Player FM - Internet Radio Done Right
Checked 4d ago
Aggiunto due anni fa
Contenuto fornito da Safe Mode Podcast. Tutti i contenuti dei podcast, inclusi episodi, grafica e descrizioni dei podcast, vengono caricati e forniti direttamente da Safe Mode Podcast o dal partner della piattaforma podcast. Se ritieni che qualcuno stia utilizzando la tua opera protetta da copyright senza la tua autorizzazione, puoi seguire la procedura descritta qui https://it.player.fm/legal.
Player FM - App Podcast
Vai offline con l'app Player FM !
Vai offline con l'app Player FM !
Rumman Chowdhury on AI red-teaming; a Sisense supply chain attack
Manage episode 413053486 series 3499462
Contenuto fornito da Safe Mode Podcast. Tutti i contenuti dei podcast, inclusi episodi, grafica e descrizioni dei podcast, vengono caricati e forniti direttamente da Safe Mode Podcast o dal partner della piattaforma podcast. Se ritieni che qualcuno stia utilizzando la tua opera protetta da copyright senza la tua autorizzazione, puoi seguire la procedura descritta qui https://it.player.fm/legal.
At last August’s DEF CON computer security conference, more than 2,000 people tried their hands at breaking some of the world’s most advanced AI models. That event was the largest-ever public red-teaming event of large language models, and since then policymakers are continuing to look to red-teaming as a key tool in responsibly deploying AI systems. The data scientist Rumman Chowdhury was one of the organizers of the Generative AI Red Teaming Challenge at DEF CON, and on this episode of Safe Mode she sits down with host Elias Groll to discuss the lessons of that event. CyberScoop reporter AJ Vicens also joins the show to discuss a potentially severe supply chain attack involving the business analytics firm Sisense.
…
continue reading
85 episodi
Manage episode 413053486 series 3499462
Contenuto fornito da Safe Mode Podcast. Tutti i contenuti dei podcast, inclusi episodi, grafica e descrizioni dei podcast, vengono caricati e forniti direttamente da Safe Mode Podcast o dal partner della piattaforma podcast. Se ritieni che qualcuno stia utilizzando la tua opera protetta da copyright senza la tua autorizzazione, puoi seguire la procedura descritta qui https://it.player.fm/legal.
At last August’s DEF CON computer security conference, more than 2,000 people tried their hands at breaking some of the world’s most advanced AI models. That event was the largest-ever public red-teaming event of large language models, and since then policymakers are continuing to look to red-teaming as a key tool in responsibly deploying AI systems. The data scientist Rumman Chowdhury was one of the organizers of the Generative AI Red Teaming Challenge at DEF CON, and on this episode of Safe Mode she sits down with host Elias Groll to discuss the lessons of that event. CyberScoop reporter AJ Vicens also joins the show to discuss a potentially severe supply chain attack involving the business analytics firm Sisense.
…
continue reading
85 episodi
All episodes
×On this episode of Safe Mode, Greg talks with Alex Pinto, Associate Director of Threat Intelligence at Verizon Business, as we unpack the key findings from this year’s Data Breach Investigations Report (DBIR). Pinto offers expert analysis on the most pressing cybersecurity trends impacting organizations worldwide—including ransomware’s dramatic spike, shifting attacker tactics, and evolving victim responses. We explore why ransomware now features in 44% of breaches, what’s driving a surge in exploited vulnerabilities and zero-day attacks on edge devices, and why small and mid-sized businesses are seeing more frequent and devastating impacts. Pinto sheds light on the motivations behind declining ransom payments, the rise of third-party risks, and the complex challenge of timely patching and remediation. In our reporter chat, Greg talks with Derek Johnson on one company’s security testing of OpenAI’s newest GPT model.…
In this episode, Greg talks with Will Pearce, CEO and Co-founder of Dreadnode about the rapidly evolving field of offensive AI security. Greg and Will discuss the unique challenges researchers face in testing AI models for vulnerabilities compared to traditional software, unveiling how adversarial attacks impact AI security and the ethical considerations at play. We also examine the role of regulatory frameworks and emerging threats, shedding light on how insights from offensive AI security can enhance human-AI interactions and elevate security standards across industries. In our reporter chat, Greg talks with Matt Kapko on Ivanti’s issues with security in their network edge devices.…
In this episode, Greg talks with Lior Div, co-founder and CEO of 7AI. Lior and Greg explore how security teams are being reinforced with AI Agents and identify the areas where CISO are embracing this technological shift to optimize their talent resources. We'll also discuss the specific security functions these agents are performing, including email security, threat hunting, and other critical cybersecurity domains. Join us as we delve into the future of AI-augmented cybersecurity teams and the potential impact on the industry's ongoing battle against sophisticated cyber threats. In our reporter chat, Greg talks with Derek Johnson about Google’s experimental LLM made for cybersecurity analysts.…
S
Safe Mode Podcast

