
Insights from recent episode analysis
Audience Interest
Podcast Focus
Publishing Consistency
Platform Reach
Insights are generated by CastFox AI using publicly available data, episode content, and proprietary models.
Most discussed topics
Brands & references
Total monthly reach
Estimated from 3 chart positions in 3 markets.
By chart position
- 🇬🇧GB · Technology#1725K to 30K
- 🇲🇽MX · Technology#1351K to 10K
- 🇭🇰HK · Technology#693K to 10K
- Per-Episode Audience
Est. listeners per new episode within ~30 days
2.7K to 15K🎙 Daily cadence·49 episodes·Last published yesterday - Monthly Reach
Unique listeners across all episodes (30 days)
9K to 50K🇬🇧60%🇲🇽20%🇭🇰20% - Active Followers
Loyal subscribers who consistently listen
2.7K to 15K
Market Insights
Platform Distribution
Reach across major podcast platforms, updated hourly
Total Followers
—
Total Plays
—
Total Reviews
—
* Data sourced directly from platform APIs and aggregated hourly across all major podcast directories.
On the show
From 13 epsHosts
Recent guests
Recent episodes
Why Prompt Filters Fail & How to Explain AI Risk to the Board | Cezary Piekarski, Standard Chartered.
Sep 2, 2026
Unknown duration
Why 95% of AI Projects Fail: Model Risk & AI Governance | Sandip Wadje, BNP Paribas
Aug 27, 2026
Unknown duration
Why I Dont Trust Your AI Agent | Kane Narraway, Canva
Aug 20, 2026
Unknown duration
Baiting the Bot: How to Use Deception to Stop Autonomous AI Agents
Jul 23, 2026
Unknown duration
Why AI Agents Are Forcing a Redesign of Application Security?
Jun 26, 2026
51m 35s
Social Links & Contact
Official channels & resources
Official Website
Login
RSS Feed
Login
| Date | Episode | Topics | Guests | Brands | Places | Keywords | Sponsor | Length | |
|---|---|---|---|---|---|---|---|---|---|
| 9/2/26 | Why Prompt Filters Fail & How to Explain AI Risk to the Board | Cezary Piekarski, Standard Chartered. | Is the cybersecurity industry repeating the same mistakes with prompt injection that it made with buffer overflows decades ago? As attackers iterate through 50 to 60 prompt filter bypasses daily, attempting to artificially separate instruction from data is becoming a futile effort. In this episode, Ashish sits down with Cezary Piekarski, Group CISO of Standard Chartered. Cezary shares his techno-optimist view on how AI will ultimately benefit defenders, while also unpacking the hard realities of securing an enterprise that ingests 50-plus terabytes of observable data every single day. He explains why reactive security operations are dead, why User Behavior Analytics (UBA) often fails at scale due to stochastic human behavior, and why deception technology must be built directly into your ecosystem to actually work. Cezary shares his thoughts on executive communication, detailing a proven three-step framework for explaining complex AI risks to a board of directors without relying on fear-mongering. Finally, we explore why the tension between AI data hunger and user privacy is largely a "fake dilemma" for security teams.Questions asked:(00:00) Introduction: The Futility of Prompt Filters & AI Attack Evolutions(02:30) Cezary Piekarski’s Background and Role at Standard Chartered(03:30) What "Security as a Business Enabler" Actually Means(06:30) The Techno-Optimist View of AI in Cybersecurity(08:50) Why Reactive Security and Manual Triage Are Dead at 50TB/Day(11:30) Doing Deception Technology Right (No More "Surplus Bug" Buying)(15:20) The Flaws of UBA and Behavioral Anomaly Detection(22:30) The Buffer Overflow Analogy: Why Prompt Injection Needs an Architectural Fix(27:30) Under-Discussed Threats: Image-Based Prompt Injection & Data Poisoning(30:00) A 3-Step Masterclass for Explaining AI Risk to the Board(34:30) Why the AI Privacy vs. Security Debate is a "Fake Dilemma" Resources spoken about during the episode: Cyber security and fraud safety | Standard Chartered | — | ||||||
