Skip to content
PodcastsEducationEnterprise Security Weekly (Audio)

Enterprise Security Weekly (Audio)

Adrian Sanabria
Enterprise Security Weekly (Audio)
Latest episode

493 episodes

  • Enterprise Security Weekly (Audio)

    Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475

    2026/09/07 | 1h 45 mins.
    Interview - Amit Assaraf
    As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation.
    This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them!
    Topic - The British Library Cyber-Attack
    For this week's topic segment, we're discussing the British Library cyber-attack.
    In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library's £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization's tech debt comes due at once.
    Resources
    https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library
    The Weekly Enterprise News
    Finally, in the enterprise security news,
    We check the vibes
    the funding
    the acquisitions
    and the closures
    is the vulnpocalypse real, or not?
    TeamPCP finds out why being perpetually online isn't great if you're doing cybercrimes
    millions of IDs get leaked online
    What's the bigger story: Huggingface and NVIDIA or Microduck?
    Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode!
    All that and more, on this episode of Enterprise Security Weekly.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-475
  • Enterprise Security Weekly (Audio)

    Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474

    2026/08/31 | 1h 36 mins.
    Interview with Dan Meacham, CISO at Legendary Entertainment
    Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh.
    Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out!
    Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS
    Black Hat Interview 1 - Google Cloud
    Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google
    The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense.
    Segment Resources:
    https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense
    https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf
    https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf
    This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more!
    Black Hat Interview 2 - Forcepoint
    Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint
    AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety.
    Segment Resources:
    https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security
    https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security
    This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more!
    Black Hat Interview 3 - Keyfactor
    From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor
    As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments.
    Segment Resources:
    https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/
    https://www.keyfactor.com/education-center/what-is-trust-infrastructure/
    https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1
    This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more!
    Black Hat Interview 4 - Delinea
    Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea
    As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session.
    This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more!
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-474
  • Enterprise Security Weekly (Audio)

    Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473

    2026/08/24 | 1h 39 mins.
    Interview with Rob Allen from Threatlocker
    Safely enabling agentic AI for Businesses
    OpenClaw was the wakeup call and businesses wanted to know how to block it. "Easy," Rob Allen said, "it's already blocked if you're using Threatlocker." Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely.
    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
    Topic Segment
    For this week's topic segment, we're discussing AI pentesting agents and how likely they are to get you into big legal trouble. You came home from Black Hat with a new, shiny AI pentesting agent. How can you be sure it isn't hacking the wrong company?
    News Segment
    Finally, in the enterprise security news,
    we check the vibes
    New MCP standard and AI text watermarking
    what does combatting "cyber-enabled crime" mean?
    A closer look at Cl0p
    One 3rd party was responsible for all the AI sandbox escapes and hacking
    reports
    vulnerabilities
    Comcast can track your movements with WiFi
    A novel solution to the AI datacenter water use concerns
    All that and more, on this episode of Enterprise Security Weekly.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-473
  • Enterprise Security Weekly (Audio)

    Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472

    2026/08/17 | 1h 42 mins.
    Interview with Jon Hladik - ChatMate
    Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security.
    Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that enabled full takeovers of Microsoft Copilot sessions through sandbox escapes. He explores the technical journey behind the eight critical CVEs uncovered by Rubrik Zero Labs and discusses the broader implications for securing generative AI assistants within enterprise environments. This interview highlights the groundbreaking research that earned a $48,000 bounty and featured as a premier briefing at Black Hat USA.
    Segment Resources:
    Find more research from Rubrik Zero Labs
    Rubrik Zero Labs' Black Hat session
    Demo of the ChatMate attack in action
    This segment is sponsored by Rubrik. Visit https://securityweekly.com/rubrik to learn more about them!
    Topic Segment - AI Notetakers and Recorders
    AI notetakers are built into everything now, and hardware-based AI recorders are becoming mainstream as well. Is privacy over in the workplace? Adrian, Jackie, Katie, and Tyler discuss.
    Questions enterprises should be asking:
    Are employees recording or transcribing meetings?
    Does this policy change if non-employees (external parties) are present?
    Is consent asked for/given?
    Is the context of the conversation taken into consideration?
    Is the geographic/legal/political context of the external party taken into account?
    Have you done your due diligence on third parties hosting/storing these recordings and transcriptions?
    Was your due diligence a SOC 2, or real, actual evidence-based due diligence?
    Do these third parties have an option to allow you to store/manage your own recordings in a place of your choosing, or does it have to be hosted by the AI recording/transcription company?
    News Segment
    Finally, in the enterprise security news,
    we check the vibes
    and the funding, and the acquisitions
    seriously, don't mess with the wifi on planes
    181,000 meetings were left wide open
    the sandbox escapes are getting ridiculous
    research on how reliable AI-generated patches are
    research on what attackers do after they get a shell
    research on how cybercriminals are using AI agents
    research on how vulnerable datacenters are
    and finally, what's a "mouthpad"?
    Stick around till the end of the news segment to find out!
    All that and more, on this episode of Enterprise Security Weekly.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-472
  • Enterprise Security Weekly (Audio)

    Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471

    2026/08/10 | 1h 37 mins.
    Interview 1: Robin Macfarlane from RRMac Associats
    The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility
    In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why?
    We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape.
    Interview 2 with Kyle Sandy from Logically
    Operational Clarity as the New Customer Experience
    Kyle Sandy joins Adrian to discuss how prioritizing resilience affects how organizations should plan for incident response. In the past, security teams were focused on prevention and limiting breach damage. Today, boards want to know how long it will take to recover operations.
    The interview wraps up with a discussion of the right and wrong way to handle a breach and the three most important things every company must get right in order to handle an incident well.
    Interview 3 with Todd Thiemann from Omdia
    AI Agents and Identity Security: How Enterprises Are Rewriting the Rules
    Todd joins ESW with some eye-opening survey insights on the topic of IAM for AI agents. While cybersecurity conversations about internal AI use often revolve around the SOC and security operations, Omdia surveyed identity professionals for a more holistic enterprise perspective.
    Unsurprisingly, AI agent use is as diverse as enterprise business units. The surprises are around where the budget comes from for these AI projects, and how authentication is handled.
    Visit https://www.securityweekly.com/esw for all the latest episodes!
    Show Notes: https://securityweekly.com/esw-471
More Education podcasts
About Enterprise Security Weekly (Audio)
News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.
Podcast website

Listen to Enterprise Security Weekly (Audio), Know Thyself and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features