Software supply chain

Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

This podcast explores the critical role of safeguards in frontier AI models like Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol, analyzing the tension between powerful capabilities and misuse prevention. It also dissects the emergence and debate around agentic ransomware, specifically Jade Puffer, and covers the rise of ClickFix as a dominant social engineering attack targeting developers. Finally, it provides an in-depth analysis of UnregStealer, a credential-theft campaign impacting Latin American financial institutions, detailing its attack chain and mitigation strategies.

State of the Art of Container Security • Adrian Mouat & Charles Humble

State of the Art of Container Security • Adrian Mouat & Charles Humble

Adrian Mouat of Chainguard delves into container security, highlighting the flaws of traditional Linux distributions in modern, immutable environments. He explains Chainguard's approach of using 'distroless' images built from source with their Wolfi OS to achieve near-zero CVEs. The discussion covers the importance of replacing rather than updating containers, the roles of SBOMs and attestations, and key lessons from major supply chain attacks like the XZ Utils backdoor.