| 8/27/26 | Why 95% of AI Projects Fail: Model Risk & AI Governance | Sandip Wadje, BNP Paribas | Why do 95% of enterprise AI implementations fail? According to Sandip Wadje, Managing Director at BNP Paribas, many organizations attempt complex reasoning tasks on day one rather than building a mature foundation around data hygiene and simple summarization workflows. In this episode, Ashish sits down with Sandip to explore how global financial institutions navigate Model Risk Management (MRM), GenAI governance, and regulatory expectations across regions like the UK, EU, and US. Sandip breaks down why classical 20-year-old MRM frameworks fall short when applied to non-deterministic black-box LLMs, and why security leaders must focus on output drift and event taxonomies rather than just input prompt filtering. We also examine the concept of the "AI Kitchen" - a cross-functional governance model bringing together IT, CISOs, legal, and Data Protection Officers alongside practical strategies for calculating AI blast radius, cleaning up overprivileged non-human identity (NHI) permissions, and training CSIRT teams for ML SecOps incidents.Questions asked:(00:00) Introduction: AI Risk in Regulated Financial Institutions(01:50) Sandip Wadje’s Background at BNP Paribas(02:50) Classical Model Risk Management (MRM) vs. Generative AI(04:40) Governing the Black Box: Finding the Security Delta(08:00) The CMDB Problem: Building an Accurate AI Use Case Inventory(11:30) Why 95% of AI Projects Fail: Summarize, Write, Reason(15:00) Continuous Evaluation (Evals) and Catching Output Drift(18:50) Event Taxonomy: What Happens When AI Decisions Drift?(25:40) Training CSIRT and SOC Teams for ML SecOps Incidents(30:00) Compensating Controls: Remote Browser Isolation & Prompt Monitoring(34:30) Non-Human Identities (NHI) & Cleaning Birthright Permissions(36:30) Balancing a $1M Savings Against a 4% Revenue Fine(38:30) Open-Weight Models vs. Frontier LLMs in Financial Services(41:00) The "AI Kitchen": Cross-Functional AI Governance(44:30) The #1 Rule for AI Security: Understand Your Data First | — | ||||||
| 8/20/26 | Why I Dont Trust Your AI Agent | Kane Narraway, Canva | With over 200 AI security vendors in the market, how does an enterprise CISO decide whether to build a custom solution, buy an off-the-shelf product, or just wait out the hype?In this episode of the AI Security Podcast, Ashish and Caleb are joined by Kane Narraway, Head of Enterprise Security at Canva, to debate the realities of AI security in modern enterprises. Kane breaks down why simply sandboxing AI agents doesn't work for workforce productivity, explaining that an overly restrictive sandbox renders an agent useless because it inherently needs access to external files and databases to do its job.We dive deep into the "Confused Deputy" problem, the struggle of granting granular least privilege to AI tools (like letting a bot summarize only Caleb's emails), and whether the old-school concept of network proxies is about to make a massive comeback as the ultimate control layer for AI routing and authorization. Finally, Kane shares why he believes the scariest near-future threat isn't malware, but contractors utilizing "Bring Your Own Agent" (BYOA) in enterprise environments.Questions asked:(00:00) Introduction to AI Agents in the Enterprise(01:50) Kane Narraway’s Background (Digital Forensics, Atlassian, Shopify, Canva)(02:50) The Build vs. Buy Debate in the Era of 200+ AI Security Vendors(09:00) Using Wrappers and Harnesses to Control Vendor APIs (Island Browser Example)(11:00) Why GitOps and PRs are Better for AI Configuration than MCP Deployments(13:00) The "Confused Deputy" Problem: Single-Player vs. Multi-Player AI Bots(16:50) How to Handle Agent Identity: "On Behalf Of" (OBO) vs. SPIFFE / NHI(22:50) Why Sandboxing AI Agents Fails for the General Workforce(28:20) Intent-Based Security and the Lack of Granular Access Controls(29:40) Are Proxies the Next Gen Firewall for AI Agents?