A CyberRisk Alliance Production For Security Professionals, By Security Professionals. #InfoSec #CyberSec #Podcast #Livestream

G-Unit Studios, Warwick, RI
Filter
Exclude
Time range
-
Minimum likes
Cybersecurity keeps changing. The problems don't always change with it. CISOs still need help figuring out what to do, getting technology deployed, and actually operating it once it's in place. The conversation here is about addressing all three instead of treating them as separate problems. #Cybersecurity #CISO #InfoSec
120
Old accounts don’t always disappear when people, software, or automated systems move on. Former employees, forgotten service accounts, and even agentic AI can leave credentials behind after their original purpose is gone. Those “ghost accounts” may remain active without anyone realizing they still exist. How confident are you that every identity in your environment still has a legitimate owner and purpose?
124
An urgent warning called for Kiteworks users to shut down their servers in response to a reported credible threat of a coordinated cyberattack. Kiteworks is used for secure file sharing, transfers, and movement of sensitive data. Taking a production server offline is a serious operational action, but so is leaving potentially exposed infrastructure running during an active threat. The discussion highlights the tension security teams face during a Sev 1 incident: move immediately, while still maintaining authorization and change control. When an urgent vendor warning calls for shutdown, how much process should remain before security teams pull the plug?
1
742
AI is supposed to help security teams find the bad stuff. But without enough context, it can also recreate a problem the industry has spent years trying to reduce: false positives and false negatives. Both matter. Too many false positives create noise, while false negatives can allow real incidents to slip through. How much context should AI have before we trust its security findings? #AISecurity #Cybersecurity #ThreatDetection
1
110
Not all agent drift is a security problem. Upgrades and other known events can legitimately change how a system behaves. The challenge is distinguishing that expected drift from unexplained changes—and deciding how much variance is acceptable before something deserves investigation. As agent systems evolve, how much drift should security teams tolerate? #AISecurity #AgenticAI #Cybersecurity
2
160
AI adoption may be following a familiar path. Business teams moved faster than IT during the early cloud era, and organizations eventually found themselves managing huge cloud environments and spending. Now AI is moving just as quickly. The challenge is protecting intellectual property without getting in the way. Can companies put security around AI without putting the brakes on it? #AI #Cybersecurity #CISO
1
131
Some public-sector technology teams have just two people. They’re responsible for running the technology environment while also trying to bolt on cybersecurity, vulnerability management, and everything else that comes with it. Even larger counties may lack a dedicated cyber team. When cybersecurity keeps expanding, what can a small team realistically cover? #Cybersecurity #PublicSector #VulnerabilityManagement
119
A coding agent shouldn’t have access to everything your developer has. Giving coding agents their own low-privilege identities limits what a compromised agent or malicious plugin can reach. The underlying idea is simple: reduce the value of the environment an attacker can access. It’s a basic security principle, but how often are organizations actually applying least privilege to AI coding agents? #AIAgents #AppSec #Cybersecurity
1
1
2
159
What happens if AI ever becomes conscious? The possibility raises questions that go beyond cybersecurity or AI governance. If an artificial system were genuinely conscious, would it deserve rights or some form of moral consideration? That debate is already emerging in AI research, even though there is currently no established evidence that today’s AI systems are conscious. Where should the line between technology and personhood be drawn? #ArtificialIntelligence #AGI #AISafety
117
An AI agent may act autonomously, but accountability still has to trace back to a human. One approach described here ties services and accounts back to people and establishes a clear lineage when agents create sub-agents. The organization also used real incidents as teaching moments without publicly shaming individuals. What should human accountability look like as AI agents become more autonomous? #AIAgents #AISecurity #IdentitySecurity
120
An AI-generated intelligence report could have consequences far beyond a chatbot conversation. The story describes an alleged incident in which an AI-generated report incorrectly identified material aboard a ship, potentially prompting a serious military response before the error was discovered. The larger concern is straightforward: what happens when AI-generated misinformation enters high-stakes decision-making? How much verification should be required before an AI-generated claim can trigger action? #AI #AISafety #Cybersecurity
118
You can’t treat every vulnerability as a code-patching emergency. The argument here is to focus security resources on what is actually being exploited, while using controls at the firewall, identity, and other layers to reduce risk. Patching still matters when it’s appropriate and possible—but what changes when the goal shifts from “fix every vulnerability” to “reduce the organization’s actual exposure”? #Cybersecurity #AppSec #RiskManagement
134
A document uploaded to an AI model can create a security problem you may not immediately see. Organizations need to know when sensitive documents are being pasted or uploaded, what those documents contain, and what impact that exposure could have. That requires detection tooling alongside clear governance. As AI use expands, what should organizations be monitoring inside documents before they reach a model? #AIsecurity #Cybersecurity #DataProtection
114
Three or four technologies doing similar jobs? That’s the security-stack problem this conversation gets into: finding crossover, identifying duplication, and figuring out which capabilities actually belong in the stack. #Cybersecurity #CISO #SecurityOperations
125
The weirdest consequence of AI writing might not be bad writing. It might be people forgetting how to write at all. And if that happens, knowing how to put words together yourself could become a strangely valuable skill. #AI #Writing #GenerativeAI
1
159
AI was supposed to help us get more done. Instead, one side effect is brutally simple: more things to do. More projects. More expectations. Same number of hours. #AI #Productivity #FutureOfWork
1
1
128
A patch may no longer buy defenders much time. AI is making it easier for threat actors to reverse-engineer patches, develop proof-of-concept exploits, and potentially launch attacks within hours of a fix being released. If attackers can move faster than organizations can respond, is the traditional 48–72 hour window still realistic? #Cybersecurity #AI #VulnerabilityManagement
2
150
Microsoft just patched roughly 972 vulnerabilities in a single September release, including 112 critical flaws and two exploited zero-days. The update also covers major Microsoft products and more than 20 potentially wormable bugs. If AI-assisted vulnerability discovery is contributing to the rising patch volume, what does this new normal mean for defenders? #Cybersecurity #Microsoft #PatchTuesday
1
6
324
Agentic AI SOC companies may be entering a shakeout. One company has already shut down, while others are raising money and pushing deeper into the market. The key question is whether traction, revenue, and a proven track record will separate the eventual winners from everyone else. How many agentic AI SOC companies can actually survive? #Cybersecurity #AgenticAI #AISOC
2
146
A confident AI answer can still be wrong. Security models can produce severity ratings, CWEs, explanations, and even clean-looking patches. But none of that proves a vulnerability has actually been fixed. For mature security teams with people who can validate findings, AI can be a useful second pair of eyes. Without that validation, does AI actually save security teams time—or create more work? #Cybersecurity #AI #AppSec
1
3
164