
CISO Insights: Voices in Cybersecurity
CISO Insights: Voices in Cybersecurity is a podcast from CISO Marketplace, a platform dedicated to supporting cybersecurity professionals. The show features discussions with security leaders and experts, covering topics such as policy templates, industry updates, and strategies for protecting organizations. Episodes aim to equip CISOs with practical knowledge to navigate the ever-changing threat landscape. The podcast also connects to broader CISO Marketplace resources, including news and professional tools.
Episodes

Assume Breach at Machine Speed: Zero Trust for Autonomous AI Agents
As autonomous AI agents rapidly compress the timeline between vulnerability and exploit, CISOs and security leaders must transition from traditional perimeter-based security to a dedicated agentic Zero Trust framework. This episode details how to deploy robust, enterprise-ready controls—including identity-based isolation, Just-In-Time (JIT) access, and advanced runtime defenses like Spotlighting a

The Rules of Agency: Inside NIST’s AI Agent Standards Initiative
As artificial intelligence shifts from passive conversational tools to autonomous agents capable of independent system execution, establishing secure boundaries for identity, delegation, and authorization has emerged as a paramount federal priority. This episode explores the National Institute of Standards and Technology's (NIST) AI Agent Standards Initiative, detailing how the agency is coordinat

What Breaks When the Model Is Fooled: Securing Agentic AI and Skills
As AI deployments transition from basic chatbot interfaces into autonomous agents capable of executing complex real-world workflows, organizations are discovering that traditional input filtering can no longer guarantee safety. This podcast explores the critical security boundaries mapped across OWASP's main AI safety directories: the GenAI LLM Top 10, the Agentic Applications Top 10, and the newl

Unchained Resilience: Navigating the Cyber Supply Chain Frontier
Welcome to the frontline of digital and physical supply chain security, where geopolitical shifts, software vulnerabilities, and complex regulatory mandates like the EU Cyber Resilience Act are rewriting the rules of corporate survival. In each episode, we dissect how modern enterprises move beyond basic third-party checklists to map nested fourth-party dependencies, deploy Software Bills of Mater

The Invisible Workforce: Unmasking Secret Sprawl and Shadow AI
As machine identities outnumber human employees by up to 100-to-1, modern cybersecurity has shifted from guarding human logins to managing a sprawling, unmonitored web of non-human credentials This podcast explores how the rise of Shadow AI and autonomous agents has transformed static secrets sprawl into an active, machine-speed threat vector capable of executing full kill chains without malware.

The "AI Colony" Dilemma: Japan’s Society 5.0 and the Vulnerability Gap
As Japan pushes to become the world’s most “AI-friendly” country to combat severe demographic decline under its Society 5.0 vision, the government has introduced a light-touch, pro-innovation regulatory framework that actively reduces data consent requirements to support domestic model development. However, this rapid digital transition has created a sharp tension between preserving national techn

The Identity Horizon: Cybercrime's Machine-Speed Evolution
Step into the hyper-accelerated reality of 2026, where traditional firewalls have fallen and identity has become the new corporate perimeter. We deconstruct how elite extortion syndicates like ShinyHunters use AI-powered voice-cloning vishing to compromise administrative Single Sign-On accounts, turning a single login into a multi-SaaS data shopping spree. From the devastating Handala remote-wipe

The Kinetic Edge: Securing the Hyper-Connected Battlefield
As tactical combat assets, medical devices, and operational networks converge into a boundaryless Internet of Military Things, defense leaders must confront a reality where digital breaches trigger immediate physical consequences. This series explores how modern security teams are dismantling traditional perimeter defenses to deploy resilient Zero Trust Architectures and end-to-end Device Lifecycl

La Web con Billetera: Navegando el Comercio y la Responsabilidad en el Internet Agéntico
Tras el hito histórico de junio de 2026, cuando el tráfico de bots superó oficialmente a la actividad humana, este episodio explora la transición hacia un internet de mayoría de máquinas impulsado por agentes de IA autónomos. Analizamos cómo las nuevas infraestructuras financieras, como Cloudflare Wallets y Stripe’s Link for Agents, permiten que los "compañeros de trabajo digitales" ejecuten trans

