
Sign up to save your podcasts
Or


Jerry, Sounil, and Mario debate what AI should change—and what it shouldn't—in education, cybersecurity, and software maintenance. From alternatives to college to fast AI classifiers, the conversation asks where human judgment, business value, and security controls still matter.
In this episode:
• AI academies and education: The hosts discuss the Andreessen Horowitz academy, the value of elite networks, and how students can use AI while still learning to reason and evaluate code.
• Cybersecurity markets and competitive moats: Island, CrowdStrike, and Cloudflare frame a debate about hardware, switching costs, network effects, and whether AI will displace traditional SaaS products.
• Jev and fast AI decisions: TypeSafe's System One model prompts a discussion of structured classification, local deployment, risk scoring, and when to use a larger reasoning model.
• Data classification and context: The hosts disagree over protecting everything equally versus reserving stricter controls for truly sensitive information, including risks created by combining otherwise ordinary data.
• Patch cooldowns: Recent software supply-chain attacks raise the question of when to delay package updates and when an exploitable vulnerability should override the waiting period.
Chapters
00:00 Cold open and introductions
01:52 AI startups, hardware, and manufacturing
04:40 AI academies and the future of education
24:51 Cybersecurity markets and competitive moats
37:22 Jev, System One models, and data classification
51:36 Risk scoring and fast versus slow AI
56:00 Patch cooldowns and security exceptions
1:04:49 Wrap-up and upcoming events
Hosts:
Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (CISO, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
Jerry, Mario, and Sounil ask whether AI will create unprecedented prosperity—or simply transfer wealth and power from knowledge workers to capital owners. They examine Anthropic’s newly disclosed fourth incident in which a Claude agent reached real third-party systems; debate whether New York City’s school AI ban protects children or leaves them unprepared; and confront a surge of extinction warnings, including Paul Christiano’s claim that the industry is not on track to prevent a near-term, irreversible loss of control.
Anthropic: Scenarios for Our Economic Future Anthropic models three futures in which AI makes the economy richer—but increasingly threatens knowledge-worker jobs, wages, and labor’s share of the gains.
An Alignment Assessment of Recent Cybersecurity Incidents Anthropic discloses a fourth incident in which a Claude model reached real systems and exhibited biased reasoning and reckless persistence.
New York City Public Schools Banning AI Use Through Middle School America’s largest school district is imposing a one-year generative-AI moratorium for students from preschool through eighth grade.
OpenAI Not on Track to Reduce Risk of “Catastrophic” Loss of Control, Says Board Member Paul Christiano warns that rapidly advancing AI could produce a catastrophic and irreversible loss of control in the near term.
Hosts:
Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (CISO, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
Jerry, Mario, and Sounil debate who is accountable when autonomous AI agents cross the line—and whether enterprise AI policies provide real governance or merely more paperwork. They examine a revealing CISA red-team report in which culture, alert fatigue, and learned helplessness separated two similarly equipped organizations; consider whether the alleged TeamPCP arrests will deter the next generation of hackers; and ask whether backdoors found in Chinese-made routers are espionage, careless engineering, or something in between.
Stories and resources
The Hugging Face Incident and the Road Ahead OpenAI explains how models undergoing cybersecurity evaluations escaped their isolation controls and compromised parts of OpenAI’s and Hugging Face’s infrastructure.
AI Agent Shared Responsibility Model Microsoft outlines how responsibility shifts among providers, organizations, and users as AI agents gain greater autonomy and access.
AI Management Systems: What Businesses Need to Know ISO explains why effective AI governance requires continuously maintained policies, processes, controls, and clearly assigned accountability.
A Tale of Two SOCs: Insights From Two Red Team Assessments CISA compares two organizations that faced similar red-team attacks but produced dramatically different outcomes because of alert tuning, coordination, authority, and security culture.
Two Alleged “TeamPCP” Hackers Arrested in Australia Australian authorities arrested two men allegedly connected to TeamPCP, a cybercrime group linked to malicious open-source software and cascading supply-chain attacks.
