Safe Mode Podcast

Safe Mode Podcast

Podcast by Safe Mode Podcast

  1. 14h ago

    The SOC wasn't built for this

    Security operations centers have run on the same playbook for decades — collect, queue, triage, investigate, escalate. But attackers now move at machine speed: one recent breach that cost a company 3,600 repos got underway in roughly 87 seconds, far outpacing even a fast 10-minute log-enrichment pipeline. This week, host Greg Otto talks with ExtraHop CEO Greg Clark about the newly announced Agentic SOC Alliance and why he believes traditional SOC architecture can't keep up. Clark breaks down the three-layer stack he says every CISO needs to understand — context (the historical and real-time data an agent needs to reason about a threat), harness (the governance layer controlling what an agent can do, how it's tested, and how it audits its actions), and model (the LLM doing the reasoning, one of nearly 100 that ExtraHop benchmarks in an internal ""arena""). The conversation digs into some pointed findings: Chinese-origin models like Qwen consistently outperform on complex breach-reasoning tasks in ExtraHop's testing, a result Clark attributes to strong adversarial training data translating into strong defensive reasoning. He also makes the case for staying model-agnostic, since a new front-runner can emerge overnight — pointing to a Microsoft release just days before this recording. Much of the discussion centers on where humans still fit in. Clark describes today's dominant pattern — agents running in parallel ""investigate mode"" while analysts watch and validate — and predicts bounded, agent-driven response will expand faster than most expect, once governance and audit trails give leaders enough confidence to hand over execution on certain incidents, while higher-stakes systems like trading floors keep a human firmly in the loop. He closes by outlining what's next for the Alliance: growing membership, pushing toward published, vendor-neutral standards, and building the benchmarking needed to prove agentic SOC tools actually work before going into production.

    The SOC wasn't built for this
  2. Jul 23

    A builder's view of the AI arms race

    It's been a wild six weeks for frontier AI models — Mythos launched, got yanked offline by the Department of Commerce over export controls, and came back online with new guardrails, all while Five Eyes agencies warned that AI is months away from reshaping the threat landscape. This week on Safe Mode, Greg Otto talks with Armadin's David Slater, who is building directly on top of these frontier models, creating a platform integrating AI into cybersecurity offense and defense. The two dig into what it was actually like watching America's leading models go dark just as Chinese models — namely GLM 5.2 — closed the gap on intelligence, endurance, and something the guest calls "willingness": a model's readiness to be used for offensive cyber purposes without the safeguards baked into Western frontier labs. The conversation covers why export controls and "kill switches" on U.S. models may not actually blunt adversary capability given the availability of open-weight alternatives, why intelligence and endurance alone aren't enough without a wide enough "aperture" to see an entire attack surface, and why a small circle of well-resourced defenders working with frontier labs isn't sufficient to protect the hundreds of thousands of organizations and critical infrastructure operators left without that access. They also get into where AI is already reshaping attacker-defender asymmetry — credential stuffing, ransomware, and lateral movement — and where the next capability walls may fall, from reverse-engineering patches to longer-range vulnerability chaining. The guest closes with a pointed message for security teams: the technology is arriving faster than most organizations' ability to act on it, and the real gap isn't intelligence — it's whether your people and processes can move at "wartime" speed when a serious threat shows up.

    A builder's view of the AI arms race
  3. Jun 18

    Zero days, zero order: The chaos reshaping vulnerability disclosure

    The rules of responsible disclosure were written for a different era — one where humans found bugs, humans reported them, and 90 days felt like plenty of time to patch. That era is over. In this episode, Greg sits down with Gal Elbaz, co-founder and CTO of Oligo Security, to unpack how AI-assisted vulnerability research is breaking the frameworks the security industry has relied on for decades. From MITRE admitting it can no longer keep up with the volume of CVE reports, to Linus Torvalds saying the same about the Linux kernel, the cracks in the system are impossible to ignore. Gal draws on his years as a hands-on researcher at Check Point — and his current work leading Oligo's research team — to offer perspective from both sides of the disclosure table. He and Greg dig into the Microsoft controversy, the tension between researcher leverage and community responsibility, and why the Spider-Man rule applies more than ever to the security research community right now. They also tackle the big questions: Should disclosure timelines be based on exploitability rather than a fixed number of days? Who owns the decision to accelerate a disclosure? And is it time to throw out CVSS scores and build something new? Gal's bottom line: the noise needs to be cut, the critical bugs need better definition, and both vendors and researchers need to get back to the table — as humans. For our reporter chat, Greg talked with Derek Johnson about the reaction to the Trump administration's fight with Anthropic.

    Zero days, zero order: The chaos reshaping vulnerability disclosure

Ratings & Reviews

4.9
out of 5
8 Ratings

About

Podcast by Safe Mode Podcast

You Might Also Like