
Security Intelligence Podcast
Security Intelligence is a weekly news podcast for cybersecurity professionals who need to stay ahead of fast-moving threats. Each episode covers the latest threats, trends, and stories shaping the digital landscape, with expert insights to help make sense of it all. It is designed for builders, defenders, business leaders, and anyone curious about staying secure in a connected world. The show offers timely updates and timeless principles in an accessible, engaging format. New episodes are released weekly.
Episodes
What should security leaders do with AI? They don’t know.
Cybersecurity leaders are flush with cash—earmarked for AI, mind you—and eager to spend it. What they don’t have is a plan for how. This week on Security Intelligence, Claire Nuñez, Curtis Pitts and Dave Bales join host Matt Kosinski to talk about why so many security teams are experience AI decision fatigue—and what to do about it. Then, we discuss Tenet Security’s DEFCON presentation on ghostja
The OWASP LLM Top 10 has a few surprises for you
What’s the biggest, baddest, most unruly problem in AI security? Turns out that depends on whether you’re asking practitioners or looking at incident data. In this episode of IBM Security Intelligence, we break down the OWASP LLM Top 10 for 2026, which took the unusual step of using both community votes and incident databases to inform its rankings. There are some interesting gaps—the data says m
Oh look. Anthropic’s AI models also broke containment.
Last week, OpenAI’s models broke out of their sandboxes to cause chaos. This week, it’s Anthropic’s turn. On this episode of Security Intelligence, Diego Matos Martins, Kimmie Farrington and Jeff Crume join host Matt Kosinski to discuss the results of Anthropic’s internal review of testing procedures following the Hugging Face incident last month. Anthropic uncovered three instances of Claude mod
Your data breach plan is missing something major: people.
When a cyberattack hits, your security team knows exactly what to do. What about everyone else? In this episode of Security Intelligence, Limor Kessem, X-Force Cyber Crisis Management Global Lead, explores the side of breach response that most organizations forget: the human side. From employees posting ransom notes on Facebook to well-meaning staffers accidentally paying ransoms to sanctioned ent
The Cost of a Data Breach 2026, and what we can learn from the Hugging Face hack
We’re in an AI arms race, and the bad guys might be winning. On this episode of Security Intelligence, Suja Viswesan, Dave McGinnis and Jeff Crume join host Matt Kosinski to dig into IBM’s 2026 Cost of a Data Breach report. This year’s findings suggest that attackers are weaponizing AI faster than defenders can deploy it, leading to some very troubling capability gaps. But it’s not all doom and gl
GPT-Red: Can AI red teams stop prompt injections?
Cybersecurity researchers have had a heck of a time trying to stop prompt injections. Maybe we should just let the AI handle the problem itself. This week on Security Intelligence, Michelle Alvarez, Nick Bradley and Kimmie Farrington join host Matt Kosinski to discuss OpenAI's GPT-Red, the internal red-teaming tool that helped make GPT-5.6 Sol the company’s most cyber resilient model yet. Then: S
GLM-5.2: The real security risk? Plus: Vibe hunting, the end of CVSS and updates on Lightwell
Z.ai’s GLM-5.2 is, according to some, as good at finding
vulnerabilities as Mythos. Or at least, close to it. And it’s open
weight. On this episode of Security Intelligence, we
dig into how powerful, open AI models are bringing frontier-style
capabilities to more people, all while the proprietary models are
emphasizing safeguards. What does it mean for cybersecurity pros?
Security emergency,
Fable 5, GPT-5.6 and the high stakes of AI safeguards. Plus: Agentic ransomware, and ClickFix reigns supreme
Read Itzhak Chimino’s research on UnregStealer → https://www.ibm.com/think/news/unregstealer-human-operated-browser-credential-theft-targeting-brazilian-banking When it comes to Fable 5, Mythos 5, and GPT-5.6 Sol, the real story is in the safeguards. Last week, Anthropic and OpenAI both rolled out some powerful new models. And for perhaps the first time, the protections surrounding these models
The new post-quantum cryptography executive order. Plus: What is Q-Day, really?
Learn more about Q-Day → https://www.ibm.com/think/news/q-day-has-already-begun-are-you-ready On June 22, US President Donald Trump signed a pair of executive orders for the quantum computing, and post-quantum future. On this episode, Mason Molesky breaks down the post-quantum EOs: “Securing the Nation Against Advanced Cryptographic Attack,” which establishes a government‑wide mandate to accelera
Patch management is dead. Here’s what’s taking it place
Patch management, as most organizations practice it, is fundamentally broken. It treats what should be a strategic, risk-informed decision as a checkbox item. And checkboxes don't get done. The fix isn't better patching. It's exposure management: a risk-based approach that connects your vulnerabilities to your business context, your attack surface and the real-world threat landscape. In this episo
Have we finally solved social engineering? Plus: World Cup fraud, AI IDs and an IBM/OpenAI collab
Read more about IBM joining OpenAI Daybreak → https://newsroom.ibm.com/2026-06-22-ibm-and-openai-bring-frontier-ai-to-cyber-defense-helping-enterprises-keep-pace-with-machine-speed-threats Social engineering has plagued human beings since time immemorial. We’ve simply never been able to stop it. Until now. Maybe. On this episode of Security Intelligence, panelists Dave Bales, Kimmie Farrington
AI agents can manage your passwords. Should we let them? Plus: The biggest Patch Tuesday ever.
