Hat.
AI Pentesting and the Future of Cybersecurity: Black Hat interview with Chris Wallis, Founder and CEO of Intruder
This segment discusses how AI addresses the long-standing gap between traditional pentesting and automated vulnerability scanning. Intruder CEO and founder Chris Wallis dives into the nuances of AI-enabled security and how these offerings will impact mid-market security teams.
Segment Resources:
https://www.intruder.io/platform/ai-pentesting
https://www.intruder.io/blog/ai-pentesting-the-depth-of-a-pentest-on-demand
https://www.intruder.io/blog/ai-web-app-pentesting-test-on-every-major-release
Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. For more information about Intruder’s products and services, please visit https://securityweekly.com/intruderbh.
How Menlo Security Is Securing AI Agents from Prompt Injection: Black Hat Interview with Ramin Farassat, Chief Product Officer of Menlo
Enterprises are deploying AI agents like Microsoft Copilot, Google Gemini, and Claude Code faster than they can secure them, and attackers are exploiting that gap through prompt injection. Hidden instructions get buried in web pages, files, and even images that a human would never notice but an AI agent reads and acts on. Menlo Security is building Menlo Agent Runtime Security (MARS) to close that gap, running every agent session in an isolated cloud that sanitizes content before an agent can act on it. Ramin Farassat, Menlo Security's Chief Product Officer, will discuss why the exposure lives in the connectors and integrations around the model rather than the model itself, and how security teams can put controls on the agent attack surface without blocking agentic AI outright.
Segment Resources:
https://www.menlosecurity.com/product/ai-agent-security
MARS is now available today, please visit https://securityweekly.com/menlobh
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-396
Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user’s chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security.
Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA.
Segment Resources:
This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them!
Topic Segment - AI Notetakers and RecordersAI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss.
Questions enterprises should be asking:
Finally, in the enterprise security news,
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-472
Famous Mathematician feuds, Delta Flight 591, Lazarus, Akira, Computer History, Zoom, Clones, LiteLLM, Josh Marpet, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-607
In the security news this week:
Visit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-939
As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company’s IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem?
Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team’s research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks.
Segment Resources:
How AI Is Reshaping What’s Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory
Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased. Greg Baker will explore how AI can create a continuously updated understanding of both the enterprise security program and the market around it—giving CISOs the context to model scenarios, prioritize investments, and move from insight to action with greater speed and confidence.
For more information about Balance Theory, please visit: https://securityweekly.com/balancetheorybh
The Business Case for Cybersecurity Workforce Resilience - Black Hat Interview with Lynn Dohm, Executive Director of WiCyS
The joint report from WiCyS and FourOne Insights reveals that mentorship, skills-based promotion, and third-party partnerships don’t just improve workforce outcomes — they deliver measurable ROI, including more than $125,000 in savings per employee.
As cybersecurity leaders grapple with persistent talent shortages, AI-driven skill shifts, and demographic headwinds, the report positions workforce resilience as a measurable business advantage — not just an HR initiative.
Segment Resources:
https://www.wicys.org/resources/the-roi-of-resilience/ https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/
This segment is sponsored by Women in CyberSecurity (WiCyS). Visit https://securityweekly.com/wicysbh to learn more about them!
Visit https://www.securityweekly.com/bsw for all the latest episodes!
Show Notes: https://securityweekly.com/bsw-460
Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-606
Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task.
And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts.
Episode Resources:
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-395
The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility
In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why?
We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape.
Interview 2 with Kyle Sandy from LogicallyOperational Clarity as the New Customer Experience
Kyle Sandy joins Adrian to discuss how prioritizing resilience affects how organizations should plan for incident response. In the past, security teams were focused on prevention and limiting breach damage. Today, boards want to know how long it will take to recover operations.
The interview wraps up with a discussion of the right and wrong way to handle a breach and the three most important things every company must get right in order to handle an incident well.
Interview 3 with Todd Thiemann from OmdiaAI Agents and Identity Security: How Enterprises Are Rewriting the Rules
Todd joins ESW with some eye-opening survey insights on the topic of IAM for AI agents. While cybersecurity conversations about internal AI use often revolve around the SOC and security operations, Omdia surveyed identity professionals for a more holistic enterprise perspective.
Unsurprisingly, AI agent use is as diverse as enterprise business units. The surprises are around where the budget comes from for these AI projects, and how authentication is handled.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-471
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-605
From the publisher's feed
Ranked by our users in the last 21 days

32,056 Listeners

30,692 Listeners

7,626 Listeners

193 Listeners

2,012 Listeners

504 Listeners

375 Listeners

653 Listeners

1,029 Listeners

17 Listeners

421 Listeners

8,062 Listeners

960 Listeners

180 Listeners

138 Listeners