(34:00) The Terrifying Future of "Bring Your Own Agent" (BYOA)(38:50) The "Gravel Road" Strategy for Managing Shadow IT and Vibe Coding(42:00) Dealing with Vendors Trying to Exploit Shadow IT Land Grabs(49:30) What Security Leaders are Over-Indexing On (Discovery vs. True Access)(50:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge | — | ||||||
| 7/23/26 | Baiting the Bot: How to Use Deception to Stop Autonomous AI Agents | When AI agents start swarming your enterprise, they won't care about stealth. They will land a beachhead and instantly spawn 500 agents to crawl, probe, and exfiltrate data at machine speed. Is your detection stack ready? In this episode, Ashish and Caleb sit down with Andy Smith, CEO and co-founder of Tracebit, to completely rethink Deception Technology for the AI era. Forget the heavy, noisy "honeypots" of the 90s. We discuss the modern implementation of deception: lightweight, high-fidelity canary tokens (like fake AWS keys, Chrome cookies, and database tables) that act as guaranteed tripwires the moment an attacker, human or AI, assumes a breach. Andy shares new research on how you can actively weaponize an AI model's own safety guardrails against it. By embedding specific, controversial text strings (like references to biological warfare or sensitive political events) into decoy secrets.Questions asked:(00:00) Introduction to AI Deception(02:30) Andy Smith’s Background and the Founding of Tracebit(03:40) Deception 101: Honeypots vs. Canary Tokens(07:20) The "Assume Breach" Philosophy of Deception(10:00) Why CISOs Default to SIEMs over Quick Deception Wins(13:20) The Psychological Deterrent of Deception on Red Teams(15:10) Setting Up a Database Tripwire (Real-World Example)(17:40) Internal AI Threats: Catching Claude Code in a Production Kubernetes Pod(20:00) Why Deception Fails: The Lack of Strategy and Deployment Complexity(26:30) Using Cloud Serverless (S3/Terraform) to Deploy Deception for Free(28:00) Modern Lateral Movement: Chrome Cookies and Browser History Canaries(41:20) The Future of Attacks: Armies of Fast, Noisy AI Agents(44:50) Weaponizing AI Guardrails to Shut Down Attack Agents(48:20) Where to Start with Your Deception Strategy TodayResources spoken about during the episode:- Tracebit Research - Deception warns your teams at the speed of an AI attacker | — | ||||||
| 6/26/26 | AI coding assistantsapplication security+4 | Caleb | Claude CodeAnthropic | COBOL | AI agentsapplication security+5 | — | 51m 35s | ||
| 6/11/26 | asset intelligenceCMDB+4 | Joe Diamond | Axonius | — | asset managementdark matter+4 | — | 42m 47s | ||
| 6/4/26 | AI securityauthorization+4 | Graham Neray | Claude CodeNotion Agents+1 | — | AI agentsauthorization+5 | — | 47m 42s | ||
| 5/21/26 | AI securityengineering security+3 | Nick RevaShivani Doke | DoorDash | San FranciscoSilicon Beach | AI developmentAppSec+5 | — | 1h 03m 09s | ||
| 5/13/26 | autonomous AIcybersecurity+4 | Sounil Yu | OpenClawClaude Code+4 | — | autonomous AIcybersecurity+6 | — | 1h 10m 14s | ||
| 4/29/26 | AI securityautonomous agents+4 | Elie Bursztein | GoogleSAIF | — | AI agentssecurity models+5 | — | 47m 22s | ||
Want analysis for the episodes below?Free for Pro Submit a request, we'll have your selected episodes analyzed within an hour. Free, at no cost to you, for Pro users. | |||||||||
| 4/22/26 | AI securityCISO+4 | Heather Ceylan | Box.comTechRiot.io | — | AI SOCautomated triage+3 | — | 46m 47s | ||
