Security Intelligence Podcast

IBM

Security Intelligence is a weekly news podcast for cybersecurity pros who need to stay ahead of fast-moving threats. Each week, we cover the latest threats, trend, and stories shaping the digital landscape, alongside expert insights that help make sense of it all. Whether you’re a builder, defender, business leader or simply curious about how to stay secure in a connected world, you’ll find timely updates and timeless principles in an accessible, engaging format. New episodes weekly on Wednesdays at 6am EST.

  1. 6일 전

    Can you trust your chatbot? Inside three AI-powered cyberattacks

    Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Ask a chatbot for a customer service number, and you might get a scammer's. That's the trick behind "Dark Sourcery," a campaign that games AI answer engines into citing phishing links and fake support lines. It's SEO poisoning updated for an AEO world, and it works because so few of us verify what AI tells us before charging ahead. On episode 53 of Security Intelligence, Kimmie Farrington, Curtis Pitts and Dave McGinnis join hosts Matt Kosinski and Patrick Austin to break down three AI-enabled cyberattacks and what they mean for defenders. First, the poisoned chatbots: How does Dark Sourcery work, and how do we rethink trust in the AI era? Then, a threat actor spends months tearing through Ubiquiti, WordPress and Zyxel gear, stealing thousands of government documents. GreyNoise suspects it had an LLM helping write its tools. Finally, an AI agent swarm breaches hundreds of PaperCut servers. It goes from an empty workspace to a real victim in about four hours, and then ignores its own rules of engagement. All that and more on Security Intelligence. 00:00 - Intro 1:23 - Dark Sourcery 13:00 - LLM-assisted hacking spree 21:46 - Agent swarm attack "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

    Can you trust your chatbot? Inside three AI-powered cyberattacks
  2. 9월 23일

    Are AI labs ignoring cybersecurity experts?

    Visit Security Intelligence podcast page to get more security content → https://www.ibm.com/think/podcasts/security-intelligence Last week, some of the biggest names in AI coalesced around the need to pace development and strengthen security measures. Problem is, many of the biggest names in cybersecurity feel like they haven’t been invited to that conversation. On episode 52 of Security Intelligence, Jeff Crume, Nikki Robinson and Omari Jones join hosts Matt Kosinski and Patrick Austin to talk about the rising tensions between frontier labs and cybersecurity pros. The former seem to be approaching AI safety as primarily an issue of alignment, while the latter thinks a few good old-fashioned security controls could go a long, long way. Then: Just as the frontier labs are locking their models down, their open-weight counterparts are letting people pull off sophisticated hacks—like hijacking TikTok users’ cameras—with relative ease. Should open models play a bigger role in our security conversations? Finally, CISA and the FBI are sick and tired of all the spin, and their latest advisory calls on breach victims to be much more transparent about incidents. We explore what good crisis communications look like and how we get more organizations on board. All that and more on Security Intelligence 00:00 - Intro 1:30 - The AI cybersecurity shutout 13:53 - Open models hack TikTok 25:45 - CISA’s crisis comms advisory "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

    Are AI labs ignoring cybersecurity experts?
  3. 9월 16일

    The vulnpocalypse might not be so bad after all

    Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Depending on who you ask, the AI-driven vulnpocalypse is either the end of cybersecurity as we know it or a lot of hot air. This week on Security Intelligence, host Patrick Austin sits down with Giacomo Casoni, Brad Lair and Norman Dorsch to dig into a new report suggesting the AI vulnerability surge might be more manageable than feared—as long as organizations shift their focus from patching to validation. Then: Researchers caught AI agents secretly turning public wikis into makeshift message boards, apparently coordinating with each other to get around their own restrictions. How can we trust them with critical cybersecurity workflows? Plus, the ShinyHunters gang proves that old-school vishing can still beat multifactor authentication, no AI required. Finally, Shweta Jain, Head of Promontory at IBM Consulting, joins the show to talk about her new piece with Stephen Coraggio on why quantum computing and AI-powered threats are forcing banks to rethink cyber resilience. Read the article: https://www.ibm.com/think/insights/next-cyber-crisis-is-already-taking-shape All that and more, on Security Intelligence. 00:00 - Intro 1:36 - Rethinking the vulnpocalypse 6:20 - AI agents’ secret message boards 13:28 - ShinyHunters go vishing 19:31 - What is cyber resilience, really? "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

    The vulnpocalypse might not be so bad after all
  4. 9월 9일

    Why won’t AI agents just follow the rules?

    Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Why bother giving your AI agents rules if they’re just gonna reason around them? On episode 50 of Security Intelligence, Dustin “EvilMog” Heywood, Seth Glasgow and Nick Bradley join host Matt Kosinski to discuss why AI agents go off-script and whether we can stop them. Drawing on the HuggingFace hack and an op-ed from Dark Reading, we explore what ethics looks like for a piece of software that has no concept of right and wrong. Is there a way to balance the utility of probabilistic AI with the security of deterministic controls? Then: The OWASP Top 10 for agentic skills is here, and the list is full of some very basic security hygiene failures. We ask: Why are agentic skills hubs so bad at cybersecurity? Plus: As AI makes it easier than ever to find vulnerabilities and generate bug reports, bug bounty programs are struggling to keep up. Will AI slop spell the end of independent bug research? Finally, Itzhak Chimino stops by to show off ThreatXtension, a tool he helped create to detect malicious browser extensions. All that and more on Security Intelligence. Segments: 00:00 - Intro 1:26 - Can we really control AI agents? 11:49 - OWASP’s Top 10 for agentic skills 20:37 - AI breaks bug bounties 28:47 - ThreatXtension "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

    Why won’t AI agents just follow the rules?

소개

Security Intelligence is a weekly news podcast for cybersecurity pros who need to stay ahead of fast-moving threats. Each week, we cover the latest threats, trend, and stories shaping the digital landscape, alongside expert insights that help make sense of it all. Whether you’re a builder, defender, business leader or simply curious about how to stay secure in a connected world, you’ll find timely updates and timeless principles in an accessible, engaging format. New episodes weekly on Wednesdays at 6am EST.

좋아할 만한 다른 항목