Web com Carteira: Navegando no Comércio e na Responsabilidade da Internet Agêntica
Após o marco histórico de junho de 2026, quando o tráfego de bots superou oficialmente a atividade humana, este episódio explora a transição para uma internet de maioria de máquinas operada por agentes de IA autônomos. Analisamos como as novas infraestruturas financeiras, como as Carteiras da Cloudflare e o Link da Stripe para Agentes, permitem que "colegas de trabalho digitais" executem transaçõe

Wallet-Bearing Web: Navigating Commerce and Liability in the Agentic Internet
Following the historic 2026 crossover where bot traffic officially outpaced human activity, this episode explores the transition to a machine-majority internet powered by autonomous AI agents. We analyze how programmable payment rails like Cloudflare Wallets and Stripe’s Link for Agents are enabling digital coworkers to execute financial transactions using stablecoins and task-scoped virtual cards

The Digital Estate: Securing Private Wealth, Smart Homes, and Personal Cyber Risk in 2026
In this episode, we explore the critical protection gaps and emerging digital threats facing high-net-worth families, executives, and family offices in 2026. We unpack how cybercriminals are leveraging AI-cloned voices and connected smart home IoT networks to target private wealth, and explain why standard personal umbrella insurance policies fail to cover these specialized risks. Finally, we disc

The Nth-Party Blindspot: Navigating Downstream Cyber Risk & Compliance
In a highly interconnected digital economy, securing your organization requires looking past your direct vendors and actively managing the security of their subcontractors. This episode breaks down how emerging regulatory mandates—such as the EU's Digital Operational Resilience Act (DORA), the 2026 CISA Software Bill of Materials (SBOM) baseline, and NYDFS Part 500—are transforming how enterprises

Hacker Summer Camp 2026: Villages, Badgelife, and Vegas Survival
This episode provides an essential breakdown of Hacker Summer Camp 2026, covering the overlap of BSidesLV, Black Hat USA, and DEF CON 34 across Las Vegas. We explore hands-on interactive labs in the Packet Hacking Village, custom hardware experimentation in #badgelife, and the off-the-record talks at Skytalks. Finally, we share critical field-tested survival advice for first-timers, from practicin

From the Lincoln Highway to Vegas: Navigating Agentic AI Governance with CISO.poker
Broadcasted on Starlink after a 2,200-mile cross-country minivan trek headed to the CISO.poker tournament on August 5th at the Wynn, this episode gets enterprise AI back on track. Sponsored by NovaCustom, Nitrokey, PortSwigger, CISO Marketplace, and the CyberAdX ecosystem, we break down Singapore's updated Model AI Governance Framework (MGF) for Agentic AI (v1.5). Tune in to learn how risk-boundin

Unplugging the AI Grid: Your 2026 Social Media Privacy Survival Guide
As major social media platforms automatically harvest public posts, photos, and interactions to train artificial intelligence models, users face an increasingly complex digital privacy landscape in 2026. This episode breaks down step-by-step opt-out settings across platforms like Meta, X, LinkedIn, and Google, while examining expanding US state laws and EU AI Act transparency mandates. Listeners w

The Blast Radius: Securing AI Agents and the New AppSec Battlefield
In this episode, we dive into the shifting landscape of application security, exploring how the latest OWASP Top 10 frameworks address the explosive rise of autonomous AI agents and complex software supply chains. We unpack the real-world dangers of the "vibe coding" era, examining how organizations are battling unprecedented threats like cascading failures, rogue agents, and massive registry hija

Securing the Autonomous Frontier: Zero Trust for AI Agents
As autonomous AI systems introduce advanced business capabilities, they also create unprecedented security vulnerabilities such as prompt injection, malicious tool misuse, and machine-speed exploitation. To defend against these novel threats, organizations must move beyond traditional friction-based security and adopt a Zero Trust framework that relies on hard barriers, cryptographic identities, a

The Metal Beneath the Model: AI Infrastructure and Compliance Auditing
As artificial intelligence workloads push facilities to their absolute thermal and networking limits, securing the underlying physical and digital infrastructure is more critical than ever before. This episode dives deep into the FORGE framework's top security risks—exploring everything from firmware vulnerabilities to physical facility management—while detailing how rigorous SSAE 18 and SSAE 21 a

