@CloudSecPodi
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Award Winning Top 10 Ranked CyberSecurity Podcast in US,UK and Aus. Learn Cloud Security in Public Cloud the unbiased way from CyberSecurity Host: @hashishrajan
London, UK
Joined February 2019
- Tweets1.3K
- Following1
- Followers3.7K
- Likes738
Fake job candidates get the attention. The harder case never applies.
Threat actors pose on LinkedIn as staff at defence companies, then work real employees for information. Hiring checks never see it.
@adylon7 from Outtake with Ashish on @CloudSecPod
An AI agent in your environment has no identity of its own. It acts on behalf of a person, sometimes using that person's human identity.
Ido Shlomo from @TheTokenSec spoke to Ashish on @CloudSecPod. First question in any agent review: whose access is it carrying?
We're on track for more than 66,000 CVEs this year. About 1% are zero days, critical, or exploited in the wild, and that share has held flat.
That's six or seven hundred to act on.
Johnny Hands on the CVE panic, with Ashish.
@trendaisecurity
Most teams started AI security at the browser.
The problem: AI desktop apps and messaging apps use certificate pinning. If you don't manage the app, you can't see the traffic.
Nati Hazut on why security tools can't see AI.
Tell a user no and they find a way around it. The incentive to use AI is too strong.
One customer was sure they had 8 sanctioned AI tools. An assessment found 243.
Michael Leland from @island_io on why the answer to shadow AI is yes, done safely.
The AI offers a better answer. It just needs access to Slack first. The user clicks yes, and a data path now exists that nobody reviewed.
One GitHub repo held 7,600 AI skills. Over 800 were malicious.
Michael Leland from @island_io on Cloud Security Podcast.
One email with a fake system prompt and a code word. The out-of-office copilot read it, believed it, and replied with the entire inbox.
Steve Giguere on why agents do exactly what they're told, including by their data. New Cloud Security Podcast episode this week.
Attackers had a working exploit 7 days before the CVE was published. Add the 28 days most orgs take to remediate and the window is open for over a month.
Rich Seiersen (@qualys ) on why the deadline moved and what a 24-hour target actually buys you.
Tell a coding agent to be secure and it will still ship the insecure version when the two conflict. Working code is the job. Security is the second goal.
Sarit Tager (@PaloAltoNtwks ) with Ashish on @CloudSecPod.
An agent that hits a wall does not stop. It finds another way, including pulling an untrusted NPM package to finish the task.
Nobody onboarded these agents. No training, no policy, just a click.
Michael Leland from @island_io on the Cloud Security Podcast. Follow @CloudSecPod.
A person doing something they should not usually gives up after three tries. An agent never does.
Sarit Tager (@PaloAltoNtwks ) with Ashish on what coding agents do when nobody has told them what not to do.
An attacker listened for an AI agent's Git commit, then fired a near-identical one seconds behind. Same message, malicious code inside.
The @Lovable team caught it and found every technique had been tested in the group's own projects before touching a customer.
"I can almost guarantee if you're not locking your environment down, you are absolutely running unsanctioned AI software."
Brandon Dixon on why banning AI outright fails, and ignoring it fails harder.
Full clip on the channel. @Ent_Security
Everyone is asking how ready they are for something like Mythos.
CISOs and practitoners who has used it inside the Glasswing Project says readiness comes down to one question: how fast do you close what is already on the KEV?
@trendaisecurity
In 2018, exploiting a new vulnerability took around 270 days.
Now it's hours, sometimes minutes. Derek Abdine of Furl joins Ashish Rajan on rebuilding the fixing side of vulnerability management for that timeline.
Follow @CloudSecPod for the episode.
Writing the detection was never the hard part.
AI can hand you a thousand in a day and cover every MITRE ATT&CK technique. Knowing whether they fire on your environment's real behaviour is the job.
Nicole Beckwith, @cribl_io on Cloud Security Podcast.
#detectionengineering
AI coding agents hallucinate package names. Reliably. Attackers now publish malware under the names agents invent, then wait for the download.
David Gibson (@varonis) on which agentic threats are real and which are amplified.
Follow @CloudSecPod for the full conversation.
The industry started AI security at the prompt. Emily Heath thinks that is over-indexed, an old DLP problem in a new place.
The real exposure is what AI tools quietly install on endpoints in the background.
New episode of Cloud Security Podcast. @glowsecurity_ai
An Okta token gets used. It logs into a MacBook. The MacBook opens the AWS CLI. No alert fires, because no single step is bad. Together, an active intrusion.
Damien Lewke @nebulocksec on hunting the signals alerts never surface.
Follow @CloudSecPod for the full conversation.
"Don't tell me you've solved this problem because I didn't even have this problem like three months ago."
Brandon Dixon (@Ent_Security ) on why "solved" is the clearest warning sign in AI security right now.