61 episodios
- Is the AI "vulnpocalypse" already here? According to Casey Ellis, Founder of Bugcrowd and pioneer of Disclose.io, we aren't quite in an apocalypse yet, we're actually in a "slopdemic." The cost of discovering vulnerabilities has plummeted, flooding bug bounty and SOC triage queues with low-quality, noisy submissions. Because these queues are so overwhelmed, many highly skilled researchers are simply hoarding zero-days because reporting them has become too difficult.
In this episode, Ashish sits down with Casey to unpack the major themes and mindset shifts from RSA and Black Hat 2026. Casey breaks down how AI is shrinking the OODA loop for defenders, forcing the industry to adopt a true "assume breach" mentality and reconsider deception technology to frustrate active adversaries. They also explore the risks of non-technical employees "vibe coding" corporate applications and why CISOs must get hands-on with AI tools at home if they want to understand the risks their workforce is taking.
Questions asked:
(00:00) Introduction to Offensive AI and Black Hat 2026(02:00) Casey Ellis’s Background (Bugcrowd, Disclose.io)(04:00) Major Themes from RSA and Black Hat 2026(09:00) The Impact of Mythos and Daybreak on Security Awareness(12:30) Why Threat Researchers Are Hoarding Zero-Days(14:00) The "Slopdemic" vs. The "Vulnpocalypse"(17:30) Managing Noisy Bug Bounty Queues and Risk Models(20:00) The Futility of Export Controls on Frontier Models(25:00) Point-and-Pwn vs. Building Complex Attack Graphs(29:30) The Defender’s Dilemma and the Shrinking OODA Loop(34:00) Shadow AI and the Risks of Non-Technical "Vibe Coding"(38:30) Why CISOs Need Hands-On Experience with AI Tools(45:30) The Resurgence of Deception Technology
Resources spoken about during the episode:
Casey's Blog Why Prompt Filters Fail & How to Explain AI Risk to the Board | Cezary Piekarski, Standard Chartered.
02/09/2026 | 37 minIs the cybersecurity industry repeating the same mistakes with prompt injection that it made with buffer overflows decades ago? As attackers iterate through 50 to 60 prompt filter bypasses daily, attempting to artificially separate instruction from data is becoming a futile effort. In this episode, Ashish sits down with Cezary Piekarski, Group CISO of Standard Chartered. Cezary shares his techno-optimist view on how AI will ultimately benefit defenders, while also unpacking the hard realities of securing an enterprise that ingests 50-plus terabytes of observable data every single day. He explains why reactive security operations are dead, why User Behavior Analytics (UBA) often fails at scale due to stochastic human behavior, and why deception technology must be built directly into your ecosystem to actually work. Cezary shares his thoughts on executive communication, detailing a proven three-step framework for explaining complex AI risks to a board of directors without relying on fear-mongering. Finally, we explore why the tension between AI data hunger and user privacy is largely a "fake dilemma" for security teams.
Questions asked:
(00:00) Introduction: The Futility of Prompt Filters & AI Attack Evolutions(02:30) Cezary Piekarski’s Background and Role at Standard Chartered(03:30) What "Security as a Business Enabler" Actually Means(06:30) The Techno-Optimist View of AI in Cybersecurity(08:50) Why Reactive Security and Manual Triage Are Dead at 50TB/Day(11:30) Doing Deception Technology Right (No More "Surplus Bug" Buying)(15:20) The Flaws of UBA and Behavioral Anomaly Detection(22:30) The Buffer Overflow Analogy: Why Prompt Injection Needs an Architectural Fix(27:30) Under-Discussed Threats: Image-Based Prompt Injection & Data Poisoning(30:00) A 3-Step Masterclass for Explaining AI Risk to the Board(34:30) Why the AI Privacy vs. Security Debate is a "Fake Dilemma"
Resources spoken about during the episode:
Cyber security and fraud safety | Standard CharteredWhy 95% of AI Projects Fail: Model Risk & AI Governance | Sandip Wadje, BNP Paribas
27/08/2026 | 45 minWhy do 95% of enterprise AI implementations fail? According to Sandip Wadje, Managing Director at BNP Paribas, many organizations attempt complex reasoning tasks on day one rather than building a mature foundation around data hygiene and simple summarization workflows. In this episode, Ashish sits down with Sandip to explore how global financial institutions navigate Model Risk Management (MRM), GenAI governance, and regulatory expectations across regions like the UK, EU, and US. Sandip breaks down why classical 20-year-old MRM frameworks fall short when applied to non-deterministic black-box LLMs, and why security leaders must focus on output drift and event taxonomies rather than just input prompt filtering. We also examine the concept of the "AI Kitchen" - a cross-functional governance model bringing together IT, CISOs, legal, and Data Protection Officers alongside practical strategies for calculating AI blast radius, cleaning up overprivileged non-human identity (NHI) permissions, and training CSIRT teams for ML SecOps incidents.