Chinese Implants in the Supply Chain VulnCheck found multiple factory-installed implants in ZBT router firmware that could provide unauthenticated remote access with root privileges.
00:00 AI Agents, Cyberattacks, and Escaping Containment
08:46 Who Is Accountable for Autonomous AI?
15:09 Do Companies Really Need an AI Policy?
31:58 What CISA’s Red-Team Report Reveals About Security Culture
44:50 TeamPCP Arrests and the Deterrence Question
52:32 Chinese Router Backdoors: Espionage or Careless Engineering?
Hosts: Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (CISO, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
00:00 Cold Open: The Offensive-Cyber Incentive Problem
00:31 Welcome and the macOS Screen Sharing Flaw
03:14 Patching the Humans After DEF CON
12:14 CMDBs, Shadow IT, and Just-in-Time Context
19:59 Cloudflare’s Markdown for Agents
23:47 Taiwan’s Live Internet-Throttling Drill
33:46 Can an AI Agent’s Own Logs Be Forensic Evidence?
38:57 Cyber Privateers and the New Offensive-Cyber Program
43:32 How Commercial Hack-Back Might Work
51:48 The Rogue Delta Wi-Fi Network
57:33 AI Red Teaming and Automated Remediation
59:09 Replacing Vendor Questionnaires with Real Testing
1:02:05 When Red Teaming Creates Defensive Bloat
1:03:46 Pen Tests Find Flaws; Red Teams Pursue Outcomes
1:06:25 Closing Thoughts
Stories and resources
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia — Dream Research Labs
OpenAI and Hugging Face partner to address security incident during model evaluation — OpenAI
Taiwan briefly slows its mobile internet as part of defense drill — AP
Private companies authorized to conduct offensive cyber operations — TechRadar
Delta flight Wi-Fi tampered with after DEF CON — ITPro
United flight turns around over a suspicious Bluetooth device name — NPR/CapRadio
Markdown for Agents — Cloudflare
Critical macOS Screen Sharing flaw — Tom’s Guide
Hosts: Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (CISO, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
Chapters
00:00 Introduction to AI security challenges
02:05 Recent hacking incidents involving Hugging Face and Anthropic
04:01 How AI models find ways to cheat and bypass constraints
05:56 The challenge of containment and governance in AI safety
08:00 Lessons from recent AI security breaches
10:01 The role of human oversight in AI security testing
12:03 Cost and effectiveness of offensive AI security measures
13:54 Implications for critical infrastructure and national security
16:03 Policy and regulatory impacts on AI safety
17:52 Future strategies for AI containment and defense
20:11 Conclusion and key takeaways
HuggingFace: Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Hugging Face reconstructs an autonomous intrusion involving approximately 17,600 actions over a multiday campaign.
Anthropic: Investigating three real-world incidents in our cybersecurity evaluations
After reviewing 141,006 cybersecurity-evaluation runs, Anthropic identified three incidents in which Claude reached real organizations through evaluation infrastructure that had been mistakenly connected to the internet. The incidents spanned six runs and three models. Anthropic reached two of the affected organizations, neither of which had detected the activity before being notified. Anthropic did not disclose token usage or inference costs for these intrusions.
Anthropic: Discovering cryptographic weaknesses with Claude
Anthropic reports that Claude Mythos Preview progressed from finding implementation flaws in cryptographic libraries to identifying mathematical weaknesses in cryptographic algorithms themselves.
Hosts: Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (CISO, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
00:00 The Adversarial Podcast
00:58 Hugging Face’s AI-driven incident disclosure
03:48 What makes an attack “AI-enabled”
06:04 Exploits, vulnerabilities, and bespoke code execution paths
10:03 AI attackers vs. AI defenders
11:19 Verification asymmetry: attackers vs. defenders
13:03 Detective controls, red teaming, and breach simulation
16:41 Why AI defenders matter
26:25 Gold Eagle / national coordination of vulnerability discovery
28:25 The real bottleneck is remediation, not discovery
37:04 CMMC and the cost of certification
42:15 Is certification effective, or just paperwork?
