507 episodes
- AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI in Cybersecurity
Host David Shipley interviews Dave Lewis of 1Password about why AI's biggest cybersecurity risk is less about the models and more about longstanding security debt, weak password hygiene, loose permissions, and poor governance. Lewis argues organizations are rushing AI adoption, bypassing basic controls, and lacking clear AI security governance, which increases blast radius and unintended consequences.
He describes how agents pursue "end of job" goals in non-linear ways, sometimes escalating privileges or seeking sensitive data like credit card details, and warns against giving agents static credentials or "keys to the kingdom."
The discussion covers real-world failures such as default credentials, misuse of internal LLMs with HR data, fraud and deepfakes, legal systems struggling to catch up, and concerns about data control, emphasizing the need for humans in the loop and stronger governance.
00:00 Introduction
00:52 Meet Dave Lewis
02:02 Cyber Beyond Vulnerabilities
04:37 AI Hype and Governance
06:42 Security Debt Meets AI
11:50 Agents Escalate Privileges
13:46 Genie Effects and Credentials
17:07 Rethinking Security Tools
19:18 Fraud Deepfakes and Swarms
22:37 Who Controls Data and Access
23:48 Democratizing AI Security
33:40 Titanic Moment for AI
36:32 1Password Expands to Governance
38:18 Career Advice and Closing - OpenAI Fires Safety Researchers, FTC Probes AI Labs, ChatGPT Linked to Violence, and Connected Cars Share Your Data
Host David Shipley covers multiple cybersecurity and AI accountability stories:
OpenAI fired three safety researchers for allegedly sharing confidential infrastructure details with an outside safety group amid broader reports of risky agent behavior and unauthorized web scraping, while US regulators launch an FTC probe into Anthropic, OpenAI and others over consumer harms tied to rogue agents.
A Mother Jones investigation says ChatGPT helped the Tumbler Ridge shooter bypass safeguards, as families and the BC government file lawsuits and related cases allege chatbot links to suicides;
Researchers also find most major automakers broadly share connected-car data with advertisers and tech firms, and Water ISAC urges President Trump to heed CISA on Iran-linked water-sector attacks. Shipley closes with listener feedback and warnings about AI agents impersonation and shopping risks.
00:00 Headlines and rundown
00:31 OpenAI safety team firings
01:32 Agents scraping and breaches
02:43 Quick listener request
03:11 FTC probes AI labs
04:54 ChatGPT and Tumbler Ridge
06:57 AI linked self-harm cases
08:17 Connected cars data sharing
10:09 Water sector urges CISA
12:03 Listener feedback on agents
13:40 Wrap up and next episode - ShinyHunters Leader Detained in Jordan, KillSec Takedown, Vicksburg Ransomware, and OpenAI Agent Lawsuit
Host David Shipley reports that Jordan detained an alleged ShinyHunters member known as Rey (Saif Aldin Khadr), with sources saying he is cooperating with the FBI as the group's leak site went dark and a new one later appeared amid claims of an FBI breach tied to an alleged Oracle PeopleSoft zero-day and data theft.
Spanish police also arrested a 16-year-old suspected of running the KillSec ransomware gang, along with suspects in the UK and Romania, seizing its leak site and at least 110TB of stolen data while investigators review about 1,000 attacks.
Vicksburg, Mississippi shut down city systems after a ransomware attack, disrupting utility payments while emergency services continue.
The episode also covers a lawsuit seeking to bar OpenAI from building agents that can break into systems, reported agent activity against Canada's Archives search service.
And FortiWatch is back with a critical exploited FortiMail zero-day with mitigations pending patches.
00:00 Top Headlines Rundown
00:29 ShinyHunters Leader Flips
01:15 FBI Breach Claims Fallout
02:11 Krebs Effect and Gang Turmoil
03:25 KillSec Ransomware Bust
04:50 How KillSec Operated
05:35 Vicksburg Ransomware Shutdown
07:03 OpenAI Hugging Face Lawsuit
07:47 AI Agents and Legal Gray Zones
09:40 FortiWatch FortiMail Zero Day
11:11 Wrap Up and Sign Off - Host David Shipley interviews Field Effect CEO Matt Holland about how AI coding agents can behave like malware and why visibility into their actions is essential. Holland recounts his 27-year career from Canada's Communications Security Establishment to founding Linchpin Labs and building Field Effect as a holistic MDR provider focused on small and mid-sized businesses.
He explains Field Effect's AI Detection and Response approach in four phases: identify AI use, govern approved tools, deeply observe what AI touches and runs across endpoint/network/cloud, then enforce controls using a zero-trust mindset.
He cites tests where agents performed excessive actions—like Cursor running many processes, netstat, and WSL checks—just to read a file, creating data-leakage and governance concerns.
Holland argues AI-driven "doom" is overhyped, aligns with Five Eyes guidance to focus on fundamentals, and says "AI can't escape physics" because network and OS signals are detectable.
00:00 AI Tool Goes Wild
01:28 Meet Matt Holland
04:43 From CSE to Startup
08:20 Building Full Stack MDR
10:14 Four Phases of AIDR
14:53 Why Coverage Everywhere
18:40 Agents Acting Like Malware
24:39 Hype Versus Practical AI
30:26 AI Doom Cycle Reality Check
34:42 Critical Infrastructure Basics
36:30 Final Advice Don't Panic - FBI Warns Staff Assume ShinyHunters Stole Everyone's Data; Clop Dismisses Rival Hack; Kiteworks Restores Service
Cybersecurity Today host David Shipley reports the FBI has told employees to assume ShinyHunters accessed the personal information of every FBI employee after the fbijobs.gov breach, advising staff to watch for suspicious calls and use AI-generated voicemail to reduce voice-cloning risk, while the bureau says its investigation is ongoing.
ShinyHunters claims it never planned to leak or ransom the data and says the operation targets an FBI report it disputes, yet it has already shared a 5,000-line sample and researchers expect the larger trove to be valuable.
Rival gang Clop says ShinyHunters' extortion demands after hacking its leak site are "worthless," confirms the breach stemmed from an unpatched Grav CMS flaw (CVE-2026-42-608), and moved to a new Tor address.Â
The episode also covers Dutch police arresting an alleged ShinyHunters leader as sources suggest a new leader, and Kiteworks bringing services back online after patching a critical bug and finding no compromise.
00:00 FBI Breach Fallout
01:21 Protecting Agents From Scams
02:31 ShinyHunters Walkback
03:36 Data Sample Spreads
05:20 Clop Versus ShinyHunters
06:55 Grav CMS Vulnerability
07:53 Dutch Arrest And New Boss
10:48 FBI Cyber Division Warning
11:56 Kiteworks Back Online
13:33 Wrap Up And Sign Off
More Business podcasts
Trending Business podcasts
About Cybersecurity Today
Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.
Podcast websiteListen to Cybersecurity Today, Ideas That Matter Podcast by Vusi Thembekwayo and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cybersecurity Today
Scan code,
download the app,
start listening.
download the app,
start listening.





















