Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.
Tune in for in-depth panel discussions, expert guest interviews, and breaking news on the latest hacking techniques, vulnerabilities, and industry trends. Stay informed and secure with the most trusted voices in cybersecurity!
At a time when the traditional approach to enterprise vulnerability management is no longer effective, security leaders are turning to AI agents to help identify, validate, and contain zero-day threats. Learn how Google Cloud Security is building autonomous detection engineering to help your organization close the remediation gap, establish compensating controls to protect business assets, and outpace AI-powered adversaries.
Segment Resources:
https://services.google.com/fh/files/misc/monitoringandstoppingaipowered_threats.pdf https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents?e=48754805
This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlecloud to learn more about them!
In the leadership and communications segment, CISOs can no longer ignore the nation-state threat, AI Policies Won't Save You If You Can't See The Risk, The Invisible Work Draining Your Best Employees , and more!
Show Notes: https://securityweekly.com/bsw-467
Venus in Furs, Money Laundering, Agentic AI Hijinx, MCP, Thunderbastard, Aaran Leyland, and More on the Security Weekly News.
Show Notes: https://securityweekly.com/swn-620
Finding flaws with LLMs and agents is changing bug bounty programs. But it's not necessarily changing how orgs fix those flaws. Shlomie Liberow shares his experience across a decade of bounty programs and how they have changed for researchers and orgs. He explains why fixing the bug reported through a bug bounty is more about understanding interconnected systems than fixing a single piece of software. We discuss how orgs can be more effective at securing their environment and what role LLMs might have in evaluating controls. Plus, we look to the future of bug bounty programs and how researchers can still excel through curiosity and expertise on a topic rather than relying on scanners, prompts, and luck.
Show Notes: https://securityweekly.com/asw-402
Interview with Christopher Crawley - The Value of SecOps
This week, we talk to Chris Crawley about his new book, The Value of Cybersecurity Operations. Chris has been training teams on security operations for years, but found that students often struggled to justify the importance of secops training and even the need for secops in general. This book was written to more broadly arm practitioners with the information they need to communicate why security operations are necessary to leadership.
The book is available in several forms: eBook, hardcover, softcover, and an audiobook read by Chris himself!
You can pick all versions up here: https://shop.montance.com/collections/all and Security Weekly listeners get 50% off with code sw-50!
The Evolving Exploitation of Trust with Josh Davies, Security Strategist at Fortra
Fortra Intelligence and Research Experts (FIRE) is Fortra's emergent threat intelligence identity, created to unify research teams across multiple security disciplines and share intelligence with the wider threat intelligence community. FIRE co-ordinator and security strategist Josh Davies joins us to share insights from original FIRE research like Calphishing, Mirage2FA, RatPressto phishkit and heavily obfuscated campaigns that evade defences. While also digging into trends from big data analysis within phishing, fraud, social engineering and credential theft.
Segment Resources:
Art of Security Podcast
Fortra Research
This segment is sponsored by Fortra. Access FIRE Research here: https://securityweekly.com/fortrabh
Why Agentic AI Security Requires a Defense-In-Depth Strategy with Kaushik Shanadi, CTO and Co-Founder of Helmet Security
Many organizations are approaching agentic AI security by stitching together individual controls, assuming that identity, network, endpoint, or application security alone is enough. Each address only one part of the problem. As AI agents become more autonomous, move across systems, and take actions on behalf of users, organizations need a true defense-in-depth strategy that combines every layer of the security stack. Kaushik can discuss how each security layer provides a different piece of the puzzle and how individually, none of the controls are sufficient. But together, they create the layered governance needed to securely deploy agentic AI.