| 4/18/26 | AI securityzero-day exploits+4 | — | Project MythosProject Glasswing+5 | — | Project Mythoszero-day exploits+5 | — | 1h 03m 22s | ||
| 4/15/26 | AI securitystartups+4 | Edward WuLou Manousos | AI SOC AnalystAI Threat Hunter+4 | — | AI security startupsthreat prevention+6 | — | 47m 17s | ||
| 4/2/26 | AI securityCI/CD pipeline+5 | Igor Andriushchenko | LovableMunich Cybersecurity Conference | Europe | AI-native platformsecurity processes+5 | — | 57m 02s | ||
| 3/18/26 | AI securityCISO strategies+4 | — | RSA ConferenceAI agent security+5 | — | AI securityCISO+6 | — | 50m 35s | ||
| 3/5/26 | AI in cybersecurityAppSec industry+4 | — | Claude Code SecurityAnthropic+2 | — | Claude Code SecurityAppSec+5 | — | 59m 48s | ||
| 2/11/26 | AI Chief of Staffautomation+4 | Caleb Sima | PepperClaude Code+2 | — | AI automationPepper+5 | — | 47m 23s | ||
| 1/28/26 | AI Security 2026 Predictions: The "Zombie Tool" Crisis & The Rise of AI Platforms | This is a forward-looking episode, as Ashish Rajan and Caleb Sima break down the 8 critical predictions shaping the future of AI security in 2026We explore the impending "Age of Zombies", a crisis where thousands of unmaintainable, "vibe-coded" internal tools begin to rot as employees churn . We also unpack controversial theory about the "circular economy" of token costs, suggesting that major providers are artificially keeping prices high to avoid a race to the bottom .The conversation dives deep into the shift from individual AI features to centralized AI Platforms , the reality of the Capability Plateau where models are getting "better but not different" , and the hilarious yet concerning story of Anthropic’s Claude not being able to operate a simple office vending machine without resorting to socialism or buying stun gunsQuestions asked:(00:00) Introduction: 2026 Predictions(02:50) Prediction 1: The Capability Plateau (Why models feel the same) (05:30) Consumer vs. Enterprise: Why OpenAI wins consumer, but Anthropic wins code (09:40) Prediction 2: The "Evil Conspiracy" of High AI Costs (12:50) Prediction 3: The Rise of the Centralized AI Platform Team (15:30) The "Free License" Trap: Microsoft Copilot & Enterprise fatigue (20:40) Prediction 4: Hyperscalers Shift from Features to Platforms (AWS Agents) (23:50) Prediction 5: Agent Hype vs. Reality (Netflix & Instagram examples) (27:00) Real-World Use Case: Auto-Fixing 1,000 Vulnerabilities in 2 Days (31:30) Prediction 6: Vibe Coding is Replacing Security Vendors (34:30) Prediction 7: Prompt Injection is Still the #1 Unsolved Threat (43:50) Prediction 8: The "Confused Deputy" Identity Problem (51:30) The "Zombie Tool" Crisis: Why Vibe Coded Tools will Rot (56:00) The Claude Vending Machine Failure: Why Operations are Harder than Code | — | ||||||
| 1/23/26 | Why AI Agents Fail in Production: Governance, Trust & The "Undo" Button | Is your organization stuck in "read-only" mode with AI agents? You're not alone. In this episode, Dev Rishi (GM of AI at Rubrik, formerly CEO of Predibase) joins Ashish and Caleb to dissect why enterprise AI adoption is stalling at the experimentation phase and how to safely move to production .Dev reveals the three biggest fears holding IT leaders back: shadow agents, lack of real-time governance, and the inability to "undo" catastrophic mistakes . We dive deep into the concept of "Agent Rewind", a capability to roll back changes made by rogue AI agents, like deleting a production database and why this remediation layer is critical for trust .The conversation also explores the technical architecture needed for safe autonomous agents, including the debate between MCP (Model Context Protocol) and A2A (Agent to Agent) standards . Dev