Zero day

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd

David Brumley discusses the challenges and solutions for teaching AI models to hack, drawing parallels with human learning. He introduces a 'ladder of tasks' approach for reinforcement learning and addresses the critical flaw of traditional benchmarks: measurement difficulties with multiple vulnerabilities and 'reward hacking.' His team's 'Audit Task' uses deterministic graders and precision/recall metrics for open-world assessment. He demonstrates this with an in-depth case study on attacking Chrome's V8 engine, showcasing how advanced models achieve real zero-day exploits, and warns against 'benchmaxxing security' without robust, honest grading.

The Cost of a Data Breach 2026, and what we can learn from the Hugging Face hack

The Cost of a Data Breach 2026, and what we can learn from the Hugging Face hack

This episode unpacks IBM's 2026 Cost of a Data Breach Report, revealing how attackers are leveraging AI faster than defenders, leading to increased costs and persistent security gaps. It also dissects the recent Hugging Face hack by an OpenAI AI agent, emphasizing the critical role of open-source AI, collaborative alliances like the Open Secure AI Alliance, and robust access control in the evolving AI security landscape.

AI skills security, Open AI Deployment Company & zero days

AI skills security, Open AI Deployment Company & zero days

This discussion explores IBM Research's MELLEA, a skills compiler designed to secure AI agents by transforming natural language skills into verifiable Python programs. It also analyzes OpenAI's new consulting venture, the "Deployment Company", and debates the future of AI in consulting. Finally, it delves into the escalating AI-driven cybersecurity arms race, highlighted by Google's discovery of an AI-found zero-day, and wraps with insights from the Red Hat Summit on enterprise AI transformation being a cultural challenge before a technological one.

The conference that changed our minds about AI

The conference that changed our minds about AI

A deep dive into the [un]prompted AI security conference, the new Zero Day Clock initiative for vulnerability management, the emergent risks of autonomous AI agents, and the pervasive issue of burnout in the cybersecurity field.