For more information about Helmet Security, please visit https://securityweekly.com/helmetbh
Above Security on Why Legacy Tools Don't Cut It for Modern Insider Risk with Tricia Howard, Head of Marketing at Above Security
As organizations rush to adopt agentic AI, agents are often given broad access to critical business systems and sensitive data. Legacy insider risk management tools weren't built for this, and organizations have spent years on insider risk posturing and investments that leave security teams inundated with false positives while the real risk slips through undetected. In this segment, Tricia Howard draws on her decade in cybersecurity, including years watching user and entity behavior analytics (UEBA) overpromise and underdeliver, to unpack why understanding human – and now AI – intent is the missing piece.
Segment Resources:
Blog Post: Redefining Insider Threat
Blog Post: What I wanted UEBA to be, Years Ago
To learn more about Above Security and insider risk management in the era of agentic AI, visit: https://securityweekly.com/abovebh
The Identity Crisis Your Security Team Didn't See Coming: Governing AI Agents with Darren Guccione, CEO and Co-Founder of Keeper Security
AI agents outnumber human identities in enterprise environments, and traditional security software was never built to govern them. 89% of cybersecurity decision-makers recently surveyed by Keeper Security said that AI adoption has made identity management harder.
In this Black Hat USA conversation with Cyber Risk TV, Darren Guccione, CEO and Co-Founder of Keeper Security, shares a practical framework for extending identity governance to non-human identities and AI agents before the access gap becomes a breach.
Segment Resources:
Privileged Access Management
Identity Security at Machine Speed
To learn more about Keeper Security, visit: https://securityweekly.com/keeperbh
Show Notes: https://securityweekly.com/esw-478
Ear mite butterfly effects, Chuds, Agentic AI galore, CISA, Shiny Hunters, FreeBSD, Ghost Accounts, Pervs, Josh Marpet, and More on this episode of the Security Weekly News.
Show Notes: https://securityweekly.com/swn-619
In the security news this week:
Build your own router, or just buy one
What to patch first
But maybe don't buy D-Link
AI nearly starts a war
Flock cameras lose their keys
The AI slowdown won't save bad security
Opus at home, just slower
Black Hat says fundamentals still work
Hacker gadgets, and my top pick
Gyazo screenshots
Fake job interviews, real malware
VINCE gets a new home
Munich university gets disconnected
LinkedIn fights the scraping machine
SolarWinds hard-codes another bad idea
Fake LastPass kills 145 security tools
Colorado water gets its settings changed
AI CEOs sell apocalypse and bonds
The AI safety cult gets audited
Ransomware recovery takes weeks, not hours
TeamPCP's supply-chain tour continues
Zuckoff hunts smart glasses
Show Notes: https://securityweekly.com/psw-945
As businesses race to embrace AI, security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. How do you balance the benefits of AI with the Risks of AI?
Evan McHenry, Chief Information Security Officer at Robinhood Markets, joins Business Security Weekly to discuss how to practically implement and secure AI in the enterprise. Evan will share his lessons learned over the last 18 months, including how to communicate with the Board, why you should own Enterprise Architecture and embrace IT, and why you don't have time to argue with your CFO. If you're struggling to balance the benefits of AI with the Risks of AI, this interview is for you.
In the leadership and communications segment, Security spending is growing — except for the typical CISO, What Leaders Need to Know About AI and Psychological Safety, The Cyber Gap, and more!
Show Notes: https://securityweekly.com/bsw-466
WWIII,Security Debt, JFK, CISA, SUSE, OpenAI, Google, DORA, Aaran Leyland, and More on the Security Weekly News.
Show Notes: https://securityweekly.com/swn-618
Prompt injection demonstrates one of the major challenges in securing LLMs and agents -- how do you ensure an agent ignores attackers and only does what you instructed it to do. The flaw highlights how LLMs mix inputs, context, and outputs without any strict boundaries between them. Julie Brunias joins us to talk through examples of injections, why their consequences can go beyond information leaks, and why trying to mitigate them with other LLMs is insufficient.
Segment resources:
https://llmgateway.io/open-source
https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise
Show Notes: https://securityweekly.com/asw-401
Interview with Rob Sadowski from Cohesity
Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment
Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act.
In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality.
With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell.