Questions asked:
(00:00) Introduction: AI Risk in Regulated Financial Institutions(01:50) Sandip Wadje’s Background at BNP Paribas(02:50) Classical Model Risk Management (MRM) vs. Generative AI(04:40) Governing the Black Box: Finding the Security Delta(08:00) The CMDB Problem: Building an Accurate AI Use Case Inventory(11:30) Why 95% of AI Projects Fail: Summarize, Write, Reason(15:00) Continuous Evaluation (Evals) and Catching Output Drift(18:50) Event Taxonomy: What Happens When AI Decisions Drift?(25:40) Training CSIRT and SOC Teams for ML SecOps Incidents(30:00) Compensating Controls: Remote Browser Isolation & Prompt Monitoring(34:30) Non-Human Identities (NHI) & Cleaning Birthright Permissions(36:30) Balancing a $1M Savings Against a 4% Revenue Fine(38:30) Open-Weight Models vs. Frontier LLMs in Financial Services(41:00) The "AI Kitchen": Cross-Functional AI Governance(44:30) The #1 Rule for AI Security: Understand Your Data First- With over 200 AI security vendors in the market, how does an enterprise CISO decide whether to build a custom solution, buy an off-the-shelf product, or just wait out the hype?
In this episode of the AI Security Podcast, Ashish and Caleb are joined by Kane Narraway, Head of Enterprise Security at Canva, to debate the realities of AI security in modern enterprises. Kane breaks down why simply sandboxing AI agents doesn't work for workforce productivity, explaining that an overly restrictive sandbox renders an agent useless because it inherently needs access to external files and databases to do its job.
We dive deep into the "Confused Deputy" problem, the struggle of granting granular least privilege to AI tools (like letting a bot summarize only Caleb's emails), and whether the old-school concept of network proxies is about to make a massive comeback as the ultimate control layer for AI routing and authorization. Finally, Kane shares why he believes the scariest near-future threat isn't malware, but contractors utilizing "Bring Your Own Agent" (BYOA) in enterprise environments.
Questions asked:
(00:00) Introduction to AI Agents in the Enterprise(01:50) Kane Narraway’s Background (Digital Forensics, Atlassian, Shopify, Canva)(02:50) The Build vs. Buy Debate in the Era of 200+ AI Security Vendors(09:00) Using Wrappers and Harnesses to Control Vendor APIs (Island Browser Example)(11:00) Why GitOps and PRs are Better for AI Configuration than MCP Deployments(13:00) The "Confused Deputy" Problem: Single-Player vs. Multi-Player AI Bots(16:50) How to Handle Agent Identity: "On Behalf Of" (OBO) vs. SPIFFE / NHI(22:50) Why Sandboxing AI Agents Fails for the General Workforce(28:20) Intent-Based Security and the Lack of Granular Access Controls(29:40) Are Proxies the Next Gen Firewall for AI Agents?(34:00) The Terrifying Future of "Bring Your Own Agent" (BYOA)(38:50) The "Gravel Road" Strategy for Managing Shadow IT and Vibe Coding(42:00) Dealing with Vendors Trying to Exploit Shadow IT Land Grabs(49:30) What Security Leaders are Over-Indexing On (Discovery vs. True Access)(50:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge - When AI agents start swarming your enterprise, they won't care about stealth. They will land a beachhead and instantly spawn 500 agents to crawl, probe, and exfiltrate data at machine speed. Is your detection stack ready?
In this episode, Ashish and Caleb sit down with Andy Smith, CEO and co-founder of Tracebit, to completely rethink Deception Technology for the AI era. Forget the heavy, noisy "honeypots" of the 90s. We discuss the modern implementation of deception: lightweight, high-fidelity canary tokens (like fake AWS keys, Chrome cookies, and database tables) that act as guaranteed tripwires the moment an attacker, human or AI, assumes a breach.
Andy shares new research on how you can actively weaponize an AI model's own safety guardrails against it. By embedding specific, controversial text strings (like references to biological warfare or sensitive political events) into decoy secrets.
Questions asked:
(00:00) Introduction to AI Deception(02:30) Andy Smith’s Background and the Founding of Tracebit(03:40) Deception 101: Honeypots vs. Canary Tokens(07:20) The "Assume Breach" Philosophy of Deception(10:00) Why CISOs Default to SIEMs over Quick Deception Wins(13:20) The Psychological Deterrent of Deception on Red Teams(15:10) Setting Up a Database Tripwire (Real-World Example)(17:40) Internal AI Threats: Catching Claude Code in a Production Kubernetes Pod(20:00) Why Deception Fails: The Lack of Strategy and Deployment Complexity(26:30) Using Cloud Serverless (S3/Terraform) to Deploy Deception for Free(28:00) Modern Lateral Movement: Chrome Cookies and Browser History Canaries(41:20) The Future of Attacks: Armies of Fast, Noisy AI Agents(44:50) Weaponizing AI Guardrails to Shut Down Attack Agents(48:20) Where to Start with Your Deception Strategy Today
Resources spoken about during the episode:
- Tracebit Research - Deception warns your teams at the speed of an AI attacker
Más podcasts de Tecnología
Podcasts a la moda de Tecnología
Acerca de AI Security Podcast
The #1 source for AI Security insights for CISOs and cybersecurity leaders.
Hosted by two former CISOs, the AI Security Podcast provides expert, no-fluff discussions on the security of AI systems and the use of AI in Cybersecurity. Whether you're a CISO, security architect, engineer, or cyber leader, you'll find practical strategies, emerging risk analysis, and real-world implementations without the marketing noise.
These conversations are helping cybersecurity leaders make informed decisions and lead with confidence in the age of AI.
Sitio web del podcastEscucha AI Security Podcast, Apple Events y muchos más podcasts de todo el mundo con la aplicación de radio.es

Descarga la app gratuita: radio.es
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.es
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


AI Security Podcast
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.
AI Security Podcast: Podcasts del grupo



