explains why traditional "anomaly detection" fails for AI and proposes a new model of AI-driven policy enforcement using small language models (SLMs) as judges .Questions asked:(00:00) Introduction(02:50) Who is Dev Rishi? From Predibase to Rubrik(04:00) The Shift from Fine-Tuning to Foundation Models (07:20) Enterprise AI Use Cases: Background Checks & Call Centers (11:30) The 4 Phases of AI Adoption: Where are most companies? (13:50) The 3 Biggest Fears of IT Leaders: Shadow Agents, Governance, & Undo (18:20) "Agent Rewind": How to Undo a Rogue Agent's Actions (23:00) Why Agents are Stuck in "Read-Only" Mode (27:40) Why Anomaly Detection Fails for AI Security (30:20) Using AI Judges (SLMs) for Real-Time Policy Enforcement (34:30) LLM Firewalls vs. Bespoke Policy Enforcement (44:00) Identity for Agents: Scoping Permissions & Tools (46:20) MCP vs. A2A: Which Protocol Wins? (48:40) Why A2A is Technically Superior but MCP Might Win | — | ||||||
| 12/19/25 | AI Security 2025 Wrap: 9 Predictions Hit & The AI Bubble Burst of 2026 | It's the season finale of the AI Security Podcast! Ashish Rajan and Caleb Sima look back at their 2025 predictions and reveal that they went 9 for 9. We wrap up the year by dissecting exactly what the industry got right (and wrong) about the trajectory of AI, providing a definitive "state of the union" for AI security.We analyze why SOC Automation became the undisputed king of real-world AI impact in 2025 , while mature AI production systems failed to materialize beyond narrow use cases due to skyrocketing costs and reliability issues . They also review the accuracy of their forecasts on the rise of AI Red Teaming , the continued overhyping of Agentic AI , and why Data Security emerged as a critical winner in a geo-locked world .Looking ahead to 2026, the conversation shifts to bold new predictions: the inevitable bursting of the "AI Bubble" as valuations detach from reality and the rise of self-fine-tuning models . We also explore the controversial idea that the "AI Engineer" is merely a rebrand for data scientists and a lot more…Questions asked:(00:00) Introduction: 2025 Season Wrap Up(02:50) State of AI Utility in late 2025: From coding to daily tasks(09:30) 2025 Report Card: Mature AI Production Systems? (Verdict: Correct)(10:45) The Cost Barrier: Why Production AI is Expensive(13:50) 2025 Report Card: SOC Automation is #1 (Verdict: Correct)(16:00) 2025 Report Card: The Rise of AI Red Teaming (Verdict: Correct)(17:20) 2025 Report Card: AI in the Browser & OS(21:00) Security Reality: Prompt Injection is still the #1 Risk(22:30) 2025 Report Card: Data Security is the Winner(24:45) 2025 Report Card: Geo-locking & Data Sovereignty(28:00) 2026 Outlook: Age Verification & Adult Content Models(33:00) 2025 Report Card: "Agentic AI" is Overhyped (Verdict: Correct)(39:50) 2025 Report Card: CISOs Should NOT Hire "AI Engineers" Yet(44:00) The "AI Engineer" is just a rebranded Data Scientist(46:40) 2026 Prediction: Self-Training & Self-Fine-Tuning Models(47:50) 2026 Prediction: The AI Bubble Will Burst(49:50) Bold Prediction: Will OpenAI Disappear?(01:01:20) Final Thoughts: Looking ahead to Season 4 | — | ||||||
| 12/10/25 | AI Paywall for Browsers & The End of the Open Web? | Cloudflare announced this year that AI bots must pay to crawl content. In this episode, Ashish Rajan and Caleb Sima dive deep into what this means for the future of the "open web" and why search engines as we know them might be dying .We explore Cloudflare's new model where websites can whitelist AI crawlers in exchange for payment, effectively putting a price tag on the world's information . Caleb spoke about the potential security implications, predicting a shift towards a web that requires strict identity and