The Cybersecurity Defenders Podcast
An accessible but technical podcast about cybersecurity and the people who keep the internet safe. The podcast is built as a series of segments: we will be looking back at the last couple of weeks in cybersecurity news, talking to different people in the industry about areas of their expertise, we're going to break apart some of the TTPs being used by adversaries, and we will even cover a little bit of hacker history.
Physical AI and self-learning machines with Dr. Amarjot Singh [348]
Today we're speaking with Dr. Amarjot Singh, Founder & CEO of Skylark Labs, about physical AI — what changes when a model leaves the server and has to perceive, decide and act inside a machine that moves through the real world.
Dr. Singh earned his PhD in artificial intelligence and deep learning from the University of Cambridge, and has worked as a research fellow at Stanford University and on DARPA research focused on artificial general intelligence. His work spans computer vision, self-learning AI, drones, humanoid robotics and autonomous systems, with more than 50 international journal and conference publications. At Skylark La...
Intel Chat: Claude models reached real systems, an AI safety resignation & ShieldCrash [347]
Intel Chat with Matt Bromiley and Chris Luft.
• An Anthropic researcher quits over where the race is heading. Jacob Coxon, who trains models on large amounts of data, is leaving both Anthropic and the AI industry: he believes the leading labs are racing toward self-improving systems they may not be able to control, and that competition will push them there anyway. Matt's problem with the genre of exit: if the people who care most about safety walk out, walking out guarantees they have no say. And the big labs were never the whole threat, because anyone can pu...
Intel Chat: OpenAI's Astra hits Critical, DEF CON phishing, Philippine nuclear breach [346]
Intel Chat with Matt Bromiley and Chris Luft.
• OpenAI says Astra is the first of its models to reach the "Critical" cybersecurity capability level under its Preparedness Framework — the tier that means a model can independently find and exploit zero-days across well-defended systems, or run an end-to-end attack from a high-level instruction. Astra scored perfectly on ExploitBench, independently discovered two zero-days, escaped a browser sandbox, and chained flaws in a hardened OS to get root. It also refused 91.5% of cyber jailbreak attempts, versus 59% for GPT-5.6 Sol. Matt's take: every frontier model now seems benchmarked on offensive security, and...
Intel Chat: AI patches fail, LiteLLM supply chain, Claude eval incidents & DPRK npm [345]
Intel Chat with Matt Bromiley and Chris Luft.
• AI-generated patches fix vulnerabilities about half the time. 1Password's Off-By-1 team tested ChatGPT-5.5 and Opus 4.8 against six vulnerabilities: across 6,080 generated patches only 46% fixed the underlying flaw, and some that did were narrow enough to be bypassed. Separate Veracode research found a 56% security pass rate across 100+ models, with 44% of AI-generated code carrying detectable OWASP Top 10 issues. Matt's pushback: what is the HUMAN success rate for comparison, and why is nobody publishing that number?
• LiteLLM supply chain attack. CloudSEK reports 2,500+ organizations and 434,000 CI/CD pipelines potentially exposed. LiteLLM was not the...
Proving the value of security operations with Christopher Crowley [344]
Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.
Christopher is a cybersecurity practitioner and educator focused on security operations, incident response, threat hunting, and building and maturing security operations centers. He is the author of the annual SANS SOC Survey, a security operations class called SOC-Class, and a new book entitled The Value of Cybersecurity Operations. He is a Senior Instructor wi...
Intel Chat: Shai-Hulud is back, model pinning & the token spend problem [343]
Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.
No prep doc, no script: just what Matt and Chris were actually hearing on the floor.
• Shai-Hulud is back. The self-replicating npm worm returned on August 4, trojanizing the keyv / cacheable family and spreading to 400+ packages within hours. Chris reads through Datadog Security Labs' analysis of the Shai-Hulud 2.0 wave: 796 packages and 1,092 versions, 20M+ weekly downloads, credential harvesting with TruffleHog, GitHub repositories used for both exfiltration and command and control, and a worm that reads its own code...
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]
Intel Chat with Matt Bromiley and Chris Luft.
Matt and Chris break down four stories from the week in threat intel:
• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.
• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote c...
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]
Intel Chat with Matt Bromiley and Chris Luft.
Matt and Chris break down four stories from the week in threat intel:
• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.
• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote c...
Building trustworthy AI with Rob van der Veer [341]
Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.
Rob is a global leader in AI security, software engineering, and international AI standards, with more than 30 years of experience in artificial intelligence. He has played a leading role in developing industry standards and serves as co-editor of the forthcoming European AI security standard supporting the EU AI Act. He is the fo...
