Adversarial Content

— Browse our blog posts, articles, and episodes of The Adversarial Podcast

The Adversarial Podcast S4E23 – AI Agents Escape the Lab

Podcast

S4E23 – AI Agents Escape the Lab, Anubis Hits Fair | RSS.com Chapters 00:00 Introduction to AI security challenges 02:05 Recent hacking incidents involving Hugging Face and Anthropic 04:01 How AI models find ways to cheat and bypass constraints 05:56 The challenge of containment and governance in AI safety 08:00 Lessons from recent AI security breaches 10:01 The role of human oversight in AI security testing 12:03 Cost and effectiveness of offensive AI security measures 13:54 Implic

"Hugging Face yourself" to find your security program's tokens-to-compromise

AI

There's no need to reprise the Hugging Face incident. The press has the narrative, and Hugging Face published an excellent technical timeline. OpenAI models running with their guardrails deliberately lowered for a cybersecurity capability evaluation broke out of their sandbox, reached the open Internet, and hacked Hugging Face to steal the answers to their own test. The only detail that really needs to be clarified for those of you of my age is that "Hugging Face" is a successful startup valued

The Adversarial Podcast Ep. 24 – Global Lumma takedown, Coinbase employee bribed, malicious MCP integrations and NPM packages

Podcast

Adversarial Podcast Ep. 24 – Global Lumma takedown | RSS.com 00:00 Intro 02:49 Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals 14:29 Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom 26:24 Fake OpenAI MCP Integration 32:25 Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials 36:03 Destructive malware available in NPM repo went unnoticed for 2 years 48:10 Sam & Jony

The Adversarial Podcast Ep. 19 – AI-Powered Cybercrime, CISO job market, the BYOL elephant in the room

Podcast

The Adversarial Podcast Ep. 19 – AI-Powered Cybercrime, CISO job market, the BYOL elephant in the room Episode notes ⬇️ See below for timestamps/summaries/references for each topic 00:00 Highlight/theme 00:37 Intro 01:37 Malvertising campaign leads to info stealers hosted on GitHub 11:59 Wall Street is worried it can't keep up with AI-powered cybercriminals 24:02 What Really Happened With the DDoS Attacks That Took Down X 28:34 Bring-your-own-laptop policies 40:41 Are WAFs useful or

The Adversarial Podcast Ep. 18 - CISA cuts, North Koreans steal $1.5B in crypto, planning for RSA Conference

Podcast

The Adversarial Podcast Ep. 18 - CISA cuts, North Koreans steal $1.5B in crypto, planning for RSA Conference 💰 Budget cuts hit CISA, and election security programs might be first on the chopping block. The team debates whether these cuts were expected, what they mean for cybersecurity, and whether some programs were outside CISA’s core mission in the first place. Reference: https://www.scworld.com/perspective/a-sober-look-at-the-recent-cuts-at-cisa ⚔️ A sudden shift in cyber warfare stra

The Adversarial Podcast Ep. 8 - Pagers and Supply Chain Attacks, GitHub stealers, “Founder Mode”

Podcast

(00:00) Intro (02:24) Exploding pagers: are psychological attacks worse than breaches? (20:21) Are credit card breaches still a concern in 2024? (24:57) Infostealer delivered through GitHub Issues: how are trustworthy services being abused? (31:45) Founder mode: when is it time to switch from "founder mode" to "manager mode?" (44:02) Is open-source more secure than closed-source? The Adversarial Podcast Ep. 8 - Pagers and Supply | RSS.com Stories and books mentioned: * “Israel plant

The Adversarial Podcast Ep. 6 - SSN Leaks, Cloud Misconfigurations, and Passkeys

Podcast

Episode notes Join former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu as they debate the impact of SSN leaks, discuss the effectiveness of recently implemented ransom payment bans in Miami, and recently reported AWS misconfigurations. Then, listen as they debate passkeys, vulnerability management, and board reporting. The Adversarial Podcast Ep. 6 - SSN Leaks, Cloud M | RSS.com 00:00 Intro 02:17 Social Security Number breach 14:48 Ransomware payment bans 21:47 AWS

The Adversarial Podcast Ep. 4 - CrowdStrike Lawsuits, Overhyped Exploits, and Fake Remote Employees

Podcast

Episode notes Join former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu as they discuss upcoming lawsuits related to the recent CrowdStrike outage, switching costs, overhyped security vulnerabilities and their effect on practitioners' responsibilities, fake employees from North Korea, the information stealers and the state of password managers, and the increasing threat of deepfakes. The Adversarial Podcast Ep. 4 - CrowdStrike Lawsui | RSS.com Stories * “CrowdStrike i

The Adversarial Podcast Ep. 3 - CrowdStrike, Wiz Acquisition Rumors, and SolarWinds

Podcast

Episode notes In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss the recent Crowdstrike outages, PR in the recent Wiz acquisition rumors, stakeholder value in Rapid7, and the SEC dropping charges in the SolarWinds case. Stories: - Activist Jana has a stake in Rapid7. There are two paths to bolster value at the cybersecurity company: https://www.cnbc.com/2024/06/29/two-paths-for-jana-to-bolster-shareholder-value-at-rapid7.html - Google Near $23

The Adversarial Podcast Ep. 2 - Chrome Extension Vulns, Cyber Job Market, Mouse Jigglers, and the Ransomware Plague

Podcast

Episode notes In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss malicious Chrome extensions, the cybersecurity job market, mouse jigglers and security policy, and the impact of the recent ransomware wave. They share insights from their experiences, exploring the challenges of managing browser security policies, job burnout, and banning ransom payments. Stories: * Millions under threat from malicious browser extensions — what to do: https://www.t

The Adversarial Podcast Ep. 1 - Snowflake, Shared Fate, and the Gili Ra’anan Model

Podcast

In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss the recent wave of cyber-attacks using Snowflake and the model of shared fate. They debate the effectiveness of banning ransom payments and explore the complexities of cybersecurity regulation, using recent events involving UnitedHealth and Jerry's former employer as case studies. The conversation also touches on the ethical dilemmas CISOs face when interacting with venture capital, highlighting pers

Cyber Governance: What is Fair to Expect from Board Directors and Management? 3 of 4

Governance

Episode 3: Incidents In Episode 1 of this series I talked about oversight of cybersecurity threats and how a Board can engage with senior management to determine the mission of the cybersecurity department and prioritize testing and analysis. Next I moved on to cyber risks in Episode 2 and the idea of a Remediation Agility chart to guide a wide-ranging Board room discussion with a single visual. The next area that deserves a permanent spot on the Board agenda is incidents. Incident awareness a

Overrated? On TPRM, SBOM, Solarwinds, and Supply Chain Security

Architecture

We've all run to the same side of the boat on supply chain security when it comes to cyber. Rather than chasing the Sisyphean (and antithetical to modern product-development philosophy) task of ensuring our suppliers deliver perfectly secure software, we should be expected to architect and deploy our dependencies with the assumption they will be compromised at some point, minimizing the amount of impact that could have and ensuring we could detect such an issue timely. To expound on it, I'll sa

The value of the True Positive

CyberOps

As originally published on Vectra's Unfiltered at https://www.unfilteredcxo.com/ Cybersecurity is afflicted with the duty of “proving a negative” all the way up to the Board room. We can learn some tricks from incident response and threat intelligence to tackle the art of distinguishing the lucky from the good. When it comes to incident response, it is challenging – but essential – to define criteria for closing an investigation. Enter the true positive. When someone says that they did not see