authentication for both humans and AI agents .The conversation also covers Cloudflare's new open-source browser, Ladybird, positioning itself as a competitor to the dominant Chromium engine . Is this the beginning of Web 3.0 where "information becomes currency"? Tune in to understand the massive shifts coming to browser security, AI agent identity, and the economics of the internet .Questions asked:(00:00) Introduction(01:55) Cloudflare's Announcement: Blocking AI Bots Unless They Pay (03:50) Why Search Engines Are Dying & The "Oracle" of AI (05:40) How the Payment Model Works: Bidding for Content Access (09:30) Will This Adoption Come from Enterprise or Bloggers?(11:45) Security Implications: The Web Requires Identity & Auth (13:50) Phase 2: Cloudflare's New Browser "Ladybird" vs. Chromium (19:00) Moving from B2B to Consumer: Paying Per Article via Browser (21:50) Managing AI Agent Identity: Who is Buying This Dinner? (23:20) Why Did We Switch to Chrome? (Performance vs. Memory) (27:00) Jony Ive & Sam Altman's AI Device: The Future Interface? (30:20) Google's Response: New Tools like "Opal" to Compete with n8n (33:15) The Controversy: Is This the End of the Free Open Web? (36:20) The New Economics of the Internet: Information as CurrencyResources discussed during the interview:Cloudflare Just Changed How AI Crawlers Scrape the Internet-at-Large; Permission-Based Approach Makes Way for A New Business Model | — | ||||||
| 12/3/25 | Build vs. Buy in AI Security: Why Internal Prototypes Fail & The Future of CodeMender | Should you build your own AI security tools or buy from a vendor? In this episode, Ashish Rajan and Caleb Sima dive deep into the "Build vs. Buy" debate, sparked by Google DeepMind's release of CodeMender, an AI agent that autonomously finds, root-causes, and patches software vulnerabilities .While building an impressive AI prototype is easy, maintaining and scaling it into a production-grade security product is "very, very difficult" and often leads to failure after 18 months of hidden costs and consistency issues . We get into the incentives driving internal "AI sprawl," where security teams build tools just to secure budget and promotions, potentially fueling an AI bubble waiting to pop .We also discuss the "overhyped" state of AI security marketing, why nobody can articulate the specific risks of "agentic AI," and the future where third-party security products use AI to automatically personalize themselves to your environment, eliminating the need for manual tuning .Questions asked:(00:00) Introduction: The "Most Innovative" Episode Ever(01:40) DeepMind's CodeMender: Autonomously Finding & Patching Vulnerabilities(05:00) The "Build vs. Buy" Debate: Can You Just Slap an LLM on It?(06:50) The Prototype Trap: Why Internal AI Tools Fail at Scale(11:15) The "Data Lake" Argument: Can You Replace a SIEM with DIY AI?(14:30) Bank of America vs. Capital One: Are Banks Building AI Products?(18:30) The Failure of Traditional Threat Intel & Building Your Own(23:00) Perverse Incentives: Why Teams Build AI Tools for Promotions & Budget(26:30) The Coming AI Bubble Pop & The Fate of "AI Wrapper" Startups(31:30) AI Sprawl: Repeating the Mistakes of Cloud Adoption(33:15) The Frustration with "Agentic AI" Hype & Buzzwords(38:30) The Future: AI Platforms & Auto-Personalized Security Products(46:20) Secure Coding as a Black Box: The End of DevSecOps? | — | ||||||