To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries.
This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience.
https://www.cohesity.com/dm/global-cyber-resilience-report/
This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them!
Topic: When should we use AI for writing and when should we avoid it?
I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words.
Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other.
https://charity.wtf/p/confessions-of-an-unrepentant-slop
When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it.
I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine.
In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language.
And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review
Weekly Enterprise News
Finally, in the enterprise security news,
We check the vibes, funding, and acquisitions
Tenable now has Mythos built-in???
We check in on how vulnerability remediation is going
Microsoft is creating a code of conduct for AI
OpenAI just got called to the principal's office
Booz Allen created new cybersecurity AI benchmarks
50% of CISOs see Mythos as a sign to resign???
Ayman read the latest Anthropic AI misuse report
MIT explains the 12 possible AI outcomes (very ominous)
a 9-year old decided to promote his YouTube account… with his dad's corporate card
All that and more, on this episode of Enterprise Security Weekly.
Show Notes: https://securityweekly.com/esw-477
Bacteria, Spartans Invade Athens, Agentic AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet, and More on this episode of the Security Weekly News.
Show Notes: https://securityweekly.com/swn-617
In the security news this week:
UK government rolls out passkeys to 20 million users
Phishing-resistant authentication and replay resistance
Passkey adoption, device security, and user acceptance
EU Cyber Resilience Act guidance, scope, and compliance
CRA vulnerability disclosure and reporting requirements
The real cost of cyberattacks and cybersecurity spending
Cyber insurance and improving organizational security
Nightmare Eclipse and the release of Windows zero-days
Check Point VPN vulnerabilities and perimeter security
GitLab security updates and shadow IT
Discovering unmanaged GitLab instances
Cyberattacks against oil tankers and insider threats
VPN patching and implied rules
Zero-downtime GitLab updates and version management
Running Windows ARM on Apple Silicon with VMware and Parallels
Show Notes: https://securityweekly.com/psw-944
The overwhelming majority of people, across the full span of their professional lives, operate without formal authority over the domains in which they work (i.e., leadership). Yet followership has almost no sustained literature, no targeted development, and no rigorous framework of its own. If you're not a leader, what does a follower look like?
Kenyada Meadows, CEO & Founder at The Executive Parent Company, joins Business Security Weekly to discuss his book, The PASSENGER Seat, which outlines a framework for followership. Kenyada will outline the nine disciplines of the framework across three dimensions, including:
(P) Principled Anchoring — Holds values explicitly and specifically enough to guide behavior under pressure; knows the limit line before reaching it.
(A) Accountability — Communicates upward honestly, documents concerns before decisions are made, and owns errors without deflection.
(S) Self-Mastery — Invests deliberately in work, home, and inner domains, so identity — and ethical agency — isn't hostage to institutional threat.
(S) Systems Thinking — Reads the institution analytically — what produces the patterns observed, and where honest information is being filtered.
(E) Emerging Risk Management — Functions as an early-warning system for risks that formal frameworks haven't yet named.
(N) Negotiation — Translates insight and values into institutional impact through credibility, framing, coalition, and timing. -(G) Guardianship — Protects what the institution stands for over time, especially when no one is watching.
(E) Enablement — Ensures influence strengthens collective capacity rather than merely advancing individual position.
(R) Results-Driven Influence — Binds the other eight disciplines toward outcomes that are genuinely better — not merely visible.
In the leadership and communications segment, Stop playing with the CISO role. Fix cybersecurity leadership, What CIO-CISO alignment looks like when it's working, Why judgment is emerging as cybersecurity's defining skill, and more!
Show Notes: https://securityweekly.com/bsw-465
RoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More on the Security Weekly News.
Show Notes: https://securityweekly.com/swn-616
While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jason Cortlund break down how threat actors leverage LLMs as a force multiplier to accelerate mobile app attacks. Then we discuss actionable defense strategies, from viewing agents as an active adversary to leveraging server-side threat telemetry, attestation, and layered defense strategies combined with polymorphic code releases.