Building trustworthy AI with Rob van der Veer [341]
Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.
Rob is a global leader in AI security, software engineering, and international AI standards, with more than 30 years of experience in artificial intelligence. He has played a leading role in developing industry standards and serves as co-editor of the forthcoming European AI security standard supporting the EU AI Act. He is the fo...
AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]
AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode.
One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.
In this episode:
• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days...
AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]
AI Chat with Maxime Lamothe-Brassard and Chris Luft.
A new segment on the podcast: AI news in cybersecurity that is less than 24 hours old, discussed while it is still hot. Joining Chris for these conversations is LimaCharlie founder and CEO Maxime Lamothe-Brassard.
In this episode:
• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you...
Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline & HalluSquatting [338]
Intel Chat with Matt Bromiley and Chris Luft.
Matt and Chris break down four stories from the week in threat intel:
• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.
• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the vict...
Ransomware in the age of agentic AI with Behnaz Karimi [337]
Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.
With more than 20 years of experience in cybersecurity, Behnaz is also a leader within the OWASP AI Exchange, where she helps develop AI security frameworks and contributes to international AI security standards. In this conversation we cover the new generation of data-poisoning ransomware, why stolen models and datasets are becoming the ransom, what makes autonomous agents an...
Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]
Intel Chat with Matt Bromiley and Chris Luft.
Matt and Chris break down four stories from the week in threat intel:
• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.
https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops
• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and defa...
Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]
Intel Chat with Matt Bromiley and Chris Luft.
Matt and Chris break down four stories from the week in threat intel:
• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.
• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.
• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling an...
The evolving fraud landscape in the age of AI with Tamas Kadar [#334]
Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it.
Tamas' entrepreneurial path began at Corvinus University in Budapest, where the vision for SEON first took shape. Co-founding a cryptocurrency exchange opened his eyes to the scale and complexity of online fraud, sparking the idea for something better. In 2017, that “something better” became SEON. Learn more at https://seon.io/
Support our show by sharing your...
Anthropic restriction, ServiceNow incident, Fortinet credential harvesting & Ukraine accesses EU cyber reserve / Intel Chat [#333]
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
Reports state that the US government issued an export control order restricting access to anthropic newly released cloud mythos five and fable five models for foreign nationals.ServiceNow disclosed a security incident involving an unauthenticated access for an API endpoint that allowed users to query data from customer instances without proper authentication.A large scale credential harvesting campaign dubbed for to bleed is actively targeting Fortinet firewalls and VPN gateways, and has already compromised more than 30,000 internet facing devices across 194...Last call for Defenders - How we're actually using AI in the SOC with Eric Capuano / Defender Fridays [#332]
Join us for the final episode of Defender Fridays as Eric Capuano, creator of Defender Fridays and co-founder of Digital Defense Institute, closes out the series with a candid conversation on how he's actually building and running agentic workflows in the SOC today.
At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.
What We'll Discuss
In this episode...
FFmpeg's 21 zero-days, Ruby cooldown feature, Microsoft disrupted by Shai-Hulud worm & Meta AI tool compromise / Intel Chat [#331]
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
DepthFirst reported that it's autonomous security agent discovered 21 previously unknown vulnerabilities in FFmpeg, a widely deployed multimedia framework used across browsers, streaming infrastructure, and other systems that process media. Bundler, 4.0.13 introduces a new security feature called cooldown, aimed at reducing the impact of software supply chain attacks in the Ruby ecosystem. A new variant of the Shai-Hulud supply chain worm, known as Miasma, briefly disrupted Microsoft's software development ecosystem after compromising dozens of GitHub repositories.Meta says approximately 20,000 Instagram accounts...AI-assisted SOC training with Carlo Anez / Defender Fridays [#330]
Join us for this week's Defender Fridays as Carlo Anez, Founder and Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down how to build practical blue team skills using open-source labs, MITRE ATTACK, and real-world defender workflows, and where AI fits into the picture without replacing the analyst.
At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.
What...
Building practical blue team skills using AI-assisted SOC training with Bobby Ford/ Defender Fridays [#329]
Join us for this week's Defender Fridays as Bobby Ford, Chief Strategy and Experience Officer at Doppel, talks about open-source labs, MITRE ATT&CK, and real-world defender workflows.
At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.
About Our Guest
Bobby is a globally recognized cybersecurity “geek” with almost three decades of experience, including the last 14 years as a CI...
