Enterprise Security Weekly (Audio)

Adrian Sanabria

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.

  1. 5d ago

    State of the AI SOC, regulating AI, and can AI agents feel pain? - Aqsa Taylor - ESW #479

    Interview with Aqsa Taylor Exaforce's Chief Security Evangelist, Aqsa, joins us to discuss the current state of the AI SOC and why it covers so much more than it did over 2 years ago, when our podcast first started covering this market. Exaforce also recently released AI Security and its ExaGo mobile app - we're very excited about the possibility of analyzing incidents at the grocery store! This segment is sponsored by Exaforce. Visit https://securityweekly.com/exaforce to learn more about them! Topic Segment - Regulating AI The AI industry's sandbox escapes have had a big impact on everyone and unsurprisingly, there's a bill proposing to ban some AI products and pause the development of others. It seems that, increasingly, as pro-AI and anti-AI groups become more polarized and divided, you could start an entire podcast that does nothing but fact-check both sides. We're an emotional species and it seems the more heated debate gets, the more folks on both sides are willing to straight-up fabricate things to help argue their points. Today's focus is this YouTube video: https://www.youtube.com/watch?v=WXsTCJl7sU4 It's the most on-the-nose type of propaganda - straight up claiming the government is going to break into your house and take your GPUs and LLMs. Could the bill proposed by Bernie Sanders and Greg Casar be characterized as extreme? Sure, but it's nowhere near as extreme as the title of the video, "They're Banning AI Servers at Home" suggests. The hardest things to swallow about the video: it characterizes Bernie Sanders as "the government", as if he's representative of most of the US government rather than an outlier that has little to no chance to get a bill like this passed it never mentions the fact that the bill establishes a model cutoff, measured in training effort (10^25 flops, which doesn't include the open weight models you're using at home, unless you have an 8x cluster of DGX Sparks - $40k+ worth of AI compute) Enterprise News Finally, in the enterprise security news, we check the vibes massive, connected funding NVIDIA OpenShell cars are still hackable a ransomware arrest turned into a murder investigation AI welfare All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-479

    State of the AI SOC, regulating AI, and can AI agents feel pain? - Aqsa Taylor - ESW #479
  2. Sep 28

    Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keeper - Kaushik Shanadi, Josh Davies, Tricia Howard, Christopher Crowley, Darren Guccione - ESW #478

    Interview with Christopher Crawley - The Value of SecOps This week, we talk to Chris Crawley about his new book, The Value of Cybersecurity Operations. Chris has been training teams on security operations for years, but found that students often struggled to justify the importance of secops training and even the need for secops in general. This book was written to more broadly arm practitioners with the information they need to communicate why security operations are necessary to leadership. The book is available in several forms: eBook, hardcover, softcover, and an audiobook read by Chris himself! You can pick all versions up here: https://shop.montance.com/collections/all and Security Weekly listeners get 50% off with code sw-50! The Evolving Exploitation of Trust with Josh Davies, Security Strategist at Fortra Fortra Intelligence and Research Experts (FIRE) is Fortra's emergent threat intelligence identity, created to unify research teams across multiple security disciplines and share intelligence with the wider threat intelligence community. FIRE co-ordinator and security strategist Josh Davies joins us to share insights from original FIRE research like Calphishing, Mirage2FA, RatPressto phishkit and heavily obfuscated campaigns that evade defences. While also digging into trends from big data analysis within phishing, fraud, social engineering and credential theft. Segment Resources: Art of Security Podcast Fortra Research This segment is sponsored by Fortra. Access FIRE Research here: https://securityweekly.com/fortrabh Why Agentic AI Security Requires a Defense-In-Depth Strategy with Kaushik Shanadi, CTO and Co-Founder of Helmet Security Many organizations are approaching agentic AI security by stitching together individual controls, assuming that identity, network, endpoint, or application security alone is enough. Each address only one part of the problem. As AI agents become more autonomous, move across systems, and take actions on behalf of users, organizations need a true defense-in-depth strategy that combines every layer of the security stack. Kaushik can discuss how each security layer provides a different piece of the puzzle and how individually, none of the controls are sufficient. But together, they create the layered governance needed to securely deploy agentic AI. For more information about Helmet Security, please visit https://securityweekly.com/helmetbh Above Security on Why Legacy Tools Don't Cut It for Modern Insider Risk with Tricia Howard, Head of Marketing at Above Security As organizations rush to adopt agentic AI, agents are often given broad access to critical business systems and sensitive data. Legacy insider risk management tools weren't built for this, and organizations have spent years on insider risk posturing and investments that leave security teams inundated with false positives while the real risk slips through undetected. In this segment, Tricia Howard draws on her decade in cybersecurity, including years watching user and entity behavior analytics (UEBA) overpromise and underdeliver, to unpack why understanding human – and now AI – intent is the missing piece. Segment Resources: Blog Post: Redefining Insider Threat Blog Post: What I wanted UEBA to be, Years Ago To learn more about Above Security and insider risk management in the era of agentic AI, visit: https://securityweekly.com/abovebh The Identity Crisis Your Security Team Didn't See Coming: Governing AI Agents with Darren Guccione, CEO and Co-Founder of Keeper Security AI agents outnumber human identities in enterprise environments, and traditional security software was never built to govern them. 89% of cybersecurity decision-makers recently surveyed by Keeper Security said that AI adoption has made identity management harder. In this Black Hat USA conversation with Cyber Risk TV, Darren Guccione, CEO and Co-Founder of Keeper Security, shares a practical framework for extending identity governance to non-human identities and AI agents before the access gap becomes a breach. Segment Resources: Privileged Access Management Identity Security at Machine Speed To learn more about Keeper Security, visit: https://securityweekly.com/keeperbh Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-478

    Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keeper - Kaushik Shanadi, Josh Davies, Tricia Howard, Christopher Crowley, Darren Guccione - ESW #478
  3. Sep 21

    Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477

    Interview with Rob Sadowsky from Cohesity Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act. In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality. With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell. To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries. This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience. https://www.cohesity.com/dm/global-cyber-resilience-report/ This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them! Topic: When should we use AI for writing and when should we avoid it? I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words. Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other. https://charity.wtf/p/confessions-of-an-unrepentant-slop When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it. I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine. In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language. And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review Weekly Enterprise News Finally, in the enterprise security news, We check the vibes, funding, and acquisitions Tenable now has Mythos built-in??? We check in on how vulnerability remediation is going Microsoft is creating a code of conduct for AI OpenAI just got called to the principal's office Booz Allen created new cybersecurity AI benchmarks 50% of CISOs see Mythos as a sign to resign??? Ayman read the latest Anthropic AI misuse report MIT explains the 12 possible AI outcomes (very ominous) a 9-year old decided to promote his YouTube account… with his dad's corporate card All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-477

    Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477
  4. Sep 14

    Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476

    Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest. This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them! Topic Segment - SmartTVs and Privacy For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear. We share our recent experiences and dive into some of the primary concerns and theories about what's going on here. If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms. Weekly Enterprise News Finally, in the enterprise security news, We check the vibes We check finding and acquisitions Nightmare Eclipse or Good Night of Sleep Eclipse? Update on Anthropic's Glasswing project How long would it take for a mobile phone worm to spread? Don't expose SSH to the public Internet Massive amounts of cryptocurrency continue to get stolen Did you actually read your third party's SOC 2? Your boss may be reading your AI chat history All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-476

    Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
  5. Sep 7

    Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475

    Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation. This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them! Topic - The British Library Cyber-Attack For this week's topic segment, we're discussing the British Library cyber-attack. In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once. Resources https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library The Weekly Enterprise News Finally, in the enterprise security news, We check the vibes the funding the acquisitions and the closures is the vulnpocalypse real, or not? TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes millions of IDs get leaked online What's the bigger story: Huggingface and NVIDIA or Microduck? Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-475

    Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475
  6. Aug 31

    Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474

    Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh. Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out! Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS Black Hat Interview 1 - Google Cloud Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense. Segment Resources: https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more! Black Hat Interview 2 - Forcepoint Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety. Segment Resources: https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more! Black Hat Interview 3 - Keyfactor From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments. Segment Resources: https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/ https://www.keyfactor.com/education-center/what-is-trust-infrastructure/ https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1 This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more! Black Hat Interview 4 - Delinea Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session. This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-474

    Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474
  7. Aug 17

    Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

    Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security. Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA. Segment Resources: Find more research from Rubrik Zero Labs Rubrik Zero Labs' Black Hat session Demo of the ChatMate attack in action This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them! Topic Segment - AI Notetakers and Recorders AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss. Questions enterprises should be asking: Are employees recording or transcribing meetings? Does this policy change if non-employees (external parties) are present? Is consent asked for/given? Is the context of the conversation taken into consideration? Is the geographic/legal/political context of the external party taken into account? Have you done your due diligence on third parties hosting/storing these recordings and transcriptions? Was your due diligence a SOC 2, or real, actual evidence-based due diligence? Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company? News Segment Finally, in the enterprise security news, we check the vibes and the funding, and the acquisitions seriously, don't mess with the wifi on planes 181,000 meetings were left wide open the sandbox escapes are getting ridiculous research on how reliable AI-generated patches are research on what attackers do after they get a shell research on how cybercriminals are using AI agents research on how vulnerable datacenters are and finally, what's a "mouthpad"? Stick around till the end of the news segment to find out! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-472

    Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

Ratings & Reviews

4.9
out of 5
14 Ratings

About

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.

You Might Also Like