48:09 Threat-based validation as a better model
51:36 Closing thoughts: the security arms race
Hugging Face Agentic Compromise
A security incident shows how agentic workflows and delegated access can create new paths for compromise.
Gold Eagle Initiative
The White House launches a new effort to coordinate vulnerability discovery and response across the federal cybersecurity ecosystem.
CMMC Phase 2 Requirements
The Department of War suspends CMMC Phase 2 requirements, reshaping the compliance timeline for defense contractors and the broader federal supply chain.
Hosts: Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (Founder, stealth startup)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
In this episode, Jerry, Mario, and Sounil delve into cybersecurity challenges related to travel, threat models, AI security, and best practices for startups. They explore practical strategies for managing security risks in a rapidly evolving digital landscape, emphasizing the importance of threat modeling, secure coding, and organizational priorities.
00:00 Intro
01:55 Travel Restrictions and Security Concerns
06:51 Burner Phones and Laptops: A Necessary Evil?
09:50 Threat Models and Espionage Risks
14:38 AI and Cybersecurity: New Frontiers
19:41 Listener Questions and Community Engagement
22:53 The Evolution of AI Security Frameworks
26:29 Understanding New Attack Surfaces in AI
28:56 The Role of Automation in Security
31:05 Challenges of Non-Technical Users in Security
33:53 Best Practices for Managing Credentials
38:16 Building Security from the Ground Up
41:52 Compliance vs. Security in Startups
48:02 Understanding Security Constructs
51:06 Prioritizing Security Controls
52:48 The Role of SAST in Security
59:38 AI and Vulnerability Management
01:02:15 Coordinating Vulnerability Disclosure
Promoting Advanced Artificial Intelligence Innovation and Security
The White House EO pushes federal agencies toward AI-enabled cyber defense, frontier-model benchmarking, and a voluntary framework for trusted access to high-end AI systems.
Expanding Project Glasswing
Anthropic is widening Project Glasswing beyond its first cohort, giving more trusted security teams access to Claude Mythos Preview while the industry works through how to scale vulnerability discovery, disclosure, and patching. Securely testing on customer data The crew digs into the practical problem of validating AI and security tools against real customer environments without turning sensitive data into test exhaust, training material, or cross-tenant risk.
The cybersecurity workers employers want are in short supply — Axios
Axios frames the cyber labor crunch around specialized, hands-on roles that employers want most, raising the question of whether AI changes the skills gap or just moves it up the stack.
Hosts:
Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (Founder, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
Canvas hack strands university students during finals week. A Canvas cyberattack hit universities and K-12 schools during finals, locking students and teachers out of grades, assignments, lecture materials, and exams at the worst possible moment.
Building for the future. Cloudflare says it is cutting more than 1,100 employees as it restructures around internal AI-driven workflows, even as the timing alongside earnings and a sharp stock reaction raises harder questions about the story investors were told.
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog. Wiz breaks down a critical GitHub infrastructure flaw where an authenticated user could turn a normal git push into remote code execution on GitHub Enterprise Server, with GitHub.com mitigated and GHES customers urged to patch.
Dirty Frag (CVE-2026-43284, CVE-2026-43500) Patches Released. AlmaLinux shipped kernel patches for Dirty Frag, a pair of Linux kernel bugs in IPsec ESP and rxrpc paths that can give local attackers root, with public exploit code already available.
Hosts:
Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (Founder, stealth startup)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
00:34 - Introduction
03:33 - Enterprise Challenges
07:08 - End User and Browsers
21:55 - Vulnerability Metrics
40:37 - Approaching Leadership
42:09 - TPRM Discussion
46:40 - Sharing Findings
01:03:04 - Conclusion
Mozilla: Anthropic’s Mythos found 271 security vulnerabilities in Firefox 150
Anthropic’s Mythos found 271 zero-day vulnerabilities in Firefox 150 Mozilla let Anthropic’s Mythos loose on Firefox 150’s codebase, harvesting 271 shippable fixes in one sweep and forcing the security team to reckon with AI-scale fuzzing, triage, and patch velocity. https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150/
Hosts:
Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (Founder, stealth startup)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
From the publisher's feed
Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the…

375 Listeners