1 Ken Bagnall on how companies can work with governments to take down malicious infrastructure 32:38
In this episode, Greg Otto talks with Ken Bagnall, CEO of Silent Push Ken sheds light on the dynamics of the current cybercrime ecosystem. Ken reveals that a significant portion of the infrastructure is actually operated by affiliate networks using pre-existing technologies. During the discussion, Ken elaborates on how this ecosystem is fueled and examines the influential role played by affiliate groups, particularly those emerging from Africa and other developing countries. By offering these insights, the episode provides a fresh perspective on the often-overlooked aspects of global cybercrime operations. In our reporter chat, Greg talks with Matt Kapko about the growing problem with remote IT workers from North Korea.…
In this episode, Greg Otto talks with Edera co-founder and CTO Alex Zenla, charting her path from beginnings in Minecraft IRC channels to pioneering container isolation technology. Alex discusses her unique expertise in container security, GPU protection, and AI infrastructure, and how Edera is transforming the tech landscape with a commitment to balancing open-source benefits with robust security, setting new standards for cloud security's future. In our reporter chat, Greg talks with Derek B. Johnson about a controversial executive order from Donald Trump that upends the way elections could be conducted in the future.…
S
Safe Mode Podcast

In this episode, Greg Otto talks with FTI Consulting’s Allie Bohan exploring the challenges organizations face in maintaining effective communication during cyberattacks. Allie and Greg uncover essential strategies for incidents, ensuring companies remain connected with stakeholders even when digital channels are compromised. We also talk on how to keep morale boosted within an organization during a time that many would consider one of the worst chapters in a business’s history. In our reporter chat, Greg talks with Matt Kapko about who is sending those massively annoying scam text messages about unpaid toll violations.…
In this episode, Greg Otto talks with Sunil Mallik, the CISO of Discover Financial Services. Sunil shares his career path and the evolving challenges and responsibilities in cybersecurity, covering how he communicates with his board, strategic approaches to cybersecurity, and the importance of balancing technological investment with personnel training. In our reporter chat, Greg talks with Tim Starks about Sean Plankey being nominated for CISA director. Editor's Note: At 13:42, Mallik misspoke about his former employer. He was previously employed by Freddie Mac, not Fannie Mae.…
S
Safe Mode Podcast

In this episode, Greg Otto talks with Dan Lorenc, CEO and co-founder of Chainguard. They explore the challenges organizations face with CVE management, where dealing with vulnerabilities often drains valuable engineering resources. They also discuss how new visualization tools are redefining this landscape by offering clear insights into CVE trends, empowering teams to make informed decisions and optimize both security and efficiency in their software development processes. In our reporter chat, Greg talks with Matt Kapko about the United States’ indictment of China-linked hackers.…
S
Safe Mode Podcast