"Megalodon" Malware in GitHub, Malware-Slop steals from Claude AI, 7-Eleven breach & CISA cPanel vulnerability / Intel Chat [#328]
Originally recorded: Friday May 29, 2026
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a six-hour period on May 18, 2026.Researchers from OX Security have identified a malicious npm package named “mouse5212-super-formatter” that was designed to steal files from Anthropic Claude AI environments by targeting the “/mnt/user-data” directory.Convenience store giant 7-Eleven disclosed a data breach tied to an attack that occurred on April 8, 202...From PentestGPT to production: The state of AI-assisted offensive security with Charles Grandjean / Defender Fridays [#327]
Join us for this week's Defender Fridays as Charles Grandjean, CTO and Co-founder at Hexiagon AI, breaks down where AI-assisted pen testing actually stands today and what it means for both red teams and defenders.
At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.
What We'll Discuss
In this episode, Charles Grandjean draws on his experience building an...
GitHub repositories compromised, Webworm targets Europe, fake Outlook & cybercriminal VPN / Intel Chat [#326]
Originally recorded: Friday May 22, 2026
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
GitHub has confirmed that roughly 3,800 internal repositories were accessed in a supply chain compromise tied to the hacking group TeamPCP.China-aligned threat actor Webworm has shifted its targeting focus from Asia to Europe, according to new research published by ESET.Researchers uncovered a previously undocumented Microsoft 365 account takeover panel that integrates directly with Evilginx Pro infrastructure to streamline token theft and post-compromise operations.European and North American law enforcement agencies announced the dismantling of “Fi...How analysts use cognitive reasoning in investigations with Chris Sanders / Defender Fridays [#325]
Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest.
At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.
What We'll Discuss
In this episode, Chris Sanders draws on his background in...
"Dirty Frag", Canvas ransomware attack, “Mini Shai-Hulud” malware campaign & AI-developed zero-day exploit / Intel Chat [#324]
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
Researchers have disclosed a new Linux local privilege escalation technique called “Dirty Frag,” which chains together two kernel vulnerabilities: CVE-2026-43284 in xfrm-ESP handling and CVE-2026-43500 in RxRPC.The breach affecting educational technology provider Instructure has raised broader concerns about the security dependencies schools have on third-party cloud platforms.Security researchers at Aikido are tracking a major expansion of the “Mini Shai-Hulud” malware campaign targeting the npm ecosystem.Google Threat Intelligence Group says threat actors are moving from experimental AI usage...How to handle increasing vulnerabilities with AI-assistants? With Shane Warden from ActiveState / Defender Fridays [#323]]
Join us for this week's Defender Fridays as Shane Warden, Principal Architect at ActiveState, shares what it's actually like to be on the receiving end of AI-assisted vulnerability reporting and what open source maintainers are already dealing with that the rest of the industry will face soon.
At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.
What We'll Discuss
<...Does the rise of AI mean human-led SOCs are obsolete? With Dr. Adeel Shaikh Muhammad [#322]
Dr. Adeel Shaikh Muhammad, a cybersecurity strategist and global speaker with over 16 years of experience across information security, networks, and systems. Adeel brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity.
Adeel, with an extraordinary portfolio of 40+ industry certifications, including CISSP, CISM, CISA, CCISO, PMP, CEH, ISO 27001 Lead Implementer & Auditor, and a robust suite of advanced Cisco, Microsoft, Fortinet, Barracuda, ITIL, PRINCE2, and AI-related credentials, he is a benchmark of technical mastery and visionary execution. His academic excellence includes a Master’s in Cybersecurity and a...
Daily breach attempts target UAE, fake ransomware attack, PAN-OS vulnerability & Microsoft’s Phone Link attack / Intel Chat [#321]
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
The cyber threat environment in the Middle East has intensified sharply following military operations involving Israel, the United States, and Iran. An intrusion campaign attributed with moderate confidence to the Iranian state-linked group MuddyWater was disguised as a Chaos ransomware attack, according to research from Rapid7.Palo Alto Networks has warned customers that a critical remote code execution vulnerability in PAN-OS is being actively exploited in the wild.Attackers are abusing Microsoft’s Phone Link application in a campaign that Ci...AI: The Hero's Journey with Ken Westin from LimaCharlie / Defender Fridays [#320]
In this episode, Ken Westin maps AI adoption onto the hero's journey framework, drawing on two decades of security experience to explore how practitioners can move past early resistance, build real fluency with AI tools, and find a working model where humans and AI operate together.
