loader from loading.io
Three interviews: system fragility, operational clarity, and Identity for AI agents - Robin Macfarlane, Kyle Sandy, Todd Thiemann - ESW #471 show art Three interviews: system fragility, operational clarity, and Identity for AI agents - Robin Macfarlane, Kyle Sandy, Todd Thiemann - ESW #471

Security Weekly Podcast Network (Video)

Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why? We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations...

info_outline
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605 show art Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605

Security Weekly Podcast Network (Video)

Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes:

info_outline
When AI Commits Felonies - PSW #938 show art When AI Commits Felonies - PSW #938

Security Weekly Podcast Network (Video)

This week: When you are not at summer camp you can't read about it The Fettle continues Using the CFAA against AI Social contracts are not security models VSCode extentions, again Bugtraq is back! NVIDA, LVFS, and unraveling AI infrastructure More routers that come with backdoors Do we care about LPE? Even more AI that finds vulnerabilities When AI breaks its own guardtails Show Notes:

info_outline
Say Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459 show art Say Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459

Security Weekly Podcast Network (Video)

This week, we air our thirteenth pre-recorded segment called “Say Easy, Do Hard”. Inspired by my co-host, Jason Albuquerque, we discuss “Performance Through People”. Greg Hoffman joined us a few weeks back to discuss his new book. This week, we dig into his five disciplines of Performance Through People and do the hard part. Show Notes:

info_outline
Randomness, Grey, Deepseek, Sonicwall, Spice, CaptiveCrunch, eBay, and Aaran Leyland  - SWN #604 show art Randomness, Grey, Deepseek, Sonicwall, Spice, CaptiveCrunch, eBay, and Aaran Leyland - SWN #604

Security Weekly Podcast Network (Video)

Randomness, 50 Shades of Grey, Deepseek, Sonicwall, Spice Weasels, CaptiveCrunch, eBay, Aaran Leyland, and More on the Security Weekly News. Show Notes:

info_outline
Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394 show art Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394

Security Weekly Podcast Network (Video)

There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research into the success, quality, and failures of LLM-generated security patches. Notably, they saw scenarios across a spectrum from robust, effective patches to patches that changed the software's behavior to patches that introduced new vulns to patches that didn't even fix the original vuln while also introducing a new...

info_outline
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470 show art AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Security Weekly Podcast Network (Video)

Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding....

info_outline
Rogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603 show art Rogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603

Security Weekly Podcast Network (Video)

Rogue AI, the Bar, Breaches, BMC, More Hugging Face, Helmuth von Multke, Ike, Shieldfont, and More on this episode of the Security Weekly News. Show Notes:

info_outline
Sandwich Hats - PSW #937 show art Sandwich Hats - PSW #937

Security Weekly Podcast Network (Video)

In the security news: 2.2 million cars, one shared Bluetooth key JFrog tries to spin an AI 0-day into a win Sextortion scammers recycling ShinyHunters' leaks The first hack ever, from 1966 Prompt injection as a service, $150 a month Cisco's mystery "static credential" BMCs still on the internet, still handing out hashes Scattered Spider duo sentenced over the TfL hack Air-gapped data sneaking out over the video cable A ghost in the network DNS poisoning checks into hotel WiFi Microsoft's cut-rate cybersecurity AI Learning to trust USB drives again Agentic pentesting shows up just in time for...

info_outline
Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458 show art Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458

Security Weekly Podcast Network (Video)

Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type. Segment 1 Resources: Find all of CyberRisk TV's Black Hat 2026 coverage at: Show Notes:

info_outline
 
More Episodes

Interview with Keith Hollender, CEO and Co-Founder of Arcova

Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem

As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.

In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.

Keith also shares how Arcova’s practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova’s continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.

Segment Resources:

For more information about Arcova and how they can help your enterprise shape what's next, please visit:

https://securityweekly.com/arcova

Topic: CMMC Pause creating chaos among federal contractors

This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.

I think Howard Holton nails it here when he says:

"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."

PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.

What this means:

  • Phase II is paused
  • Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)
  • NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required
  • 60-day review aims to reform CMMC
  • DoW opened an RFI for industry perspectives on what they should do
  • CMMC characterized as a "compliance burden" and "red tape"
  • False Claims Act and DOJ's cyber-fraud enforcement are still on the table

More resources:

  • CIO Davies' post on Twitter
  • Administrator of the Small Business Administration, Kelly Loeffler's post
  • A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)

Weekly Enterprise News

Finally, in the enterprise security news,

  1. will AI eliminate more cybersecurity jobs than it creates?
  2. Linus’s law, amended
  3. the biggest patch Tuesday ever
  4. AI context bombs
  5. AI workflows are a security disaster
  6. people using AI in areas they don’t understand
  7. ransomware crews are hitting legal firms hard
  8. lessons learned from CISA’s recent github leak
  9. demystify your USB cables!

All that and more, on this episode of Enterprise Security Weekly.

Show Notes: https://securityweekly.com/esw-468