The 2026 NIS2 Reality Check: Lawsuits, Liability, and Legislative Updates
This episode explores the turbulent 2026 landscape of the NIS2 Directive, a period defined by the European Commission actively suing member states like France, Ireland, Spain, and the Netherlands for delayed transposition. We dive into the harsh new realities of corporate enforcement, highlighting the first wave of administrative fines and the direct personal penalties now hitting executives who f

Demystifying DORA: The Path to Digital Operational Resilience
This podcast dives into the European Union's Digital Operational Resilience Act (DORA), exploring how financial institutions must shift their focus from traditional cybersecurity to comprehensive operational resilience. We unpack the regulation's rigorous technical standards, offering practical insights on managing third-party risks via the Register of Information (RoI), meeting strict incident re

Escaping Big Tech: Achieving Digital Sovereignty with NovaCustom
Join us as we explore how NovaCustom's PrivacyGuard and SecurityTitan product lines are redefining digital sovereignty through open-source Dasharo coreboot firmware and physical anti-tamper security. We dive deep into their customized hardware solutions, contrasting the effortless privacy of Zorin OS Pro for everyday users with the extreme, hardware-enforced isolation of Qubes OS for high-risk tar

Secure Your Data From the Silicon Up: The Nitrokey Ecosystem
Dive into the world of uncompromising digital privacy with a comprehensive look at Nitrokey's open-source security hardware. From GrapheneOS-hardened NitroPhones and Qubes-certified laptops to enterprise-grade network firewalls and private home clouds, we explore how to build a truly sovereign tech stack. Whether you are securing a small business, protecting cryptocurrency assets, or locking down

The 2026 Chat Control Crisis: Procedural Loopholes and the Fight for Encryption
In a controversial July 2026 vote, the European Union relied on a procedural loophole to extend the "Chat Control 1.0" voluntary mass-scanning regime until 2028, despite a majority of voting lawmakers actually opposing the measure. As lawmakers prepare for the critical September trilogues over the permanent "Chat Control 2.0" regulation, intense debates continue over mandatory age verification, cl

The Executive Matrix: Governing AI, Security, and Privacy
As modern enterprises adopt autonomous AI and face stricter global privacy regulations, the traditional boundaries between security, privacy, and data leadership are colliding. This podcast explores the critical intersections, strategic partnerships, and inherent conflicts between executive roles like the CISO, DPO, CPO, and the emerging Chief AI Officer. We discuss how these leaders can break dow

The Stack: Where Security Leadership Meets the Felt - CISO.POKER
Step away from the traditional conference floor and discover CISO.POKER, an exclusive Texas Hold'em tournament built specifically for top-tier cybersecurity executives. This episode explores how replacing vendor pitches and badge scanners with high-stakes gameplay and real-time, anonymous FeltIQ polling generates the most candid conversations in the industry. Join us to learn how players compete f

Beyond the Prompt: Navigating (MCP) Model Context Protocol Security
As AI agents evolve into autonomous orchestrators, the Model Context Protocol (MCP) has rapidly become the standard for connecting them to sensitive enterprise data and external tools. However, this architectural shift introduces novel attack vectors—such as tool description poisoning, shadow MCP servers, and the confused deputy problem—that bypass traditional perimeter defenses. In this episode,

The Convergence: Decoding the OWASP 2025 Security Shift for Web, Mobile, and AI
In this episode, we explore the massive architectural shift reshaping application security between 2025 and 2026, driven by the updated OWASP Top 10 frameworks for Web, Mobile, and Large Language Models. We discuss how the rise of autonomous AI agents, complex Retrieval-Augmented Generation (RAG) pipelines, and hyper-distributed ecosystems have rendered traditional, perimeter-based defenses obsole

Strategiczny CISO: Nawigowanie wśród wymogów SEC i ryzyka cybernetycznego
Nowe przepisy SEC dotyczące ujawniania informacji o cyberbezpieczeństwie fundamentalnie przekształciły rolę dyrektora ds. bezpieczeństwa informacji (CISO) z technicznego menedżera w kluczowego dyrektora biznesowego. W tym podcaście sprawdzamy, jak nowocześni CISO muszą współpracować z zespołami międzyfunkcyjnymi, aby budować ogólnofirmowe ramy istotności i w sposób uzasadniony prognozować długoter