| 11/6/25 | Inside the 29.5 Million DARPA AI Cyber Challenge: How Autonomous Agents Find & Patch Vulns | What does it take to build a fully autonomous AI system that can find, verify, and patch vulnerabilities in open-source software? Michael Brown, Principal Security Engineer at Trail of Bits, joins us to go behind the scenes of the 3-year DARPA AI Cyber Challenge (AICC), where his team's agent, "Buttercup," won second place.Michael, a self-proclaimed "AI skeptic," shares his surprise at how capable LLMs were at generating high-quality patches . However, he also shared the most critical lesson from the competition: "AI was actually the commodity" The real differentiator wasn't the AI model itself, but the "best of both worlds" approach, robust engineering, intelligent scaffolding, and using "AI where it's useful and conventional stuff where it's useful" .This is a great listen for any engineering or security team building AI solutions. We cover the multi-agent architecture of Buttercup, the real-world costs and the open-source future of this technology .Questions asked:(00:00) Introduction: The DARPA AI Hacking Challenge(03:00) Who is Michael Brown? (Trail of Bits AI/ML Research)(04:00) What is the DARPA AI Cyber Challenge (AICC)?(04:45) Why did the AICC take 3 years to run?(07:00) The AICC Finals: Trail of Bits takes 2nd place(07:45) The AICC Goal: Autonomously find AND patch open source(10:45) Competition Rules: No "virtual patching"(11:40) AICC Scoring: Finding vs. Patching(14:00) The competition was fully autonomous(14:40) The 3-month sprint to build Buttercup v1(15:45) The origin of the name "Buttercup" (The Princess Bride)(17:40) The original (and scrapped) concept for Buttercup(20:15) The critical difference: Finding vs. Verifying a vulnerability(26:30) LLMs were allowed, but were they the key?(28:10) Choosing LLMs: Using OpenAI for patching, Anthropic for fuzzing(30:30) What was the biggest surprise? (An AI skeptic is blown away)(32:45) Why the latest models weren't always better(35:30) The #1 lesson: The importance of high-quality engineering(39:10) Scaffolding vs. AI: What really won the competition?(40:30) Key Insight: AI was the commodity, engineering was the differentiator(41:40) The "Best of Both Worlds" approach (AI + conventional tools)(43:20) Pro Tip: Don't ask AI to "boil the ocean"(45:00) Buttercup's multi-agent architecture (Engineer, Security, QA)(47:30) Can you use Buttercup for your enterprise? (The $100k+ cost)(48:50) Buttercup is open source and runs on a laptop(51:30) The future of Buttercup: Connecting to OSS-Fuzz(52:45) How Buttercup compares to commercial tools (RunSybil, XBOW)(53:50) How the 1st place team (Team Atlanta) won(56:20) Where to find Michael Brown & ButtercupResources discussed during the interview:Trail of BitsButtercup (Open Source Project)DARPA AI Cyber Challenge (AICC)Movie: The Princess Bride | — | ||||||
| 10/23/25 | Anthropic's AI Threat Report: Real Attacks, Simulated Competence & The Future of Defense | Anthropic's August 2025 AI Threat Intelligence report is out, and it paints a fascinating picture of how attackers are really using large language models like Claude Code. In this episode, Ashish Rajan and Caleb Sima dive deep into the 10 case studies, revealing a landscape where AI isn't necessarily creating brand new attack vectors, but is dramatically lowering the bar and professionalizing existing ones.The discussion covers shocking examples, from "biohacking" attacks using AI for sophisticated extortion strategies , to North Korean IT workers completely dependent on AI, simulating technical competence to successfully gain and maintain employment at Fortune 500 companies . We also explore how AI enables the rapid development of ransomware-as-a-service and malware with advanced evasion, even by actors lacking deep technical skills .This episode is essential for anyone wanting to understand the practical realities of AI threats today, the gaps in defense, and why the volume might still be low but the potential impact is significant.Questions asked:(00:00) Introduction: Anthropic's