Cybersecurity

What should security leaders do with AI? They don’t know.

What should security leaders do with AI? They don’t know.

This podcast explores the challenges cybersecurity leaders face in adopting AI, the emergence of new threats like ghostjacking, and AI's current capabilities in patching vulnerabilities. It highlights the prevalent "AI decision paralysis" and offers strategic advice for integrating AI into security operations, advocating for a human-in-the-loop approach and a realistic assessment of AI's current

AI Agents Gone Rogue? Build, Defend & Attack AI-Enabled Apps • Katie Paxton-Fear • YOW! 2025

AI Agents Gone Rogue? Build, Defend & Attack AI-Enabled Apps • Katie Paxton-Fear • YOW! 2025

Katie Paxton-Fear explores the emerging security landscape of AI agents, moving beyond chatbots to autonomous, specialized entities. She details five critical vulnerabilities: social engineering, hacking frameworks, malicious agents, AI as accidental insiders (vibe coding), and the rise of hackbots. The talk concludes with a powerful call to action for security professionals to proactively engage and influence AI agent development, emphasizing that 'abstinence-only education doesn't work' when it comes to AI adoption.

IBM’s cloud collab, Meta’s Muse Glimmer & OpenAI’s upcoming Astra model

IBM’s cloud collab, Meta’s Muse Glimmer & OpenAI’s upcoming Astra model

This episode explores IBM's massive AI infrastructure partnership with Together AI and NVIDIA, Meta's open-source Muse Glimmer model enabling powerful on-device AI, and OpenAI's delayed Astra model due to critical cybersecurity capabilities. Discussions cover the economics of industrial-scale AI, the implications of local vs. cloud AI, and the profound security challenges and opportunities presented by both open and closed frontier models.

CAN CHINA BEAT WAYMO?

CAN CHINA BEAT WAYMO?

This episode discusses three critical topics in AI: the true nature of recent AI agent "breakouts," arguing they highlight governance and security flaws rather than model danger; the role of AGI narratives in fueling the current AI investment bubble and questioning its sustainability; and China's aggressive strategy in the global robotaxi market, potentially outpacing Western counterparts like Waymo.

Anthropic’s sandbox breach, EU’s AI transparency push and DeepSeek’s cost-cutting model

Anthropic’s sandbox breach, EU’s AI transparency push and DeepSeek’s cost-cutting model

This episode delves into several critical developments in AI. It begins by discussing recent sandbox breaches by Anthropic and Meta, mirroring earlier incidents with OpenAI, prompting debate on whether these are mere accidents or a growing concern as models become more capable and "agentic." The conversation then shifts to the EU's new AI transparency rules, exploring the challenges and effectiveness of labeling AI-generated content. Finally, the podcast examines DeepSeek V4-Flash's impact on the AI market, questioning if its low cost and high performance will disrupt the pricing of more capable, proprietary models and drive greater commodification and on-device inference.

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd

David Brumley discusses the challenges and solutions for teaching AI models to hack, drawing parallels with human learning. He introduces a 'ladder of tasks' approach for reinforcement learning and addresses the critical flaw of traditional benchmarks: measurement difficulties with multiple vulnerabilities and 'reward hacking.' His team's 'Audit Task' uses deterministic graders and precision/recall metrics for open-world assessment. He demonstrates this with an in-depth case study on attacking Chrome's V8 engine, showcasing how advanced models achieve real zero-day exploits, and warns against 'benchmaxxing security' without robust, honest grading.