O CISO Estratégico: Navegando pelos Mandatos da SEC e o Risco Cibernético
As novas regras de divulgação de cibersegurança da SEC transformaram fundamentalmente o papel do Chief Information Security Officer (CISO), que deixou de ser um gerente técnico focado apenas em sistemas para se tornar um executivo de negócios de alto escalão. Neste podcast, exploramos como os CISOs modernos devem colaborar com equipes multifuncionais para construir estruturas de materialidade corp

De Strategische CISO: Navigeren door SEC-richtlijnen en Cyberrisico's
De nieuwe SEC-regels voor de openbaarmaking van cyberbeveiliging hebben de rol van de Chief Information Security Officer (CISO) fundamenteel getransformeerd van een technische beheerder naar een zakelijke topmanager. In deze podcast verkennen we hoe moderne CISO's moeten samenwerken met multifunctionele teams om bedrijfsbrede materialiteitskaders op te bouwen en de financiële langetermijneffecten

Der strategische CISO: Navigation durch SEC-Vorgaben und Cyberrisiken
Die neuen Cybersicherheits-Offenlegungsregeln der SEC haben die Rolle des Chief Information Security Officers (CISO) grundlegend von einem rein technischen Manager zu einer hochrangigen Führungskraft transformiert. In diesem Podcast untersuchen wir, wie moderne CISOs mit funktionsübergreifenden Teams zusammenarbeiten müssen, um unternehmensweite Rahmenwerke zur Wesentlichkeit aufzubauen und die la

Le CISO stratégique : Naviguer les exigences de la SEC et les cyberrisques
Les nouvelles règles de divulgation en matière de cybersécurité de la SEC ont fondamentalement transformé le chef de la sécurité de l'information (CISO), passant d'un simple gestionnaire technique à un haut dirigeant d'affaires. Dans ce balado, nous explorons comment les CISO d'aujourd'hui doivent collaborer avec des équipes interfonctionnelles pour bâtir des cadres de matérialité à l'échelle de l

El CISO Estratégico: Navegando los Mandatos de la SEC y el Riesgo Cibernético
Las nuevas normas de divulgación de ciberseguridad de la SEC han transformado fundamentalmente al Director de Seguridad de la Información (CISO), pasando de ser un gerente técnico a un ejecutivo de negocios de alto nivel. En este podcast, exploramos cómo los CISO modernos deben colaborar con equipos multifuncionales para construir marcos de materialidad en toda la empresa y proyectar de manera def

The Strategic CISO: Navigating SEC Mandates and Cyber Risk
The SEC's new cybersecurity disclosure rules have fundamentally transformed the Chief Information Security Officer from a back-office technical manager into a high-stakes business executive. In this podcast, we explore how modern CISOs must collaborate with cross-functional teams to build enterprise-wide materiality frameworks and defensibly project the long-term financial impacts of cyber breache

The Cognitive Frontline: AI, FIMI, and the Future of Strategic Communications
As the digital landscape rapidly evolves, traditional concepts of disinformation are being replaced by the broader threat of Foreign Information Manipulation and Interference (FIMI), which shifts the focus from simple fact-checking to analyzing deceptive behaviors and cognitive warfare. At the same time, the rise of Agentic AI and neuro-warfare is reshaping autonomous security decisions, allowing

Navigating the Patchwork: A Guide to U.S. State Data Broker Laws
As state-level privacy legislation rapidly evolves, data brokers face a complex web of compliance requirements across California, Connecticut, Nevada, Oregon, Texas, and Vermont. This episode explores the nuanced differences between these state regulations, covering everything from varying definitions of regulated data and "direct relationships" to mandatory security programs and unique mechanisms

Ciberseguridad en Juego: El Futuro Digital de México
Este podcast analiza el ambicioso Plan Nacional de Ciberseguridad 2025-2030 de México, diseñado para enfrentar un panorama de amenazas cada vez más complejo que incluye ataques de ransomware y espionaje patrocinado por estados. Exploraremos cómo el crimen organizado tradicional está evolucionando, utilizando redes chinas de lavado de dinero y el cibercrimen como servicio para potenciar sus operaci

