Minutes, Not Months: Inside the New Cyber Velocity Facing Federal Agencies
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
48 hours. That's the time it took for a federal employee credentials to be stolen as a result of a phishing attack, to being listed on a dark web marketplace. In Episode 8 of The GIST of Govt IT, Brian and Sean sit down at Check Point's Engage Summit in DC with Yochai Corem, General Manager of Check Point's Exposure Management division, to unpack what happens when both sides of cyber warfare have agentic AI — and why the next three years will not be kind to defenders. Yochai shares why pen testing once a quarter is no longer relevant, how a single Chinese developer built an entire attack program in a week using an army of agents, and what Iranian threat actors targeting Israeli hospitals look like in real-time during active kinetic conflict. The conversation digs into agentic red teaming vs. automated red teaming (and why the difference matters), why "safe remediation" still keeps a human in the loop, how to use the firewalls, WAFs, and IPS you already own as compensating controls when patching takes weeks, and the under-discussed reality that government leaders must put their hands on the keyboard with AI. Plus: Yochai's family cookbook and other vibe-coding stories.
RESOURCES MENTIONED IN THIS EPISODE
Featured Guest
- Yochai Corem, GM, Exposure Management, Check Point
- Corem Travel — Yochai's travel planning app
Check Point
- Check Point
- Check Point Exposure Management
- Check Point Engage Summit - Washington, DC
Check Point's Exposure Management Acquisitions
- Cyberint (now part of Check Point's external risk management)
- Veriti (automated security control management)
- Cyclops (now Check Point's CAASM offering)
Exposure Management & CTEM Framework
- Gartner Continuous Threat Exposure Management (CTEM) overview
- CISA Known Exploited Vulnerabilities (KEV) Catalog
Agentic AI & Red Teaming
- OWASP Top 10 for LLM Applications
- OWASP AIVSS — AI Vulnerability Scoring System for Agentic AI
- MITRE ATLAS (Adversarial Threat Landscape for AI Systems)
Threat Actor Tracking
- Check Point Research (threat intelligence blog)
- Check Point ThreatCloud AI
Concepts & References
- Air-gapped network security guidance (NIST SP 800-82)
- IRGC (Iranian threat actor background — CISA advisory on CyberAv3ngers)
Related Episodes
- Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT Fight
- Episode 6: Cupcakes & OODA Loops: Inside(r) Insights Into the New Federal AI Cyber Playbook
- Episode 5: Vibe Hacking and Nation State Cyber Threats
Upcoming Events
- GIST 360 Breakfast Briefing at the National Press Club, July 14, 2026 - When the Perimeter Disappears
The Hosts & Show
- Swish
- GIST 360
CONNECT WITH US
Got an idea for a future episode? Want to be a guest? Let us know.
Brian Lake - blake@swishdata.com
Sean Applegate - sapplegate@swishdata.com
Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.