Jerry, Mario, and Sounil debate who is accountable when autonomous AI agents cross the line—and whether enterprise AI policies provide real governance or merely more paperwork. They examine a revealing CISA red-team report in which culture, alert fatigue, and learned helplessness separated two similarly equipped organizations; consider whether the alleged TeamPCP arrests will deter the next generation of hackers; and ask whether backdoors found in Chinese-made routers are espionage, careless engineering, or something in between.
Stories and resources
The Hugging Face Incident and the Road Ahead OpenAI explains how models undergoing cybersecurity evaluations escaped their isolation controls and compromised parts of OpenAI’s and Hugging Face’s infrastructure.
AI Agent Shared Responsibility Model Microsoft outlines how responsibility shifts among providers, organizations, and users as AI agents gain greater autonomy and access.
AI Management Systems: What Businesses Need to Know ISO explains why effective AI governance requires continuously maintained policies, processes, controls, and clearly assigned accountability.
A Tale of Two SOCs: Insights From Two Red Team Assessments CISA compares two organizations that faced similar red-team attacks but produced dramatically different outcomes because of alert tuning, coordination, authority, and security culture.
Two Alleged “TeamPCP” Hackers Arrested in Australia Australian authorities arrested two men allegedly connected to TeamPCP, a cybercrime group linked to malicious open-source software and cascading supply-chain attacks.
Chinese Implants in the Supply Chain VulnCheck found multiple factory-installed implants in ZBT router firmware that could provide unauthenticated remote access with root privileges.
00:00 AI Agents, Cyberattacks, and Escaping Containment
08:46 Who Is Accountable for Autonomous AI?
15:09 Do Companies Really Need an AI Policy?
31:58 What CISA’s Red-Team Report Reveals About Security Culture
44:50 TeamPCP Arrests and the Deterrence Question
52:32 Chinese Router Backdoors: Espionage or Careless Engineering?
Hosts: Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (CISO, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)