Patch management

GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell

GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell

This podcast explores the implications of open-weight AI models like GLM-5.2 for cybersecurity, CISA's new four-variable vulnerability prioritization model, the rise of AI-assisted 'vibe hunting,' and the commercial launch of IBM and Red Hat's Lightwell for securing open-source software. It highlights the tension between AI capabilities for attackers and defenders, the challenges of rapid vulnerability remediation, and the need for new "trust infrastructures" in the AI era.

LLMjacking: How hackers steal your AI API keys and stick you with the bill

LLMjacking: How hackers steal your AI API keys and stick you with the bill

Experts discuss the rise of LLMjacking, where stolen AI API keys lead to massive financial losses. They explore how AI is reshaping adversary simulations, the enduring need for human expertise in the loop, and the debate over accelerating security patch timelines in the face of AI-powered threats.