AI upends the idea that systems have fixed roles.
Managing Senior Consultant Shad Malloy on why traditional threat modeling starts to fall apart with agentic AI and how frameworks like MAESTRO help fill the gap.
His advice: https://t.co/bjSjZsyeb1
Tony West shares what it was actually like building Joro with AI-assisted development, including where the models helped and where they completely hallucinated integrations.
Full story: https://t.co/ln1u0IFX4q
A failed login should not take 6 seconds.
Observed in the wild roughly 36 hours after disclosure.
Upgrade to 1.83.7 or higher.
Full analysis: https://t.co/jQctWd2EY2
“What if consumers were never the real target?”
Sergio Villegas (me) and John Untz discuss the recent Daemon Tools supply chain compromise and why consumers may have just been collateral damage.
Full episode: https://t.co/kfaqBNd3Xj
NIST is changing CVE enrichment.
You still get the vulnerabilities.
You just get less context for many of them.
So what does a security team do with this?
Senior Managing Operator Richard Brown breaks it down: https://t.co/DkROkHY9aJ
AI has gotten way better at finding and exploiting vulnerabilities.
Claude Mythos Preview shows the gap between discovery and exploitation is shrinking fast.
So what's that mean for your organization: https://t.co/s3EWoR5yCd
What does "continuous validation" mean in the AI age? It's more than just frequent pen tests; it involves leveraging AI effectively alongside human insight. Check out our session on AI Security in the Age of Project Glasswing and GPT-5.4 Cyber: https://t.co/etoxzYQqf4
Where to focus next? Big shifts in security change how teams think about risk.
Our recent conversation around Project Glasswing got practical.
Full episode: https://t.co/jNtrFPuytB
Why do smart people fall for seemingly obvious attacks?
Because attackers are really exploiting human behavior.
@AletheDenis explains how trust, urgency, and cognitive overload create a “cycle of compliance.”
https://t.co/uDCYSrtP8L
Modern social engineering is way more than just phishing.
Think deepfakes, voice cloning, and real-time impersonation designed to exploit trust and urgency.
Join @AletheDenis to learn about modern deception tactics and how to defend against them.
https://t.co/fNPtp0x81m
If phishing kits can steal session tokens, are we still having the wrong conversation about MFA bypass?
Leron Gray on why security is (and always will be) a cat-and-mouse game.
Full episode: https://t.co/bRdkAuGokK