In this episode, Greg Otto talks with Virtru Co-founder and CEO John Ackerly , discussing the significance of open standards, the challenges and successes of implementing the Trusted Data Format across federal agencies, and the critical role of interoperability and compliance. John also gives us details on how close the country was to a national privacy law before the 9/11 attacks upended everything In our reporter chat, Greg talks with CyberScoop Tim Starks about a flurry of news around the Department of Homeland Security.…
In this episode, you will hear Cynthia Kaiser, deputy assistant director in the bureau’s cyber division talk about the implications of the Salt Typhoon breach, which she spoke about during CyberScoop’s Zero Trust Summit. Kaiser characterized the breach as “a different level of insidiousness” from Beijing, one that reflects its “ambition and reckless aggression in cyberspace.” In our reporter chat, Greg talks with CyberScoop’s new cybercrime reporter Matt Kapko about a slew of reports around Russian nation-state cyber actors.…
Greg Otto talks with Jackie Burns-Koven, Head of Cyber Threat Intelligence at Chainalysis. They discuss research from Chainalysis that shows a 35% drop in ransom payments over the second half of 2024. They also discuss the growing refusal of victims to pay ransoms and how attackers are adapting their tactics. Additionally, she highlights the influence of Ransomware-as-a-Service, the evolution of data leak sites, and the effectiveness of international collaboration in combating these cyber threats. In our reporter chat, Greg talks with Tim Starks about the Trump administration’s nominee for national cyber director.…
Greg Otto talks with John Hultquist, Chief Analyst for Google Threat Intelligence Group. They explore the qualitative differences between AI-generated and human-crafted social engineering tactics, and discuss the technical limitations of AI when used by less sophisticated threat actors like those in North Korea. Additionally, the episode addresses the challenges posed by AI in cybersecurity, including how it accelerates attacks, the need for enhanced defense systems beyond current SOAR/XDR models, and a proposed roadmap for maturing autonomous AI frameworks in the coming years. In our reporter chat, Greg talks to Derek B. Johnson on the ongoing friction between Elon Musk, DOGE, and the federal government. . LINK: https://cyberscoop.com/musk-doge-opm-treasury-breach/…
S
Safe Mode Podcast

1 Hugh Thompson on what the SEC got right (and wrong) with its cyber incident reporting mandate 43:16
Greg Otto talks with Hugh Thompson, Executive Chairman for RSAC Conference. Greg and Hugh discuss how the SEC's cyber disclosure regulations have fallen short of their intended purpose, failing to provide investors with enhanced transparency due to ongoing debates about materiality and insufficient market consequences. Additionally, they discuss the evolving regulatory landscape for 2025 and recent efforts to strengthen border gateway protocol (BGP) security. In our reporter chat, Greg talks to Derek B. Johnson on DeepSeek’s newfound fame and its time in the security spotlight.…
Greg Otto talks with Exabeam’s Gabrielle Hempel about the complex terrain of AI regulation at both the federal and state levels, offering a deep dive into the legislative challenges, and the balancing act of fostering innovation while protecting public interests. They also reflect on how public interaction with AI systems is shaping legislative efforts, aiming to provide a comprehensive exploration of the regulatory landscape and its implications for businesses. In our reporter chat, Greg talks to Tim Starks about a Congressional hearing that examined DHS’s elimination of the entire Cyber Safety Review Board’s roster. LINK: https://cyberscoop.com/removal-cyber-safety-review-board-members/…
S
Safe Mode Podcast

1 Guidepoint Security’s Jason Baker on lessons learned from negotiations with ransomware groups 51:58
As we head into 2025, Greg talks with Jason Baker, a ransomware negotiator for Guidepoint Security, on how ransomware has shifted and evolved, and the challenges it poses for businesses and governments alike. Jason also sheds light on the top threat actors, the future of international regulations and where they might fall concerning the contentious issue of paying ransoms, and what businesses can do to limit the damage if they are ever attacked. In our reporter chat, Greg talks to Tim Starks about the conversations happening in Washington, D.C. regarding enhanced offensive cybersecurity operations. LINK: https://cyberscoop.com/aggressive-cyber-offense-trump-administration-us-strategy-debate/…
Benvenuto su Player FM!
Player FM ricerca sul web podcast di alta qualità che tu possa goderti adesso. È la migliore app di podcast e funziona su Android, iPhone e web. Registrati per sincronizzare le iscrizioni su tutti i tuoi dispositivi.