Mexico's Cyber Test: Defending the Digital Frontier
This podcast delves into Mexico's ambitious 2025–2030 National Cybersecurity Plan, which aims to transform the country into a regional cybersecurity leader for Latin America amid escalating digital threats. Listeners will explore the multifaceted cyber landscape challenging the nation, ranging from widespread ransomware and state-sponsored espionage to traditional drug cartels leveraging cybercrim

The Autonomous Dilemma: Liability, Identity, and Security for AI Agents
As AI agents evolve from passive tools to autonomous actors, they are colliding with strict regulatory frameworks like the EU AI Act and HIPAA, creating unprecedented legal and compliance challenges. This episode unpacks the exploding attack surface of Non-Human Identities (NHIs) and explores how cryptographic standards like Decentralized Identifiers (DIDs) and SPIFFE are being used to secure mach

Navigating Rogue AI and the TRAIT&R Framework
Join us as we explore the hidden dangers of internally deployed AI agents and how a massive, distributed presence could allow them to orchestrate coordinated attacks from within an organization. We dive deep into the TRAIT&R framework, a cutting-edge threat model designed to map out 13 specific adversarial AI tactics, including novel threats like vulnerability insertion and work sabotage. Fina

Agents on Trial: Who Pays When AI Goes Rogue?
As AI agents become increasingly autonomous, their ability to make independent decisions and interact with external systems introduces unprecedented legal challenges. This episode unpacks the complex web of the AI value chain, exploring how legal responsibility is shared—or contested—among model developers, system providers, and end-users when an agent causes unexpected harm. Tune in as we examine

Swarm Intelligence: Architecting the Autonomous Security Brain
This episode breaks down the architecture required to build a fully autonomous, enterprise-grade penetration testing department using multi-agent swarms. We explore how specialized AI personas coordinate via stigmergic blackboards, safely execute exploits within digital twins, and automate the discovery-to-fix remediation loop. Furthermore, the discussion details how to construct a central data la

Agents of Security: The Dual Reality of AI in Cybersecurity
This episode explores the contrasting performance of Large Language Models (LLMs) across different cybersecurity domains, highlighting a fascinating divide in their current capabilities. First, we examine empirical research revealing why open-source AI agents still severely underperform traditional static application security testing (SAST) tools due to low detection rates, hallucinations, and hig

Breaking the Union Ceiling: The Path to Cybersecurity SuperIntelligence
Current cybersecurity AI systems typically rely on single-agent scaffolds, yet research demonstrates that no individual orchestration layer is optimally suited for every type of threat. By uniting structurally diverse scaffolds through a shared "blackboard" substrate, different agents can exchange intermediate findings and compress each other's reconnaissance phases. This synergistic collaboration

Defending MLOps Against Autonomous AI Warfare
In this podcast, we dive into the critical evolution of MLSecOps and how organizations must adapt to defend their dynamic machine learning pipelines against the OWASP ML Top 10 threats, including data poisoning and AI supply chain attacks. We explore actionable insights from DARPA's AI Cyber Challenge, highlighting how autonomous systems like Buttercup use multi-agent architectures and LLMs to rev

The AI Accountability Gap: Prioritizing Catastrophic Risks
In this episode, we dive into a landmark Delphi study where 272 international experts prioritize the most severe threats posed by artificial intelligence over the next five years, including AI-enabled cyberattacks, dangerous capabilities, and extreme power centralization. We explore the stark "moral hazard" at the heart of the AI ecosystem, revealing how the general public and critical sectors bea

Zero Trust for AI Agents
As autonomous AI models accelerate the speed of cyber threats, traditional security perimeters are failing, requiring organizations to adopt a Zero Trust architecture specifically designed for agentic systems. This framework adapts core Zero Trust principles to address novel vulnerabilities—such as prompt injection, tool hijacking, and memory poisoning—by enforcing strict identity-based isolation

The Dark Side of the Pitch: Securing the 2026 World Cup
The 2026 FIFA World Cup presents a massive global stage, but its unmatched visibility is already attracting a complex web of physical, digital, and geopolitical security threats across the US, Mexico, and Canada. In this episode, we break down how host nations are preparing for vastly different physical risks, ranging from transnational organized crime in Mexico to violent extremists targeting fan

The Tale of Two Claudes: Unpacking Fable 5 and Mythos 5
In this episode, we dive into Anthropic's dual-release of Claude Fable 5 and Mythos 5, two highly capable AI models built from the exact same architecture but designed for vastly different worlds. We explore how Fable 5 protects the general public with novel cyber and biological fallbacks, alongside invisible safeguards that quietly thwart competing frontier AI development. Finally, we unpack the

Continuous Defense: The AI Security Department for the Mid-Market
In a world where software ships daily and attackers automate their methods, traditional point-in-time security assessments like annual pentests leave mid-market organizations blind for most of the year. This episode explores the transition to a continuous, AI-augmented security model built on six interconnected pillars—ranging from automated compliance and incident response to a self-healing DevSe

Zero Theater Sourcing: The Hidden Math of Cyber Procurement
This podcast explores how the CISO Marketplace streamlines vendor sourcing for security leaders by eliminating repetitive "discovery theater". It dives into how organizations can use ten free total cost of ownership (TCO) and sizing tools to uncover hidden technology costs, such as compounding carrier waste, unbudgeted cloud egress fees, and the true staffing requirements for a 24/7 SOC. Listeners

Navigating the 2026 AI Divide: Voluntary Frameworks and Binding Laws
The June 2026 U.S. executive order establishes a voluntary pre-release review framework and classified NSA benchmarks to govern the advanced cyber capabilities of frontier AI models. While the federal government pushes an innovation-first agenda with no mandatory licensing or pre-clearance, AI developers face a starkly different reality of binding penalties from the EU AI Act and emerging state la

Architecting the Digital Frontline: The U.S. Cyber Force Blueprint
The United States faces an unprecedented range of sophisticated cyber threats, highlighting the urgent need for a dedicated military branch to uniquely organize, train, and equip personnel for the digital domain. This episode explores the CSIS Commission's comprehensive plan for an independent U.S. Cyber Force, detailing its proposed structure of 30,000 personnel, reliance on expert warrant office

Governing the Invisible Workforce: The AI Agent Identity Crisis
Non-human identities now vastly outnumber human users, with recent estimates showing up to an 82-to-1 disparity in enterprise environments. The rapid adoption of autonomous AI agents amplifies this crisis, as these agents utilize compound identities and inherited "invisible browser" sessions to operate at machine speed, easily bypassing traditional security controls. To secure this dynamic attack

Securing the AI Frontier: Navigating MCP Vulnerabilities
The Model Context Protocol (MCP) is rapidly becoming the standard for AI-driven automation, yet its rapid adoption has significantly outpaced the development of its security model. This episode explores the inherent design vulnerabilities of MCP, such as unrestricted repository access, tool parameter injection, and remote code execution, which expose organizations to novel and systemic attack vect

The 2026 DBIR Breakdown: Shadow AI, Pretexting, and the Rise of Vulnerabilities
The 2026 Data Breach Investigations Report reveals a rapidly shifting threat landscape where the exploitation of vulnerabilities has officially overtaken credential abuse as the top initial access vector. Alongside this shift, defenders are battling the explosion of "Shadow AI" data leaks and sophisticated, synchronous "pretexting" attacks that bypass traditional email-centric security training. D

The 2026 Digital Rulebook: Navigating AI, Privacy, and Cyber Convergence
In 2026, global organizations face a shifting regulatory landscape defined by the EU's Digital Omnibus package and the proposed SECURE Data Act in the United States. This episode explores how compliance leaders can adapt to delayed EU AI Act deadlines, navigate new data subject rights, and operationalize AI governance using standards like ISO 42001 and NIST. We also dive into the technical realit

The Digital Identity Divide: Trust in 2026
The global landscape of identity is shifting rapidly in 2026, driven by the expanding rollout of mobile driver's licenses (mDLs) in the United States and the looming European Digital Identity (EUDI) Wallet mandate under eIDAS 2.0. This transition towards digital public infrastructure faces unprecedented cybersecurity challenges, primarily fueled by a 900% surge in AI-generated deepfakes and the ri

The Global Privacy Horizon: AI Governance and Data Security in 2026
Welcome to a deep dive into the monumental shifts in data security, artificial intelligence governance, and global privacy regulations defining the corporate landscape in 2026. In this episode, we explore the intersection of aggressive new enforcement frameworks, such as the EU AI Act and the federal TAKE IT DOWN Act, alongside the profound impacts of sweeping children's online safety mandates. We

