Home Podcasts The Adversarial Podcast
The Adversarial Podcast

The Adversarial Podcast

Jerry Perullo, Sounil Yu, Mario Duarte 59 Episodes Jul 21, 2026

Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the latest cybersecurity news. Each week, they discuss the most pressing headlines, offer candid commentary, and share unique insights from their extensive experience in the field.

Episodes

S4E22 – HuggingFace compromised by agentic attack, Gold Eagle program
S4E22 – HuggingFace compromised by agentic attack, Gold Eagle program Jul 21, 2026 3160 00:00 The Adversarial Podcast00:58 Hugging Face’s AI-driven incident disclosure 03:48 What makes an attack “AI-enabled” 06:04 Exploits, vulnerabilities, and bespoke code execution paths 10:03 AI attackers vs. AI defenders11:19 Verification asymmetry: attackers vs. defenders13:03 Detective controls, red teaming, and breach simulation 16:41 Why AI defenders matter 26:25 Gold Eagle / national coordin
S4E21 - Travel Security, AI Defense Matrix, Startup Security
S4E21 - Travel Security, AI Defense Matrix, Startup Security Jul 1, 2026 3993 In this episode, Jerry, Mario, and Sounil delve into cybersecurity challenges related to travel, threat models, AI security, and best practices for startups. They explore practical strategies for managing security risks in a rapidly evolving digital landscape, emphasizing the importance of threat modeling, secure coding, and organizational priorities.00:00 Intro01:55 Travel Restrictions and Securi
S4E20 - AI Executive Order, Project Glasswing Expanding, Cybersecurity Workforce
S4E20 - AI Executive Order, Project Glasswing Expanding, Cybersecurity Workforce Jun 9, 2026 3974 Promoting Advanced Artificial Intelligence Innovation and Security The White House EO pushes federal agencies toward AI-enabled cyber defense, frontier-model benchmarking, and a voluntary framework for trusted access to high-end AI systems. Expanding Project Glasswing Anthropic is widening Project Glasswing beyond its first cohort, giving more trusted security teams access to Claude Mythos Preview
S4E19 – Canvas hacked, Cloudflare layoffs, GitHub CVE rundown
S4E19 – Canvas hacked, Cloudflare layoffs, GitHub CVE rundown May 12, 2026 4152 Canvas hack strands university students during finals week. A Canvas cyberattack hit universities and K-12 schools during finals, locking students and teachers out of grades, assignments, lecture materials, and exams at the worst possible moment.Building for the future. Cloudflare says it is cutting more than 1,100 employees as it restructures around internal AI-driven workflows, even as the timin
S4E18 – Mythos and TPRM, does SOC 2 really work?
S4E18 – Mythos and TPRM, does SOC 2 really work? Apr 28, 2026 3926 00:34 - Introduction03:33 - Enterprise Challenges07:08 - End User and Browsers21:55 - Vulnerability Metrics40:37 - Approaching Leadership42:09 - TPRM Discussion46:40 - Sharing Findings01:03:04 - ConclusionMozilla: Anthropic’s Mythos found 271 security vulnerabilities in Firefox 150Anthropic’s Mythos found 271 zero-day vulnerabilities in Firefox 150 Mozilla let Anthropic’s Mythos loose on Firefox 1
S4E17 – Mythos, Delve's downfall, and supply chain attacks
S4E17 – Mythos, Delve's downfall, and supply chain attacks Apr 23, 2026 4138 Project Glasswing (https://www.anthropic.com/glasswing) Anthropic is letting AWS, Apple, Google, Microsoft, JPMorgan, Cisco, NVIDIA, and friends point Claude Mythos at their shared attack surface while backing it with $100M in credits and $4M for OSS security groups so blue teams can burn down latent vulns before the offense gets equivalent AI. Inside the TeamPCP cascading supply chain attack (htt
Special RSAC episode with Cloudflare - Cybersecurity and AI, CISO/Board dynamics, future of cybersecurity
Special RSAC episode with Cloudflare - Cybersecurity and AI, CISO/Board dynamics, future of cybersecurity Apr 14, 2026 2678 The Adversarial Podcast brings you a special episode in collaboration with Cloudflare's Security Signal Podcast.0:39 - 3:33 AI Governance and Autonomy 6:26 - 8:49 Human in the Loop 9:17 - 11:40 Cybersecurity and AI 15:26 - 18:19 Resilience and Anti-Fragility 28:24 - 33:05 Threat Intelligence 33:31 - 36:50 Board and CISO Dynamics 41:09 - 42:35 Future of Cybersecurity 42:35 - 44:14 Books and Resourc
S4E15 – RSAC, Iranian hackers, White House's Cyber Strategy and Cyber EOs, the Future of TPRM
S4E15 – RSAC, Iranian hackers, White House's Cyber Strategy and Cyber EOs, the Future of TPRM Mar 17, 2026 4192 Iran-linked hackers claim responsibility for attack on US medical device maker StrykerAttackers tied to Iran say they hit Stryker, and investors punished the stock as the company scrambled to assess exposure.Trump Signs Executive Order Aimed at Cybercrime GangsThe President issued an order to tide together federal tools, international partners, and private-sector incentives for hunting down and di
S4E14 – Federal Gov vs. Anthropic, 40% layoff at Blocks due to AI
S4E14 – Federal Gov vs. Anthropic, 40% layoff at Blocks due to AI Mar 3, 2026 3719 Claude Code Security research preview Claude now reasons about code like a human researcher, re-checks its own findings for confidence, and surfaces patch suggestions in a dashboard while keeping humans in control—limited preview for Enterprise/Team customers plus expedited access for open-source maintainers. Pentagon gives Anthropic a best-and-final offer With a deadline looming, the Pentagon dem
S4E13 – Munich Security Conference, hiring AI specialists, Gemini used by criminals
S4E13 – Munich Security Conference, hiring AI specialists, Gemini used by criminals Feb 18, 2026 4375 GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use Google’s threat team distills red-team learnings from sophisticated experimentation as it hardens defenses and anticipates adversarial AI backdoors.New Trump Cyber Strategy Prompts Companies to Mull Legal Limits The administration’s aggressive cyber doctrine is forcing firms to reconsider h
Adversarial Podcast S4E12 – Curl shuts down bug bounty program, most expensive security control that gave zero security
Adversarial Podcast S4E12 – Curl shuts down bug bounty program, most expensive security control that gave zero security Feb 5, 2026 4685 The end of the curl bug bounty program. Curl’s creator Daniel Stenberg announced the shutdown of the project’s bug-bounty program because overwhelming volumes of low-quality and AI-generated reports, coupled with bad-faith security submissions, impose excessive mental and time costs while providing little real improvement to the software.Changing Federal Reserve Regulations. The memo directs Feder
Adversarial Podcast S4E11 – Iran Internet blackout, threat intelligence briefings, cyber framework alignment
Adversarial Podcast S4E11 – Iran Internet blackout, threat intelligence briefings, cyber framework alignment Jan 20, 2026 4522 00:00 Intro 01:40 Iran's Internet blackout 48:06 U.S. Weighs Expanding Private Companies’ Role in Cyberwarfare 57:35 Aligning cybersecurity programs to frameworksThere's an internet blackout in Iran. How are videos and images getting out? During Iran’s nationwide internet blackout imposed amid widespread anti-government protests, some citizens have been using Elon Musk’s Starlink satellite service

Recommended