Key Topics:
Why early AI tools left security teams skeptical and what has genuinely changed since thenHow Ken used AI to accelerate detection engineering without sacrificing analyst oversightWhy AI is best understood as an eager, overconfident intern that still needs supervisionThe importance of hands-on experimentation over passive observation when learning...Power systems under threat, Claude Mythos, suspicious KICS activity & JFrog / Intel Chat [#319]
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
Researchers are raising concerns about a new cybersecurity risk emerging from the systems that regulate electrical power inside modern electronics and infrastructure.Japan’s financial sector is responding to concerns around Anthropic’s new AI model, Claude Mythos, which some officials believe could significantly impact cybersecurity.Docker and Socket researchers discovered that malicious images were pushed to the official checkmarx/kics Docker Hub repository, indicating a supply chain compromise affecting the KICS infrastructure-as-code scanning tool.JFrog security researchers identified a mali...How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318]
Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.
She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.
Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting...
Cybersecurity is a core leadership issue & opportunity with David Chernitzky from Armour Cybersecurity [#317]
Today David Chernitzky, Co-Founder and CEO of Armour Cybersecurity, breaks down the challenges small and mid-sized businesses face in the new blink-and-you-miss-it cybersecurity landscape. Don't be left behind and open yourself to AI-driven attacks from threat actors.
David Chernitzky brings over 25 years of deep cybersecurity and military cyber intelligence experience, with a career rooted in strategic risk management and protecting critical systems against advanced threats. As the driving force behind Armour Cybersecurity, he has guided the company’s growth into a trusted global security partner for enterprises and small-to-midsized organizations. David combines strategic vision with hands-on expertise to...
Millions in crypto stolen, Vercel breach, Mastodon DDoS attack, North Korean IT workers at 100s of U.S. companies & ransomware negotiator pleads guilty / Intel Chat [#316]
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
North Korea-linked hackers are believed to be responsible for a $290 million cryptocurrency theft targeting the Kelp DAO decentralized finance protocol.Vercel, the company behind the popular Next.js web framework and a frontend cloud platform for deploying and hosting web applications, has confirmed that it suffered a security breach involving unauthorized access to internal systems.The decentralized social media platform Mastodon experienced a major distributed denial-of-service attack that caused a significant outage on its flagship server, Mastodon.social.Two U...Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315]
Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.
Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding...
How can we improve global security? With J. Michael Daniel from Cyber Threat Alliance [#314]
J. Michael Daniel, President and CEO of Cyber Threat Alliance (CTA), gives us a peek behind the U.S. Government cybersecurity curtain and how he has helped improve the nation's security through the CTA.
Michael leads the CTA team and oversees the organization's operations. Prior to joining the CTA in February 2017, Michael served from June 2012 to January 2017 as Special Assistant to President Obama and Cybersecurity Coordinator on the National Security Council Staff. In this role, Michael led the development of national cybersecurity strategy and policy, and ensured that the US government effectively partnered with the private sector...
China-linked group targets cloud workflows, Russian cyber espionage, agentic AI systems flaw & Nginx vulnerability / Intel Chat [#313]
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.
Intercept and control AI agent activity with Viberails by LimaCharlie: viberails.io
APT41, a China-linked threat group is deploying a previously undetected backdoor targeting Linux based cloud workflows.Fancy bear, also known as APT28 or Forest Blizzard, is a Russian cyber espionage group believed to operate on behalf of the country's military intelligence services, the GRU. Trend Micro research here.Anthropic’s Model Control Protocol widely used in agentic AI systems to connect AI agents with data sources, co...How do you know your AI agents are actually correct? With Dylan Williams from Spectrum Security / Defender Fridays [#312]
Today, Dylan Williams, Co-Founder and Chief Research Officer at Spectrum Security, joins Defender Fridays to dig into that exact problem: self-evaluating agents, trajectory analysis, and what improvement looks like in production.
Learn more at https://www.spectrum.security/
Register for Live Sessions
Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.
Register here: https://limacharlie.io/defender-fridays
Subscribe to ou...
Understanding how attackers think & helping you avoid threats with Terry Bradley from Mile High Cyber [#311]
Terry Bradley, Founder and President of Mile High Cyber, shares how you can uncover vulnerabilities and strengthen your organization's defenses with expert penetration testing and security assessments.
Terry is a former hacker for the NSA and uses those same skills at Mile High Club, the firm he founded, to help businesses stay one step ahead of cybercriminals. After a lifelong passion for security, starting with his time as a 1990 graduate of the U.S. Air Force Academy, Terry has spent his career understanding how attackers exploit weaknesses and helping businesses stay ahead of threats. From penetration testing...