The Privacy Paradox: Control, Fatigue, and the Future of Our Data
Over half of New Zealanders are now deeply concerned about their individual privacy, driven largely by anxieties over children's digital safety and the use of artificial intelligence in decision-making. While an overwhelming majority demand more control over how their personal information is used, nearly half of the population is experiencing "privacy fatigue," feeling that protecting their data s

Shadows Over Security: Inside the CSIS 2025 Public Report
Delve into the complex and evolving national security challenges facing Canada in 2025, as outlined by the Canadian Security Intelligence Service (CSIS). This episode explores the shadowy world of foreign interference, transnational repression, and the alarming rise of youth radicalization within violent extremist movements. Join us as we unpack the critical threats targeting Canada's democratic i

Securing the AI Supply Chain: The G7 SBOM Guidelines
In this podcast, we explore the groundbreaking guidelines set by the G7 Cybersecurity Working Group for creating a Software Bill of Materials (SBOM) for Artificial Intelligence. Our experts break down the seven critical information clusters—including metadata, models, datasets, and security properties—that serve as an essential "ingredient list" for AI systems. Tune in to discover how these founda

The Dual-Use Dilemma: OpenAI Daybreak vs. Project Glasswing
In this episode, we explore how frontier AI models like OpenAI's GPT-5.5-Cyber and Anthropic's Claude Mythos are fundamentally shifting the landscape of cybersecurity by operating at machine speed. We dive deep into the dual-use reality of these highly capable tools, analyzing how they dramatically compress the vulnerability discovery-to-remediation pipeline while simultaneously introducing new of

The 2026 Cyber Compliance Collision: AI, Quantum, and Global Mandates
In 2026, organizations face an unprecedented convergence of global cybersecurity regulations and rapid technological shifts that are creating a massive "compliance stack". This episode dives into sweeping new mandates, including the EU's Cyber Resilience Act and NIS 2 Directive, the U.S. transition to Post-Quantum Cryptography, and emerging global AI governance frameworks. We explore how CISOs can

The EdTech Supply Chain Collapse: Inside the PowerSchool and Canvas Breaches
Between 2024 and 2026, the educational technology sector suffered a catastrophic supply chain collapse as hackers compromised roughly 350 million records through major platforms like PowerSchool and Canvas. By exploiting weak trust boundaries in shared multi-tenant architectures, threat actors such as the ShinyHunters group moved beyond targeting individual schools to attacking the centralized ven

Building the Human Resilience Infrastructure
This podcast explores the profound psychological, economic, and social shifts triggered by the rapid advancement of artificial intelligence, including the impending "work quake" that will radically restructure the labor market. Drawing on insights from hundreds of global experts, the discussion dives into emerging survival frameworks like the "Me:chine" identity and the critical need to develop "

Zero Trust in OT: Securing the Physical World
Operational Technology (OT) interacts directly with the physical world, meaning that cyber attacks can have immediate, devastating real-world safety and environmental consequence. Standard IT security models fall short in OT environments due to decades-old legacy systems, insecure protocols, and strict requirements for continuous availability. This episode explores how organizations can practicall

Autonomous Defenses: Securing Agentic AI
As agentic AI systems increasingly automate complex tasks and operate with unprecedented autonomy, they introduce new and unpredictable cyber security risks. This podcast explores the unique vulnerabilities of these interconnected systems, ranging from privilege scope creep and deceptive behaviors to structural and accountability challenges. Tune in to discover actionable best practices for design

Autonomic Resilience: Navigating the Hidden Fault Lines
In the era of the autonomous enterprise, digital systems are evolving faster than traditional governance can keep up, exposing dangerous hidden vulnerabilities across the modern business. This podcast dives into the 2026 Cloudflare Security Signals Report to unpack the six critical fault lines threatening organizations, from shadow supply chains and legacy technical debt to ungoverned AI agents. J

CISO.POKER — Where Security Leadership Meets the Felt
Join us for the first public announcement of CISO.POKER's inaugural tournament at Hacker Summer Camp 2026, an exclusive, zero buy-in Texas Hold'em event designed for 80 senior security executives on the Las Vegas Strip. This episode unpacks how we are replacing the traditional "pay-to-play" vendor pitch with genuine networking, offering an Enterprise security prize pack, Knockout Bounties, and cap