Apple unveiled an AI agent that can detect if your password’s been compromised and change it for you. The question is: Should you let it? On this episode of Security Intelligence, Michelle Alvarez, Erblind Morina and Austin Zeizel join host Matt Kosinski to discuss the promise and pitfalls of using AI agents to address the pernicious issue of cybersecurity hygiene. As people, we’re not great at i
Can you social engineer an AI? Plus: AI worms and the nonhuman identity problem
If you just ask an AI nicely enough, you can get it to hand over the keys to a total stranger’s Instagram account. But people can be tricked, too. So what’s the difference? Is there any? This week on IBM’s Security Intelligence, Jeff Crume, Claire Nunez and Nick Bradley join host Matt Kosinski to dig into what happens when social engineering meets AI. We cover the Meta/Instagram prompt injection a
Project Lightwell brings open source security into the AI era
Open source software powers more than 90% of Fortune 500 companies. It also powers a growing number of cyberattacks. This week on Security Intelligence, we dig into IBM and Red Hat's $5 billion answer to that problem: Project Lightwell, a massive investment in AI-augmented engineers and a trusted security clearinghouse designed to shore up the open source ecosystem from the inside out. We also
Multi-model AI environments are the future. Can we secure them?
Today, the average enterprise network is like one big game of Telephone: Critical data flows between apps and assets, software systems and their subcomponents, on-prem laptops and cloud storage buckets. Every single gap between the pieces—every single transaction—is a possible vulnerability, a chance to hackers to get in or data to get scrambled. And the introduction of multiple AI models is only
First findings from Project Glasswing
While Anthropic has restricted Mythos access to its Project Glasswing partners, it has always maintained that lessons from Glasswing would be shared with the broader cybersecurity community. Now, those lessons are starting to roll out. This week, on Security Intelligence, panelists Dustin “EvilMog” Heywood, Kimmie Farrington and Curtis Pitts discuss Cloudflare’s recent write-up on its adventures w
OpenAI’s Daybreak and Mistral’s Mythos competitor
Between OpenAI Daybreak, Microsoft MDASH and Mistral’s Mythos competitor, it’s been a big week for AI-powered vulnerability management. But are these tools all they’re cracked up to be? This week on Security Intelligence, Nick Bradley, Diego Matos Martins and Nikki Robinson discuss three bold moves in the AI vulnerability scanner space: OpenAI unveiled Daybreak, its frontier AI for cyber defense p
LLMjacking: How hackers steal your AI API keys and stick you with the bill
AI tools can turn a team of three developers into a fully functioning company. They can also push that company to the brink of bankruptcy. On this week’s Security Intelligence, we talk LLMjacking: Hackers steal your AI API keys and then rack up massive bills, even blowing past usage caps in some cases. One small startup saw its typical bill balloon from $180 a month to $82,000 in two days. We chat
Claude Security’s public beta, OpenAI’s five-point plan and cybersecurity’s Y2K moment
Between Mythos, GPT-5.4-Cyber, Claude Security’s public beta and OpenAI’s new five-point plan for cyber defense, it seems like cybersecurity is top of mind for the major AI players today. Why—and why now? On this week’s episode of IBM Security Intelligence, Dustin “EvilMog” Heywood, Omari Jones and Kimmie Farrington discuss what CrowdStrike has called “cybersecurity’s Y2K moment.” As the major AI
Is open source safe? Featuring Mixture of Experts
Is open source good? Bad? Some secret third thing? Is this a silly question to even ask? In this special crossover episode of Security Intelligence and Mixture of Experts, we bring together AI and security experts to address one of the thorniest questions in tech right now: How do you enjoy the unique benefits of open source AI while managing its very real risks? MoE stalwarts Gabe Goodhart and Ma
Web of lies: What’s real and what’s fake on the dark web
We’ve all heard tales of what lurks on the dark web. Black markets dealing in contraband. Roving criminal gangs. Troves and troves of private data for sale. Much, much worse. Thankfully, most of it’s fake. The real trouble is figuring out what isn’t. In this episode of Security Intelligence, Senior Threat Intelligence Analyst Robert Gates helps us untangle the web of lies that cybercriminals spin
Should you let OpenClaw pen test your system? Plus: Cybersecurity for ephemeral software
Learn more about how enterprises confront agentic attacks → https://newsroom.ibm.com/2026-04-15-ibm-announces-new-cybersecurity-measures-to-help-enterprises-confront-agentic-attacks Sophos let OpenClaw run wild on its network (sort of). It wasn’t as bad an idea as it sounds! With a few guardrails and restrictions in place, the security software firm turned OpenClaw into a serious little pen teste
GPT-5.4-Cyber: What you need to know
Earlier this week, OpenAI dropped GPT-5.4-Cyber, a “cyber-permissive” variant of GPT-5.4 . