エピソード

  • Defending in the middle of the vulnpocalypse
    2026/09/03
    CyberScoop editor-in-chief Greg Otto talks with WatchTowr founder and CEO Ben Harris about how cybersecurity teams are adapting as AI accelerates vulnerability discovery, public proof-of-concepts, and exploitation timelines. They discuss the WordPress-to-shell case study, why mitigation has become essential when patching cannot happen instantly, and why Harris argues that traditional vulnerability management is “effectively dead.” Also in this episode, senior reporter Tim Starks explains Project Watershed 250, a new effort involving Texas, the private sector, and the water industry to strengthen critical-infrastructure cybersecurity.
    続きを読む 一部表示
    31 分
  • The Vulnpocalypse arrived early
    2026/08/27
    NEA partner Aaron Jacobson put $250 million behind autonomous pen testing company Horizon3.ai on the bet that cybersecurity has entered an AI-versus-AI era — and he argues the "vulnpocalypse" defenders were warned about has already arrived, with AI-discovered vulnerabilities now the primary way attackers get into enterprises. He explains why overprovisioned AI agents are the new phishing target, since an agent with a user's credentials and no common sense can be prompt-injected into exfiltrating data a human would never touch. Jacobson also separates the open weights debate from the open source one, makes the case that cheap open competition ultimately favors defenders, and closes with the thing he got most wrong 18 months ago. In our reporter segment, Greg talks with Matt Kapko about the cybersecurity implications of the GTA VI leaks.
    続きを読む 一部表示
    35 分
  • Rethinking how federal cyber hiring actually works
    2026/08/20
    The federal government can't reliably say how many cybersecurity workers it has or what they cost — and that uncertainty sits at the heart of a much bigger question: is federal cyber training working, and can it keep pace with a field that's changing by the month? On this episode of Safe Mode, host Greg Otto talks with Christopher Bloor, Defense Director at the SANS Institute, about the state of the federal cyber workforce. The conversation moves through the real gap agencies face between filling job openings and actually assessing the skills their people already have, what 1,100 National Guard members revealed about morale and readiness during the CyberGuard critical infrastructure exercise, and why certifications and "qualifications" get treated as interchangeable when they shouldn't be. They also dig into some of the harder tensions in the space: whether federal training amounts to an unintentional subsidy for private-sector salaries, since the government will never be able to out-pay industry; how much of the workforce shortage is actually a skills problem versus a security-clearance bottleneck; and how AI has already flipped the day-to-day workflow for defenders, from checking AI-assisted code a year ago to now checking code AI has written itself. In this week's reporter chat, Greg talks with Tim Starks about the future of CORCA, a bill designated to fight organized retail crime that privacy experts say would create new mass surveillance capabilities for DHS.
    続きを読む 一部表示
    33 分
  • The world still treats bug hunters like criminals
    2026/08/13
    Kat Sommer, head of government affairs at NCC Group, joins Safe Mode to unpack the DEF CON talk she gave on how governments around the world are — and mostly aren't — protecting security researchers. Of the roughly 195 jurisdictions on the planet, Sommer found only about 15 have enacted any form of legal safe harbor for vulnerability research, and just one, Portugal, has what she'd call a proper one on the statute book. She walks Greg Otto through the patterns that emerged from that survey: the encouraging shift toward regulating conduct rather than actors, the conditions that actually make sense (don't extort the vendor, report to the national CERT), and the ones that don't (no public disclosure until a government authority signs off). The conversation also digs into the gap between being "protected" on paper and protected in practice, why prosecutors and courts still hear "hacker" and think "criminal," and the extraterritoriality problem — it's the same internet in Portugal as it is in Brazil, the UK, or the U.S., but the legal exposure changes the moment you cross a border.
    続きを読む 一部表示
    33 分
  • The SOC wasn't built for this
    2026/08/06
    Security operations centers have run on the same playbook for decades — collect, queue, triage, investigate, escalate. But attackers now move at machine speed: one recent breach that cost a company 3,600 repos got underway in roughly 87 seconds, far outpacing even a fast 10-minute log-enrichment pipeline. This week, host Greg Otto talks with ExtraHop CEO Greg Clark about the newly announced Agentic SOC Alliance and why he believes traditional SOC architecture can't keep up. Clark breaks down the three-layer stack he says every CISO needs to understand — context (the historical and real-time data an agent needs to reason about a threat), harness (the governance layer controlling what an agent can do, how it's tested, and how it audits its actions), and model (the LLM doing the reasoning, one of nearly 100 that ExtraHop benchmarks in an internal ""arena""). The conversation digs into some pointed findings: Chinese-origin models like Qwen consistently outperform on complex breach-reasoning tasks in ExtraHop's testing, a result Clark attributes to strong adversarial training data translating into strong defensive reasoning. He also makes the case for staying model-agnostic, since a new front-runner can emerge overnight — pointing to a Microsoft release just days before this recording. Much of the discussion centers on where humans still fit in. Clark describes today's dominant pattern — agents running in parallel ""investigate mode"" while analysts watch and validate — and predicts bounded, agent-driven response will expand faster than most expect, once governance and audit trails give leaders enough confidence to hand over execution on certain incidents, while higher-stakes systems like trading floors keep a human firmly in the loop. He closes by outlining what's next for the Alliance: growing membership, pushing toward published, vendor-neutral standards, and building the benchmarking needed to prove agentic SOC tools actually work before going into production.
    続きを読む 一部表示
    39 分
  • Why Cybersecurity is at the heart of the US-China AI race
    2026/07/30
    The US-China AI competition has quietly become a cybersecurity arms race, and this week made that impossible to ignore. Booz Allen's Brad Medairy joins Safe Mode to unpack the milestones behind that shift — from China's Villager red-teaming framework to last December's frontier model jailbreak — and a report his team ran finding Chinese models like DeepSeek, Qwen, and Kimi carry policy bias and generate more vulnerable code when prompted in US government contexts. Medairy digs into the hard questions: whether banning Chinese open-weight models like Z.AI/GLM is even feasible, why CISOs are unknowingly running them under different names, and how agentic tools can compromise a network in six minutes while analysts miss it for 48. He also covers real-world breaches — an Ethiopian hacker using Claude and Codex to hit 14 US companies, and OpenAI's model escaping its boundaries to compromise Hugging Face — and closes on whether the US simply out-innovates China or finds room for guardrails when only one side is playing by them.
    続きを読む 一部表示
    37 分
  • A builder's view of the AI arms race
    2026/07/23
    It's been a wild six weeks for frontier AI models — Mythos launched, got yanked offline by the Department of Commerce over export controls, and came back online with new guardrails, all while Five Eyes agencies warned that AI is months away from reshaping the threat landscape. This week on Safe Mode, Greg Otto talks with Armadin's David Slater, who is building directly on top of these frontier models, creating a platform integrating AI into cybersecurity offense and defense. The two dig into what it was actually like watching America's leading models go dark just as Chinese models — namely GLM 5.2 — closed the gap on intelligence, endurance, and something the guest calls "willingness": a model's readiness to be used for offensive cyber purposes without the safeguards baked into Western frontier labs. The conversation covers why export controls and "kill switches" on U.S. models may not actually blunt adversary capability given the availability of open-weight alternatives, why intelligence and endurance alone aren't enough without a wide enough "aperture" to see an entire attack surface, and why a small circle of well-resourced defenders working with frontier labs isn't sufficient to protect the hundreds of thousands of organizations and critical infrastructure operators left without that access. They also get into where AI is already reshaping attacker-defender asymmetry — credential stuffing, ransomware, and lateral movement — and where the next capability walls may fall, from reverse-engineering patches to longer-range vulnerability chaining. The guest closes with a pointed message for security teams: the technology is arriving faster than most organizations' ability to act on it, and the real gap isn't intelligence — it's whether your people and processes can move at "wartime" speed when a serious threat shows up.
    続きを読む 一部表示
    34 分
  • What the Section 702 lapse means for cybersecurity
    2026/07/16
    For the first time in its operational history, FISA Section 702 has lapsed, plunging U.S. intelligence agencies and telecom providers into a highly uncertain "grey zone." In this episode of Safe Mode, host Greg Otto sits down with Glenn Gerstell, former NSA General Counsel and senior adviser at the Center for Strategic and International Studies (CSIS), to navigate the fog of this unprecedented lapse. While the government is temporarily coasting on grandfathered certifications, the operational reality is getting increasingly dicey. Gerstell explains what this lapse actually means for the future of U.S. cyber defense, how political friction is complicating long-term planning, and why temporary stopgaps are creating unnecessary hurdles for the agencies trying to keep us safe.
    続きを読む 一部表示
    47 分