3493 episodes
Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612
2026/09/01 | 33 mins.Victorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-612Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398
2026/09/01 | 1h 8 mins.AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable.
Segment Resources
https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt
Vulnerability discovery and remediation gap in the AI era
AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn’t necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice.
Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security
AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation.
Segment Resources:
https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/
https://orca.security/platform/ai-appgen-security/
This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them!
Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd
Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch.
Segment Resources:
https://www.bugcrowd.com/products/pathseeker/
https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/
https://www.bugcrowd.com/products/platform
https://www.bugcrowd.com/products/ai-powered-security-intelligence/
Apply for early access at https://securityweekly.com/bugcrowdbh
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-398Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474
2026/08/31 | 1h 36 mins.Interview with Dan Meacham, CISO at Legendary Entertainment
Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh.
Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out!
Visit https://securityweekly.com/infosecworld2026 and save 30% on your ISW pass with code: ISW26-SWSAVINGS
Black Hat Interview 1 - Google Cloud
Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google
The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google’s own approach to combating today’s threats and the need for security teams to transform vulnerability management with machine-speed defense.
Segment Resources:
https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense
https://services.google.com/fh/files/misc/ebookgooglecloudsecurityaithreatdefense.pdf
https://services.google.com/fh/files/misc/whitepapercombatingaidriventhreatsgooglemachinespeed_defense.pdf
This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlebh to learn more!
Black Hat Interview 2 - Forcepoint
Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint
AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety.
Segment Resources:
https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security
https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security
This segment is sponsored by Forcepoint. Visit https://securityweekly.com/forcepointbh to learn more!
Black Hat Interview 3 - Keyfactor
From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy & AI Innovation at Keyfactor
As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments.
Segment Resources:
https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/
https://www.keyfactor.com/education-center/what-is-trust-infrastructure/
https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&pfsid=HsCXvwPWB1
This segment is sponsored by Keyfactor. Visit https://securityweekly.com/keyfactorbh to learn more!
Black Hat Interview 4 - Delinea
Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea
As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session.
This segment is sponsored by Delinea. Visit https://securityweekly.com/delineabh to learn more!
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-474- Most enterprise AI today is a conversation — it summarizes, suggests, recommends. Harman unpacks what changes when AI actually executes across endpoints, and the governance problem that creates. Where does the human stay in the loop, and where do they get out of the way?
This segment is sponsored by Tanium. Visit https://securityweekly.com/tanium to learn more about them!
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-611 - Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do.
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
In the security news this week:
Sixteen-year-old Linux LPEs still work
Ubiquiti UniFi, patch it, also light on details
If you remember magicJack, you too are old
Slovakia doesn't trust its own speed cameras
More homework on NIST's vulnerability database
Your webcam, mic, and key light, all owned
Printer moonlights as Minecraft server
Zombie credit cards
Your car's infotainment system fuels botnets
Feds warn about AI-powered PLC attacks
Can an AI actually reverse engineer its way out?
Denver International's security breach, volume six
Charlotte's breach and a parking company
Why your ancient tech might be the safe one
Microsoft counts billions of phishing emails
A password vault that leaked to any website
Australia sells password books at the post office
Another perfect ten, this time in Entra ID
Cisco's bug scores read like Olympic gymnastics
Visit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-941
More News podcasts
Trending News podcasts
About Security Weekly Podcast Network (Audio)
Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.
Tune in for in-depth panel discussions, expert guest interviews, and breaking news on the latest hacking techniques, vulnerabilities, and industry trends. Stay informed and secure with the most trusted voices in cybersecurity!
Podcast websiteListen to Security Weekly Podcast Network (Audio), Candace and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Security Weekly Podcast Network (Audio)
Scan code,
download the app,
start listening.
download the app,
start listening.
Security Weekly Podcast Network (Audio): Podcasts in Family




