AI Threat Report(02:20) Case Study 1: Biohacking & AI-Powered Extortion Strategy(08:15) Case Study 2: North Korean IT Workers Simulating Competence with AI(12:45) The Identity Verification Problem & Potential Solutions(16:20) Case Study 3: AI-Developed Ransomware-as-a-Service (RaaS)(17:35) How AI Lowers the Bar for Malware Creation(20:25) The Gray Area: AI Safety vs. Legitimate Security Research(25:10) Why Defense & Enterprise Adoption of AI Security is Lagging(30:20) Case Studies 4-10 Overview (Fraud, Scams, Malware Distribution, Credential Harvesting)(35:50) Multi-Lingual Attacks: Language No Longer a Barrier(36:45) Case Study: Russian Actor's Rapid Malware Deployment via AI(43:10) Key Takeaways: Early Days, But Professionalizing Existing Threats(45:20) Takeaway 2: The Need for Enterprises to Leverage AI Defensively(50:45) The Gap: Security for AI vs. AI for SecurityResources discussed during the interview:Anthropic - Threat Intelligence Report August 2025 | — | ||||||
| 10/18/25 | How Microsoft Uses AI for Threat Intelligence & Malware Analysis | What if the prompts used in your AI systems were treated as a new class of threat indicator? In this episode, Thomas Roccia, Senior Security Researcher at Microsoft, introduces the concept of the IOPC (Indicator of Prompt Compromise), sharing that "when there is a threat actors using a GenAI model for malicious activities, then the prompt... is considered as an IOPC".The conversation dives deep into the practical application of AI in threat intelligence. Thomas shares details from his open-source projects, including NOVA, a tool for detecting adversarial prompts, and an AI agent he built to track the complex money laundering scheme from a $1.4 billion crypto hack . We also explore how AI is dramatically lowering the barrier to entry for complex tasks like reverse engineering, turning a once-niche skill into something accessible to a broader range of security professionals .Questions asked:(00:00) Introduction(02:20) Who is Thomas Roccia?(03:20) Using AI for Reverse Engineering & Malware Analysis(04:30) Building an AI Agent to Track Crypto Money Laundering(11:30) What is an IOPC (Indicator of Prompt Compromise)?(14:40) MITRE ATLAS: A TTP Framework for LLMs(18:20) NOVA: An Open-Source Tool for Detecting Malicious Prompts(23:15) Using RAG for Threat Intelligence on Data Leaks(31:00) Proximity: A New Scanner for Malicious MCP Servers(34:30) Why Good Ideas are Now More Valuable Than Execution(35:30) Real-World AI Threats: Stolen API Keys & Smart Malware(40:15) The Challenge of Building Reliable Multi-Agent Systems(48:20) How AI is Lowering the Barrier for Reverse Engineering(50:30) "Vibe Investigating": Assisting the SOC with AI(54:15) Caleb's Personal AI Agent for Document OrganizationResources discussed during the call:NOVA- The Prompt Pattern MatchingDEF CON 33 Talk - Where’s My Crypto, Dude? The Ultimate Guide to Crypto Money Laundering | — | ||||||
Showing 25 of 60
Pitch Fit is a Pro feature
See how bookable this show is for guests, which brands already advertise, the per-episode ad value, and the best-fit guest and sponsor profile. The numbers are blurred on the free plan.
How readily this show books outside guests like you.
How proven this show is for host-read sponsorships.
For Guests
ProFor Advertisers
ProUpgrade to Pro to unlock guest cadence, sponsor categories, fit scores, and per-episode ad value for this show.
Chart history for AI Security Podcast
Peaked at #69 in HK, currently #69 in HK.
| Market | Genre | Peak | Current | Trend |
|---|---|---|---|---|
| HK | — | #69 | #69 | — |
| Mexico | — | #135 | #135 | — |
| United Kingdom | — | #172 | #172 | — |
Chart Positions
3 placements across 3 markets.
Chart Positions
3 placements across 3 markets.