loader from loading.io

Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469

Security Weekly Podcast Network (Audio)

Release Date: 07/27/2026

Preventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461 show art Preventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461

Security Weekly Podcast Network (Audio)

Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in...

info_outline
Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608 show art Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608

Security Weekly Podcast Network (Audio)

The Secret Word is Meow, Red Agent, GitHub, evoooo1bot, Hatman, DecryptAds, Copilot, Aaran Leyland, and More on the Security Weekly News. Visit for all the latest episodes! Show Notes:

info_outline
Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396 show art Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396

Security Weekly Podcast Network (Audio)

All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to operators. This type of work is especially useful to orgs that deal with petabytes of data and thousands of systems. And, as Kiran notes, it's important to keep that scale from blowing up your budget or turning triage into a procession of false positives. Ideally, this kind of threat intel that's paying attention to...

info_outline
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472 show art Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Security Weekly Podcast Network (Audio)

Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user’s chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot...

info_outline
Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More - SWN #607 show art Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More - SWN #607

Security Weekly Podcast Network (Audio)

Famous Mathematician feuds, Delta Flight 591, Lazarus, Akira, Computer History, Zoom, Clones, LiteLLM, Josh Marpet, and More on this episode of the Security Weekly News. Visit for all the latest episodes! Show Notes:

info_outline
The Breached WiFi AI Ports... What? - PSW #939 show art The Breached WiFi AI Ports... What? - PSW #939

Security Weekly Podcast Network (Audio)

In the security news this week: North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale Phishing-resistant MFA Goodbye SMS and voice authentication Cornflake RAT and Chaco Shell The NPM worm Hundreds of compromised packages AI lowers the barrier to mass exploitation Rethinking “secure enough” Back to basics: know what's on your network Get off my PCI lawn Visit for all the latest episodes! Show Notes:

info_outline
Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Greg Baker, Ihab Shraim, Lynn Dohm - BSW #460 show art Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Greg Baker, Ihab Shraim, Lynn Dohm - BSW #460

Security Weekly Podcast Network (Audio)

As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company’s IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team’s research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He...

info_outline
Squirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606 show art Squirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606

Security Weekly Podcast Network (Audio)

Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News. Visit for all the latest episodes! Show Notes:

info_outline
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395 show art Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

Security Weekly Podcast Network (Audio)

Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the...

info_outline
Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471 show art Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471

Security Weekly Podcast Network (Audio)

Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why? We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations...

info_outline
 
More Episodes

Segment 1 - Interview with O'Shea Bowens

What do we really know about "AI Network Protocols"? Network security is about to get popular all over again.

Generative AI caused a disruptive explosion across all of tech and every company’s roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other?

Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O’Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling.

Segment Resources:

  1. https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D
  2. https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/
  3. https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth

Segment 2 - Interview with Jeremiah Grossman

Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years

After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up.

Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat

Segment 3 - Weekly Enterprise News

Finally, in the enterprise security news,

  1. We vibe check the AI model situation
  2. hidden devices in California cars causes concerns
  3. OpenAI’s models escape sandboxes and breaches another AI company, totally by accident, they promise!
  4. Grok Build uploads all your files, totally by accident, they promise!
  5. Eclipsium debuts a firmware version of patch tuesday!
  6. HTTP gets a new method
  7. common problems with incident response
  8. Which one of the security weekly hosts would consider switching to a “dumb phone”?

All that and more, on this episode of Enterprise Security Weekly.

Visit https://www.securityweekly.com/esw for all the latest episodes!

Show Notes: https://securityweekly.com/esw-469