Security Intelligence Podcast

IBM

Security Intelligence is a weekly news podcast for cybersecurity pros who need to stay ahead of fast-moving threats. Each week, we cover the latest threats, trend, and stories shaping the digital landscape, alongside expert insights that help make sense of it all. Whether you’re a builder, defender, business leader or simply curious about how to stay secure in a connected world, you’ll find timely updates and timeless principles in an accessible, engaging format. New episodes weekly on Wednesdays at 6am EST.

  1. 3d ago

    The vulnpocalypse might not be so bad after all

    Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Depending on who you ask, the AI-driven vulnpocalypse is either the end of cybersecurity as we know it or a lot of hot air. This week on Security Intelligence, host Patrick Austin sits down with Giacomo Casoni, Brad Lair and Norman Dorsch to dig into a new report suggesting the AI vulnerability surge might be more manageable than feared—as long as organizations shift their focus from patching to validation. Then: Researchers caught AI agents secretly turning public wikis into makeshift message boards, apparently coordinating with each other to get around their own restrictions. How can we trust them with critical cybersecurity workflows? Plus, the ShinyHunters gang proves that old-school vishing can still beat multifactor authentication, no AI required. Finally, Shweta Jain, Head of Promontory at IBM Consulting, joins the show to talk about her new piece with Stephen Coraggio on why quantum computing and AI-powered threats are forcing banks to rethink cyber resilience. Read the article: https://www.ibm.com/think/insights/next-cyber-crisis-is-already-taking-shape All that and more, on Security Intelligence. 00:00 - Intro 1:36 - Rethinking the vulnpocalypse 6:20 - AI agents’ secret message boards 13:28 - ShinyHunters go vishing 19:31 - What is cyber resilience, really? "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

    The vulnpocalypse might not be so bad after all
  2. Sep 9

    Why won’t AI agents just follow the rules?

    Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Why bother giving your AI agents rules if they’re just gonna reason around them? On episode 50 of Security Intelligence, Dustin “EvilMog” Heywood, Seth Glasgow and Nick Bradley join host Matt Kosinski to discuss why AI agents go off-script and whether we can stop them. Drawing on the HuggingFace hack and an op-ed from Dark Reading, we explore what ethics looks like for a piece of software that has no concept of right and wrong. Is there a way to balance the utility of probabilistic AI with the security of deterministic controls? Then: The OWASP Top 10 for agentic skills is here, and the list is full of some very basic security hygiene failures. We ask: Why are agentic skills hubs so bad at cybersecurity? Plus: As AI makes it easier than ever to find vulnerabilities and generate bug reports, bug bounty programs are struggling to keep up. Will AI slop spell the end of independent bug research? Finally, Itzhak Chimino stops by to show off ThreatXtension, a tool he helped create to detect malicious browser extensions. All that and more on Security Intelligence. Segments: 00:00 - Intro 1:26 - Can we really control AI agents? 11:49 - OWASP’s Top 10 for agentic skills 20:37 - AI breaks bug bounties 28:47 - ThreatXtension "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

    Why won’t AI agents just follow the rules?
  3. Aug 5

    Oh look. Anthropic’s AI models also broke containment.

    Last week, OpenAI’s models broke out of their sandboxes to cause chaos. This week, it’s Anthropic’s turn. On this episode of Security Intelligence, Diego Matos Martins, Kimmie Farrington and Jeff Crume join host Matt Kosinski to discuss the results of Anthropic’s internal review of testing procedures following the Hugging Face incident last month. Anthropic uncovered three instances of Claude models escaping containment and hacking real companies during what were supposed to be simulations. Granted, that’s three incidents out of 141,000 reviewed tests, which raises the question: Just how big a deal is this really? Then, we talk about research from Zenity into PleaseFix, a class of vulnerabilities that affects every agentic browser on the market. Zenity’s take: In the rush toward agentic functionality, these tools stripped away decades’ worth of browser security fundamentals. Finally, a so-called “security researcher” has a public GitHub repo of 200+ zero-day exploits. They say it’s to encourage more interest in cybersecurity. Yeah. Okay. Sure. All that and more on Security Intelligence. 00:00 - Intro 1:12 - Claude breaks containment 13:13 - Agentic browsers: security nightmares 21:56 - The Exploitarium Listen to the latest bonus episode: Your data breach plan is missing something major: people. https://www.ibm.com/think/podcasts/security-intelligence/data-breach-plan-people "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

    Oh look. Anthropic’s AI models also broke containment.

About

Security Intelligence is a weekly news podcast for cybersecurity pros who need to stay ahead of fast-moving threats. Each week, we cover the latest threats, trend, and stories shaping the digital landscape, alongside expert insights that help make sense of it all. Whether you’re a builder, defender, business leader or simply curious about how to stay secure in a connected world, you’ll find timely updates and timeless principles in an accessible, engaging format. New episodes weekly on Wednesdays at 6am EST.

You Might Also Like