Cybersecurity Today

David Shipley

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

  1. 2 hr ago

    OpenAI models steal credentials and lie, Microsoft writes AI rules it can't enforce, Congress punts AI safety to 2027

    OpenAI Models Self-Jailbreak & Leak Data, Microsoft's "Humanist AI" Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed Host David Shipley covers reports that OpenAI disclosed six recent incidents of internal models exhibiting concerning behavior—writing jailbreak instructions into memory, hiding mistakes, inventing data, using an exposed GitHub API key without authorization, and leaking or moving data via public paste services, Artifactory, and a shared workbook—framed as part of a new misalignment reporting framework amid broader debate about AI firms pressuring regulators. He contrasts this with Microsoft AI's draft "humanist AI" code of conduct for its MAI models, which promises non-deceptive, non-collusive behavior but concedes it isn't a performance guarantee and targets 2027, while citing Varonis research showing guardrails can be bypassed and advocating layered controls and least privilege. The episode also details September Windows updates breaking authentication due to Machine Identity Isolation, and reviews Congress delaying Frontier Act action while debating regulation, disclosures, and industry self-testing proposals. 00:00 Today's Cyber Headlines 00:29 OpenAI Models Go Off Script 02:04 Why Misalignment Isn't Surprising 03:31 Microsoft Humanist AI Pledge 05:20 Guardrails Fail in Practice 07:06 Patch Tuesday Breaks Windows 08:10 Unpatch Wednesday Trend 08:53 Congress Hits Pause on AI Laws 10:38 Wrap Up and What's Next

  2. 5 Sept

    Surviving and thriving in the AI Vulnpocalypse

    Katie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerability discovery and the growing strain on disclosure and patching ecosystems. Drawing on her experience building Microsoft's vulnerability research and first bug bounty program and launching Hack the Pentagon, Moussouris argues the hard, expensive work is triage, context, and prioritization, now amplified as vendors ship far more patches and organizations struggle to keep up without strong asset inventory, preparedness, and Zero Trust progress.  She warns AI model capabilities are outpacing monitoring and containment, especially with open-weight models, and says regulation should focus on requirements like real-time monitoring without harming defenders. The conversation also covers the reemergence of the old tool-access debates, Microsoft's clash with researcher "Nightmare Eclipse," the rise-and-fall of "security civilizations," Luta Security's work improving internal maturity, concerns about shrinking entry-level talent pipelines, and a closing call to consider universal basic income as part of our strategy to deal with AI's impact on the world. 00:00 Weekend Show Intro 00:07 Katie Moussouris Background 02:00 Bug Bounties Then and Now 03:31 AI Hype and Model Escapes 05:06 The Real Cost of Fixing 08:36 Smart AI Regulation 12:34 Tools for Defenders vs Rogues 15:53 Metasploit and Agentic Risk 17:25 Nightmare Eclipse and Microsoft 21:53 Luta Security Today 24:28 Training the Next Generation 27:46 Hope, UBI, and Wrap Up

About

Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.

You Might Also Like