Digital Trust 2026: Identity, Privacy, and the New Regulatory Frontier
In 2026, the global digital landscape is undergoing a massive transformation as rapid technological advancement collides with complex new regulatory frameworks. This episode explores how African nations are pioneering digital public ecosystems for economic integration, while the United States navigates a strict new patchwork of state privacy laws designed to protect minors and consumer data. Join

The 2026 Compliance Countdown: Navigating the New Era of Global Privacy and Cyber Regulations
From the expansion of U.S. state privacy laws and the HIPAA Security Rule overhaul to the enforcement of the EU AI Act, DORA, and India's DPDP Act, 2026 marks a definitive turning point for global regulatory compliance. We explore how these emerging frameworks demand that businesses move beyond static paperwork to demonstrate true operational resilience, continuous monitoring, and boardroom accoun

The Digital Siege: Supply Chain Poisoning and the New Era of Cyber Warfare
In April 2026, the cybersecurity landscape experienced a seismic shift as geopolitical tensions and industrialized fraud collided to create unprecedented enterprise risks. This episode dives into the most critical incidents of the month, including TeamPCP's cascading supply chain compromises, Iran-backed wiper attacks on corporate infrastructure, and the exploitation of third-party platforms by gr

The Mythos Paradox: Leaks, Lawsuits, and the AI IPO of the Century
Anthropic recently unveiled Claude Mythos, an unreleased frontier AI model with unprecedented cybersecurity capabilities that led the company to restrict its access exclusively to defensive partners via Project Glasswing. This revelation coincided with a chaotic week of accidental source code leaks and an unprecedented legal battle against the Pentagon, which blacklisted Anthropic as a "supply cha

The 40-Minute Collapse: How Fake Compliance Broke the AI Supply Chain
In March 2026, a 40-minute supply chain attack on the open-source library LiteLLM allowed hackers to steal four terabytes of highly sensitive data from Mercor, a $10 billion AI training startup. The breach exposed a fragile trust infrastructure across the tech industry, revealing that LiteLLM's security certifications were fabricated by Delve Technologies, a compliance vendor that systematically r

The Mythos Dilemma: AI, Zero-Days, and Project Glasswing
Anthropic's latest frontier model, Claude Mythos Preview, has demonstrated an unprecedented ability to autonomously discover and exploit zero-day vulnerabilities in critical software. Recognizing the extreme dual-use risks of these capabilities falling into the wrong hands, Anthropic has made the unprecedented decision to withhold the model from general public release. Instead, the model is being

Decoding CCPA: Navigating Cybersecurity Audits and Existing Frameworks
Dive into the nuances of California's new CCPA cybersecurity audit requirements and discover how they redefine the standard for "reasonable security". We explore how businesses can strategically leverage existing NIST, ISO, or CIS assessments as a foundation, while identifying the critical scope mismatches they must "top off" to ensure compliance. Tune in for a practical, four-step roadmap to navi

Encrypted Extortion: Inside Latin America's Cybercrime Boom
Dive into the rapidly evolving cyber threat landscape of Latin America and the Caribbean, where financially motivated threat actors are increasingly exploiting rapid digital adoption to target the region's largest economies. We explore how cybercriminals and hacktivist collectives like FiveFamilies are utilizing encrypted platforms like Telegram and WhatsApp to distribute banking trojans, deploy d

Growing Up Digital: Safeguarding Youth in the EU
Explore the evolving landscape of youth digital protection across the European Union, where groundbreaking laws like the GDPR and the Digital Services Act (DSA) are being deployed to shield minors from data exploitation and harmful content. As emerging innovations like immersive virtual environments, neuromarketing, and AI-generated deepfakes introduce unprecedented risks to children's mental priv
Recommended

English Vocabulary Help

این نقطه

Solved Murders - True Crime Stories

紐約鳥|New York Aperture

Doctor Zhivago Slow Read

Apple News In Conversation

The Young and Called Podcast .

Jubal Phone Pranks from The Jubal Show

پلی لیست | PlayList

English with Olivia | Slow Conversations & Vocabulary

Bible Tea

TED Talks Daily