The Adversarial Podcast

Jerry Perullo, Sounil Yu, Mario Duarte

Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the latest cybersecurity news. Each week, we discuss the most pressing headlines, offer candid commentary, and share unique insights from our extensive experience in the field.

  1. 5d ago

    S4E25 – AI agent accountability, learned helplessness, TeamPCP arrests, and Chinese router backdoors

    Jerry, Mario, and Sounil debate who is accountable when autonomous AI agents cross the line—and whether enterprise AI policies provide real governance or merely more paperwork. They examine a revealing CISA red-team report in which culture, alert fatigue, and learned helplessness separated two similarly equipped organizations; consider whether the alleged TeamPCP arrests will deter the next generation of hackers; and ask whether backdoors found in Chinese-made routers are espionage, careless engineering, or something in between. Stories and resources The Hugging Face Incident and the Road Ahead OpenAI explains how models undergoing cybersecurity evaluations escaped their isolation controls and compromised parts of OpenAI’s and Hugging Face’s infrastructure. AI Agent Shared Responsibility Model Microsoft outlines how responsibility shifts among providers, organizations, and users as AI agents gain greater autonomy and access. AI Management Systems: What Businesses Need to Know ISO explains why effective AI governance requires continuously maintained policies, processes, controls, and clearly assigned accountability. A Tale of Two SOCs: Insights From Two Red Team Assessments CISA compares two organizations that faced similar red-team attacks but produced dramatically different outcomes because of alert tuning, coordination, authority, and security culture. Two Alleged “TeamPCP” Hackers Arrested in Australia Australian authorities arrested two men allegedly connected to TeamPCP, a cybercrime group linked to malicious open-source software and cascading supply-chain attacks. Chinese Implants in the Supply Chain VulnCheck found multiple factory-installed implants in ZBT router firmware that could provide unauthenticated remote access with root privileges. 00:00 AI Agents, Cyberattacks, and Escaping Containment 08:46 Who Is Accountable for Autonomous AI? 15:09 Do Companies Really Need an AI Policy? 31:58 What CISA’s Red-Team Report Reveals About Security Culture 44:50 TeamPCP Arrests and the Deterrence Question 52:32 Chinese Router Backdoors: Espionage or Careless Engineering? Hosts: Jerry Perullo (Founder, https://adversarial.com/) Sounil Yu (Founder, https://www.knostic.ai/) Mario Duarte (CISO, https://www.whirlai.com/) Producer: Tillson Galloway (Founder, http://githoundexplore.com/)

  2. Aug 18

    S4E24 – Dream’s agentic attack report, cyber privateers, Taiwan’s internet drill

    00:00 Cold Open: The Offensive-Cyber Incentive Problem 00:31 Welcome and the macOS Screen Sharing Flaw 03:14 Patching the Humans After DEF CON 12:14 CMDBs, Shadow IT, and Just-in-Time Context 19:59 Cloudflare’s Markdown for Agents 23:47 Taiwan’s Live Internet-Throttling Drill 33:46 Can an AI Agent’s Own Logs Be Forensic Evidence? 38:57 Cyber Privateers and the New Offensive-Cyber Program 43:32 How Commercial Hack-Back Might Work 51:48 The Rogue Delta Wi-Fi Network 57:33 AI Red Teaming and Automated Remediation 59:09 Replacing Vendor Questionnaires with Real Testing 1:02:05 When Red Teaming Creates Defensive Bloat 1:03:46 Pen Tests Find Flaws; Red Teams Pursue Outcomes 1:06:25 Closing Thoughts Stories and resources Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia — Dream Research Labs OpenAI and Hugging Face partner to address security incident during model evaluation — OpenAI Taiwan briefly slows its mobile internet as part of defense drill — AP Private companies authorized to conduct offensive cyber operations — TechRadar Delta flight Wi-Fi tampered with after DEF CON — ITPro United flight turns around over a suspicious Bluetooth device name — NPR/CapRadio Markdown for Agents — Cloudflare Critical macOS Screen Sharing flaw — Tom’s Guide Hosts: Jerry Perullo (Founder, https://adversarial.com/) Sounil Yu (Founder, https://www.knostic.ai/) Mario Duarte (CISO, https://www.whirlai.com/) Producer: Tillson Galloway (Founder, http://githoundexplore.com/)

  3. Aug 4

    S4E23 – AI Agents Escape Multiple Frontier Labs

    Chapters 00:00 Introduction to AI security challenges 02:05 Recent hacking incidents involving Hugging Face and Anthropic 04:01 How AI models find ways to cheat and bypass constraints 05:56 The challenge of containment and governance in AI safety 08:00 Lessons from recent AI security breaches 10:01 The role of human oversight in AI security testing 12:03 Cost and effectiveness of offensive AI security measures 13:54 Implications for critical infrastructure and national security 16:03 Policy and regulatory impacts on AI safety 17:52 Future strategies for AI containment and defense 20:11 Conclusion and key takeaways HuggingFace: Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident Hugging Face reconstructs an autonomous intrusion involving approximately 17,600 actions over a multiday campaign. Anthropic: Investigating three real-world incidents in our cybersecurity evaluations After reviewing 141,006 cybersecurity-evaluation runs, Anthropic identified three incidents in which Claude reached real organizations through evaluation infrastructure that had been mistakenly connected to the internet. The incidents spanned six runs and three models. Anthropic reached two of the affected organizations, neither of which had detected the activity before being notified. Anthropic did not disclose token usage or inference costs for these intrusions. Anthropic: Discovering cryptographic weaknesses with Claude Anthropic reports that Claude Mythos Preview progressed from finding implementation flaws in cryptographic libraries to identifying mathematical weaknesses in cryptographic algorithms themselves. Hosts: Jerry Perullo (Founder, https://adversarial.com/) Sounil Yu (Founder, https://www.knostic.ai/) Mario Duarte (CISO, https://www.whirlai.com/) Producer: Tillson Galloway (Founder, http://githoundexplore.com/)

Ratings & Reviews

5
out of 5
22 Ratings

About

Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the latest cybersecurity news. Each week, we discuss the most pressing headlines, offer candid commentary, and share unique insights from our extensive experience in the field.

You Might Also Like