347 avsnitt
- Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.
Christopher is a cybersecurity practitioner and educator focused on security operations, incident response, threat hunting, and building and maturing security operations centers. He is the author of the annual SANS SOC Survey, a security operations class called SOC-Class, and a new book entitled The Value of Cybersecurity Operations. He is a Senior Instructor with the SANS Institute, a faculty member at IANS, and a consultant through Montance. His background also includes network operations, software development, mobile security assessment, and security policy.
Learn more at https://montance.com and get the book at https://shop.montance.com
Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.
This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at https://limacharlie.io/
Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps - Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.
No prep doc, no script: just what Matt and Chris were actually hearing on the floor.
• Shai-Hulud is back. The self-replicating npm worm returned on August 4, trojanizing the keyv / cacheable family and spreading to 400+ packages within hours. Chris reads through Datadog Security Labs' analysis of the Shai-Hulud 2.0 wave: 796 packages and 1,092 versions, 20M+ weekly downloads, credential harvesting with TruffleHog, GitHub repositories used for both exfiltration and command and control, and a worm that reads its own code to propagate without a C2 server.
• The LLM that downloaded the malicious package by itself. A researcher asked a frontier model about a compromised package, and the model decided the best way to help was to go fetch a copy — tripping the SOC's alert and bypassing the company's centralized package clearing house on the way.
• Non-human identity as the new perimeter. Every agent you introduce is another identity: who created it, what can it reach, how long should it live?
• "Computer says no." Matt's colleague hit a refusal from Opus 5, and the session automatically downgraded to 4.8 and completed the task. Which raises the real question of the episode: do security teams now need model pinning, the way we once needed certificate pinning? And if defenders pin to older models to keep working while adversaries use the newest ones, have we rebuilt the same gap all over again?
• AI governance and change control — which models are approved for which tasks, and what happens when a vendor ships a new version or deprecates an old one.
• Token spend as a CISO budget line item. Enterprises buying tokens at a scale their vendors can't match and pulling those vendors onto their plan, token burn as an insider-threat vector, and why $100,000 of tokens is not $100,000 of productivity.
• Defender takeaways: pin your npm packages, get security off its island and talk to your developers, build approved paths before detections, least privilege and key rotation, and network-gated pushes as a deliberate chokepoint.
Stories covered:
• https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain
• https://research.jfrog.com/post/shai-hulud-is-back-august/
• https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/
• https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/
• https://unit42.paloaltonetworks.com/npm-supply-chain-attack/
Chapters:
0:00 Live from Black Hat, in person for once
0:48 How Black Hat has changed
4:31 No prep — let's talk about what's actually happening here
4:57 Shai-Hulud is back: supply chain compromise
6:23 The LLM that downloaded the malicious package
7:19 Inside Shai-Hulud 2.0
10:34 When attackers and defenders use the same tools
11:39 Non-human identity is the new perimeter
12:13 Opus 5 said no, so the session downgraded itself
15:23 Do security teams need model pinning?
18:20 Three companies, very nebulous rules
18:35 AI governance: which model for which task
21:19 Token spend hits the security budget
22:58 Is token spend a productivity metric?
25:46 Pin your packages
26:25 Get security off the island
29:17 Least privilege, key rotation, chokepoints
32:55 Why it's called Shai-Hulud
33:25 Wrapping up at Black Hat
The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
Subscribe wherever you listen:
• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740
• YouTube: https://www.youtube.com/@limacharlieio
Learn more about LimaCharlie: https://limacharlie.io
#cybersecurity #infosec #threatintel #AIsecurity #supplychainsecurity Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]
2026-07-30 | 30 min.Intel Chat with Matt Bromiley and Chris Luft.
Matt and Chris break down four stories from the week in threat intel:
• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.
• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.
• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.
• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.
Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.
Stories covered:
• https://huggingface.co/blog/security-incident-july-2026
• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover
• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/
• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plant
Chapters:
0:00 Intro & Black Hat plans
2:07 Hugging Face's AI-agent breach disclosure
12:39 WP2Shell: WordPress exploit chain
20:59 Suno & Paidwork data breaches
24:17 IRGC strikes on AWS Bahrain
28:27 Google Threat Intel's new actor names
29:29 Black Hat swag hunt & wrap-up
The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
Subscribe wherever you listen:
• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740
• YouTube: https://www.youtube.com/@limacharlieio
Learn more about LimaCharlie: https://limacharlie.io
#cybersecurity #infosec #threatintel #AIsecurity #databreachIntel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]
2026-07-30 | 30 min.Intel Chat with Matt Bromiley and Chris Luft.
Matt and Chris break down four stories from the week in threat intel:
• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.
• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.
• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.
• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.
Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.
Stories covered:
• https://huggingface.co/blog/security-incident-july-2026
• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover
• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/
• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plant
Chapters:
0:00 Intro & Black Hat plans
2:07 Hugging Face's AI-agent breach disclosure
12:39 WP2Shell: WordPress exploit chain
20:59 Suno & Paidwork data breaches
24:17 IRGC strikes on AWS Bahrain
28:27 Google Threat Intel's new actor names
29:29 Black Hat swag hunt & wrap-up
The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
Subscribe wherever you listen:
• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740
• YouTube: https://www.youtube.com/@limacharlieio
Learn more about LimaCharlie: https://limacharlie.io
#cybersecurity #infosec #threatintel #AIsecurity #databreach- Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.
Rob is a global leader in AI security, software engineering, and international AI standards, with more than 30 years of experience in artificial intelligence. He has played a leading role in developing industry standards and serves as co-editor of the forthcoming European AI security standard supporting the EU AI Act. He is the founder of the OWASP AI Exchange, co-founder of OpenCRE, and has helped bring together standards organizations, industry, and the open-source community to advance practical approaches to secure AI.
Learn more at https://www.softwareimprovementgroup.com and https://owaspai.org
Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.
This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at https://limacharlie.io/
Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
Fler podcasts i Entreprenörskap
Trendiga poddar i Entreprenörskap
Om The Cybersecurity Defenders Podcast
An accessible but technical podcast about cybersecurity and the people who keep the internet safe. The podcast is built as a series of segments: we will be looking back at the last couple of weeks in cybersecurity news, talking to different people in the industry about areas of their expertise, we're going to break apart some of the TTPs being used by adversaries, and we will even cover a little bit of hacker history.
Podcast-webbplatsLyssna på The Cybersecurity Defenders Podcast, Framtidens E-Handel och många andra poddar från världens alla hörn med radio.se-appen

Hämta den kostnadsfria radio.se-appen
- Bokmärk stationer och podcasts
- Strömma via Wi-Fi eller Bluetooth
- Stödjer Carplay & Android Auto
- Många andra appfunktioner
Hämta den kostnadsfria radio.se-appen
- Bokmärk stationer och podcasts
- Strömma via Wi-Fi eller Bluetooth
- Stödjer Carplay & Android Auto
- Många andra appfunktioner


The Cybersecurity Defenders Podcast
Skanna koden,
ladda ner appen,
börja lyssna.
ladda ner appen,
börja lyssna.











