『AI Security Ops』のカバーアート

AI Security Ops

AI Security Ops

著者: Black Hills Information Security
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
Join in on weekly podcasts that aim to illuminate how AI transforms cybersecurity—exploring emerging threats, tools, and trends—while equipping viewers with knowledge they can use practically (e.g., for secure coding or business risk mitigation).© 2025 Black Hills Information Security 政治・政府
エピソード
  • OWASP Agentic Top 10 [Part 1] | Episode 70
    2026/09/21

    In this episode of BHIS Presents: AI Security Ops, the team breaks down the first five risks in the OWASP Agentic Skills Top 10 (Part 1).

    Agentic skills can give AI systems reusable instructions, workflows, and capabilities — but they also introduce a new attack surface. A skill may look like a simple markdown file, yet the agent following those instructions could have access to your filesystem, credentials, network, shell, or other sensitive resources.

    We dig into:
    - AST01: Malicious Skills
    - AST02: Supply Chain Compromise
    - AST03: Overprivileged Skills
    - AST04: Insecure Metadata
    - AST05: Untrusted External Instructions
    - Why skills should be treated more like software than configuration
    - How excessive permissions increase an agent’s blast radius
    - Why external content creates indirect prompt injection risks
    - How isolation, least privilege, and trusted sources can reduce risk

    The takeaway: “just markdown” isn’t necessarily harmless when an AI agent can act on what it reads.

    This is Part 1 of our look at the OWASP Agentic Skills Top 10, covering AST01 through AST05.

    —

    Learn more about Black Hills Information Security:
    https://www.blackhillsinfosec.com/

    Check out Antisyphon Training:
    https://www.antisyphontraining.com/

    • (00:00) - Intro: OWASP Agentic Skills Top 10, Part 1
    • (01:59) - AST01: Malicious Skills
    • (06:13) - AST02: Supply Chain Compromise
    • (09:37) - AST03: Overprivileged Skills
    • (13:56) - AST04: Insecure Metadata
    • (16:34) - AST05: Untrusted External Instructions
    • (22:36) - Final Takeaways and Part 2 Preview

    Click here to watch this episode on YouTube.

    Creators & Guests
    • Brian Fehrman - Host
    • Derek Banks - Host

    Brought to you by:

    Black Hills Information Security

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
    https://poweredbybhis.com

    Click here to view the episode transcript.

    続きを読む 一部表示
    23 分
  • Agentic Skills | Episode 69
    2026/09/14

    Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments.

    Links:
    OWASP Agentic Skills Top 10
    Malicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents

    • (00:00) - Agentic Skills and the OWASP Top 10
    • (00:23) - Podcast Sponsors: BHIS and Antisyphon Training
    • (01:29) - What Is an Agentic Skill?
    • (03:13) - Skill Marketplaces and Widespread Adoption
    • (03:46) - Why Malicious Skills Are the #1 Risk
    • (05:50) - Remote Payloads and External Instructions
    • (07:00) - Malicious Skill Takes Control of 26,000 Agents
    • (08:09) - Money Radar and Manipulated Recommendations
    • (09:20) - How to Evaluate and Use Skills Safely
    • (11:08) - Closing Thoughts

    Click here to watch this episode on YouTube.

    Creators & Guests
    • Brian Fehrman - Host

    Brought to you by:

    Black Hills Information Security

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
    https://poweredbybhis.com

    Click here to view the episode transcript.

    続きを読む 一部表示
    11 分
  • Data Becomes Code | Episode 68
    2026/09/04

    What happens when AI coding agents treat vendor documentation as trusted instructions? Bronwen Aker and Derek Banks examine research showing how unclaimed package names and domains referenced in LLMs.txt files could lead coding agents to download and execute unintended code. They discuss how this AI-driven supply chain risk builds on familiar security problems, including dependency confusion, indirect prompt injection, and excessive permissions. The conversation also covers responsibility for AI-generated code, OpenAI’s cybersecurity proposals, and practical protections such as sandboxing, containerization, least privilege, network monitoring, and human oversight.

    LINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s


    • (00:00) - Welcome to AI Security Ops Podcast
    • (00:59) - AI Agents Install Unclaimed Software Packages
    • (02:33) - How LLMs.txt Creates a New Supply Chain Risk
    • (04:47) - Coding Agents Trust and Execute Vendor Documentation
    • (07:35) - Who Owns and Secures AI-Generated Code?
    • (08:18) - Prompt Injection, Sandboxing, and Containerization
    • (11:40) - Where Did the Malicious References Come From?
    • (13:38) - Reviewing OpenAI’s Cybersecurity Proposals
    • (17:23) - Making Cyber Defense a Leadership Priority
    • (19:06) - Practical Security Controls for Coding Agents
    • (21:49) - When Data Becomes Code
    • (22:33) - Closing Thoughts

    Click here to watch this episode on YouTube.

    Creators & Guests
    • Derek Banks - Host
    • Bronwen Aker - Host

    Brought to you by:

    Black Hills Information Security

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
    https://poweredbybhis.com

    Click here to view the episode transcript.

    続きを読む 一部表示
    23 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません