『The Adversarial Podcast』のカバーアート

The Adversarial Podcast

The Adversarial Podcast

著者: Jerry Perullo Sounil Yu Mario Duarte
無料で聴く

このコンテンツについて

Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the latest cybersecurity news. Each week, we discuss the most pressing headlines, offer candid commentary, and share unique insights from our extensive experience in the field.

Adversarial Risk Management
経済学
エピソード
  • Adversarial Podcast S4E03 – Fumbled NPM Attack, Entering the AI Browser Market, Salesloft breach
    2025/09/16

    00:00 Intro

    03:10 NPM supply chain attack leaves attackers empty handed

    24:44 Why is Atlassian buying a browser company?

    37:20 Apple's new Memory Integrity Enforcement

    52:56 Salesloft breach leads to downstream hacks

    Hackers left empty-handed after massive NPM supply-chain attack

    Hackers briefly compromised popular NPM packages like chalk and debug-js, infecting ~10% of cloud environments, but despite the massive supply-chain reach they only netted about $600 in stolen cryptocurrency.

    https://www.bleepingcomputer.com/news/security/hackers-left-empty-handed-after-massive-npm-supply-chain-attack/

    Why is Atlassian Buying a Browser Company?

    Atlassian is buying The Browser Company (makers of Arc and Dia) for $610M to gain control of the browser channel, secure its AI agent (Rovo) distribution, and enter the emerging “enterprise browser” market, even though success is uncertain against Google and Microsoft.

    https://nextword.substack.com/p/why-is-atlassian-buying-a-browser

    Memory Integrity Enforcement: A complete vision for memory safety in Apple devices

    Apple’s new Memory Integrity Enforcement (MIE) brings always-on hardware-software memory safety to iPhone 17, making advanced spyware exploits far harder.

    https://security.apple.com/blog/memory-integrity-enforcement/

    Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks

    Hackers exploited Salesloft’s Drift–Salesforce integration to steal OAuth tokens and exfiltrate sensitive Salesforce data, tracked as UNC6395.

    https://www.bleepingcomputer.com/news/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacks/

    Hosts:

    Jerry Perullo (Founder, https://adversarial.com/)

    Sounil Yu (Founder, https://www.knostic.ai/)

    Mario Duarte (Founder, stealth startup)

    Producer: Tillson Galloway (https://tillsongalloway.com)

    続きを読む 一部表示
    1 時間 9 分
  • Adversarial Podcast S4E02 - Cyber acquisitions and raises, 95% of GenAI pilots failing, Zelle's alleged security lapses
    2025/09/04

    00:00 Introduction & BlackHat

    02:06 Cybersecurity in Schools

    18:53 Black Hat Conference Highlights

    34:02 New York sues Zelle

    44:48 Trends in Cybersecurity Mergers and Acquisitions

    1:02:44 95% of generative AI pilots at companies are failing

    1:08:53 Prompt injection with poisoned calendar invites

    DARPA announces $4 million winner of AI code review competition at DEF CON

    DARPA announced Team Atlanta as the winner of its two-year competition among researchers to create the best artificial intelligence systems that can find and fix vulnerabilities.

    Attorney General James Sues Company Behind Zelle for Enabling Widespread Fraud

    New York today sued Early Warning Services, a company owned and controlled by a group of the largest banks in the United States that was tasked with developing and operating the electronic payment platform Zelle, for failing to protect its users from massive amounts of fraud.

    Cyber Acquisitions

    • Palo Alto / CyberArk
    • CrowdStrike / Onum
    • Okta / Axiom
    • Armis raises millions at $5B valuation

    MIT report: 95% of generative AI pilots at companies are failing

    A recent MIT‑commissioned study—highlighted in Fortune on August 18, 2025—reveals that approximately 95% of generative AI pilot programs at companies failed to deliver any measurable return on investment or financial uplift. The core issue appears to be not the AI itself, but poor integration into existing workflows and misaligned use cases, with only about 5% of pilots achieving rapid revenue growth by focusing sharply on specific pain points.

    Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home

    Security researchers demonstrated that a poisoned Google Calendar invite could indirectly prompt-inject Google’s Gemini, causing it to control smart-home devices.

    Hosts:

    Jerry Perullo (Founder, https://adversarial.com/)

    Sounil Yu (Founder, https://www.knostic.ai/)

    Mario Duarte (Founder, stealth startup)

    Producer: Tillson Galloway (https://tillsongalloway.com)

    続きを読む 一部表示
    1 時間 16 分
  • Adversarial Podcast S4E01 - Trump's AI Action Plan, Chip Security Act, receiving gifts from vendors
    2025/07/30

    00:00 Introduction & BlackHat

    03:14 AI Action Plan Overview

    13:30 Chip Security Act

    20:48 Government led AI-ISAC?

    23:16 UK government considering banning public sector ransomware payments

    28:14 Microsoft probing if Chinese hackers learned SharePoint flaws through alert

    42:07 Ethics in Vendor Relationships – Gifts for meetings

    America's AI Action Plan

    “America’s AI Action Plan,” released by the Trump administration, outlines a roadmap with over 90 federal actions across three pillars—accelerating AI innovation, building U.S. AI infrastructure, and asserting international AI leadership through exports and technology alliances.

    The Chip Security Act: A Bipartisan Solution to Chip Smuggling

    The Chip Security Act, introduced by U.S. lawmakers, mandates that export‑controlled AI chip makers (like NVIDIA) embed on‑chip location‑verification mechanisms to ensure devices go only where they’re authorized—aiming to deter smuggling (especially to China) without deploying intrusive GPS or kill switches.

    Why a Government-Led AI-ISAC is a Missed Opportunity

    Errol Weiss argues that an AI‑ISAC led by the U.S. government, as proposed in the July 2025 White House AI Action Plan, represents a missed opportunity, because government-led initiatives tend to be bureaucratic, slow, less innovative, struggle to win private-sector trust and buy‑in, risk duplicating existing ISAC efforts, and may be perceived as politically biased—undermining effective, rapid, cross-industry intelligence sharing

    UK plans to ban public sector bodies from paying ransom to cyber criminals

    The UK government is set to ban public sector bodies and operators of critical national infrastructure from paying ransom demands to cyber criminals, as part of a wider package also mandating mandatory reporting for other organisations planning to pay, aimed at dismantling the ransomware business model and protecting essential services from dangerous disruptions.

    Microsoft probing if Chinese hackers learned SharePoint flaws through alert, Bloomberg News reports

    Microsoft is investigating whether a leak from its Microsoft Active Protections Program (MAPP)—which provides early vulnerability alerts to security partners—may have enabled Chinese-aligned hackers (Linen Typhoon, Violet Typhoon, and Storm-2603) to exploit critical zero‑day flaws in on-premises SharePoint servers before Microsoft fully patched the software, fueling a global espionage and ransomware campaign.

    Hosts:

    Jerry Perullo (Founder, https://adversarial.com/)

    Sounil Yu (Founder, https://www.knostic.ai/)

    Mario Duarte (Founder, stealth startup)

    Producer: Tillson Galloway (https://tillsongalloway.com)

    続きを読む 一部表示
    52 分
まだレビューはありません