This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them!
Show Notes: https://securityweekly.com/asw-400
Interview with Snehal Antani
Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest.
This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them!
Topic Segment - SmartTVs and Privacy
For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear.
We share our recent experiences and dive into some of the primary concerns and theories about what's going on here.
If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms.
Weekly Enterprise News
Finally, in the enterprise security news,
We check the vibes
We check finding and acquisitions
Nightmare Eclipse or Good Night of Sleep Eclipse?
Update on Anthropic's Glasswing project
How long would it take for a mobile phone worm to spread?
Don't expose SSH to the public Internet
Massive amounts of cryptocurrency continue to get stolen
Did you actually read your third party's SOC 2?
Your boss may be reading your AI chat history
All that and more, on this episode of Enterprise Security Weekly.
Show Notes: https://securityweekly.com/esw-476
Twenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on.
Then we get to work.
Shift-left didn't fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request — so the earliest trust boundary isn't your first commit any more, it's the moment an agent gets context and authority. Most of us haven't moved our controls with it.
Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every layer built to look too boring to escalate. When your analyst closes that alert as adware, they may have just closed three separate compromises.
Google's threat tracker: a credential-harvesting campaign built and run in under six hours, with Markdown files as attacker playbooks. And malware carrying prompt-injection text designed to make your LLM scanner refuse to look at it — because a refusal that reads as "clean" is a free pass.
A CVSS 10 in Gemini CLI that never touched the model. No prompt, no injection, no tool call. The attacker just turned up before the sandbox did.
The first ever Take It Down Act sentencing — handled carefully, with what you actually do if someone tells you something, and a proper shout-out to Dale, the Cyber Safety Guy, whose work every parent with a teenager online should have bookmarked.
Two hundred and sixty-three million dollars walks out of a Bitcoin sidechain and then walks back in. Nobody stole the keys. They just convinced the system to sign a lie.
Anthropic's 154-page threat report. And an alignment lead who puts extinction odds above ten percent.
All that, plus Josh Marpet's take, on Security Weekly News #615.
Show Notes: https://securityweekly.com/swn-615
In the security news this week:
Microsoft patches all the things
Commissary freezers enter cyberwar
Fake AV, real Defender nap
Rowhammer comes for the GPU
BIOS updates are no longer optional
CVSS is not a crystal ball
Kworker, but make it malware
FortiGate gets a post-exploitation RAT
CERN goes Debian underground
UEFI shells strike again
Australia loses the plot, and phones
Cisco routers become covert gateways
MikroTik patches the takeover chain
WeWorm wriggles through mobile
The year of Linux television
Browsers become backdoors
Fake IT calls, real data theft
CVE attribution gets weird
Boston Scientific keeps talking
Security tools misconfigure themselves
AI circuit breakers for rogue agents
Passkeys meet the real world
Vibe coding, vibe vulnerabilities
AI loss of control keeps climbing
AI agents report themselves to Schneier
Show Notes: https://securityweekly.com/psw-943
AI is all the hype, but we're currently stuck at the bottom of the 'J' curve. Wild enthusiasm has given way to the reality of costs, benefits, and risks. What's next for AI and companies looking to capitalize on the AI trends?
John Willis, author, researcher, and technology industry veteran, joins Business Security Weekly to discuss AI's impact on fundraising. John explores what the history of AI can teach us about the current moment, including how to separate genuine technological transformation from hype and better understand where AI may take us next.
Next, it's time for Security Money. The Index is exploding upwards as the markets continue to climb. Both the Index and the NASDAQ, hit all time highs. The Business Security Weekly crew breaks down funding, acquisitions, and performance of both the public and private markets.
The Security Weekly 24 Index is made up of the following pure play public security companies:
SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc
Show Notes: https://securityweekly.com/bsw-464
Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland, and More on the Security Weekly News.
Show Notes: https://securityweekly.com/swn-614