Award Winning Top 10 Ranked CyberSecurity Podcast in US,UK and Aus. Learn Cloud Security in Public Cloud the unbiased way from CyberSecurity Host: @hashishrajan
Everyone's buying AISPM.
Almost no one can stop an agent going off the rails.
Full inventory. Total visibility. And no way to step in when the agent goes wrong.
Posture is not prevention.
@varonis#cloudsecurity#aisecurity
Your AI agents are unvetted employees.
You didn't train them. You didn't vet them. And they act with your access.
Rob's fix: apply the same controls you'd apply to a human. Vetting, training, limits.
He vibe-coded agents himself. One went off the rails
@Mimecast#aiagents
85% of your mission-critical apps run in a browser.
That browser was built to monetize you. Not your business.
SaaS apps. Sensitive data. IP. All running through a browser engineered to serve ads.
@island_io
You can switch on AI tooling for your non-technical teams in an afternoon. The visibility you lose takes much longer to notice.
That's modern third-party risk: the vendor isn't always outside your building anymore.
@Lovable
Someone told Claude Code to find open S3 buckets in their AWS account.
It tried. Failed. Tried again. Failed.
Then reached for Prowler on its own, without being told to.
Toni De La Fuente: AI isn't magic. When it hits its limits it looks for the right tool.
@ToniBlyx
Most organisations have accepted by design that they're not covered.
Not because they lack tools. Because the tools catch high and critical alerts.
Most breaches don't hide there.
They hide in the low and no signal events.
#cloudsecurity#CISO
When a vendor ships a patch, they ship the blueprint of the vulnerability.
AI reconstructs that blueprint and builds the exploit from it.
CVE to exploitation: 1.5 years in 2020.
Now under 24 hours.
The patch isn't buying you the time you think.
@EppSecurity@sysdig
10,000 identities. 22 million attack paths.
Once an attacker is on your system they don't need your password.
They don't need your MFA.
They just ride your authentication.
30 years of trust model, diluted the whole time.
@SpecterOps
Remediation has been a problem in security forever.
Two teams measured differently.
Security: how fast did you find it?
Remediation: how fast did you patch it?
Neither measured on how long it was exploitable.
#cloudsecurity#CISO@brinqa
An organisation built an AI app for internal use.
Developer said: it's internal. Nobody can access that.
Someone got in. Reached internal data. Exfiltrated it.
Not a sophisticated attack. Just an assumption that "internal" meant safe.
#cloudsecurity#CISO@PaloAltoNtwks
A prompt injection contest was run at a security company.
They expected security professionals to win.
Teenagers cleaned everyone's clock.
Security pros are constraint thinkers
Teenagers have no concept of constraints.
The attack surface isn't technical anymore.
@CheckPointSW
An org took 284 days to recover from ransomware.
Six months later same group hit them again.
The backdoor came back with the restore.
Most orgs can tell you when their last backup ran.
Very few can tell you when the attacker first got in.
That gap is the problem.
@Commvault
The assumption most vuln programmes were built on is gone.
That you'd have time between discovery and exploitation.
Months went down to weeks. In some cases seconds.
Sophisticated attacks no longer require sophisticated attackers.
#cloudsecurity#CISO@brinqa
Everyone complains about AI hallucinations in security.
Have you ever worked a 3am shift?
Humans hallucinate too. You misread an alert because you didn't have the right context.
An agent does the same thing for the same reason.
@runpanther@jack_naglieri
AI guardrails are dead.
They were built as perimeter checks. Block prompt injection at the entry point.
But with agentic AI the attack surface isn't at the entry point anymore.
#cloudsecurity#AIsecurity#CISO@CheckPointSW@LakeraAI
An HR employee opened WhatsApp.
Activated Meta AI inside it.
Started feeding patient records into it for a summary.
Unsanctioned AI. Inside a sanctioned app. With HIPAA data.
how would you even write an IR rule to stop that?
#cloudsecurity#CISO@Ent_Security
Security can't keep being the blocker.
Joe Sullivan says the number one trait for the next gen security team is curiosity.
@sgerlach's anti-pattern: needs procedures. Stays in the box.
@StackHawk
Offence already has YOLO mode.
Give AI the objective. Get out of the way. Come back when you find a zero day.
Defence is still asking a human to approve every step.
@EppSecurity , CISO at @sysdig , asks
What does YOLO mode look like for cybersecurity?
#cloudsecurity#CISO
Inception to production in less than three days.
Including testing. Including everything.
Your security programme was built for a deployment cadence that no longer exists.
#cloudsecurity#CISO@PaloAltoNtwks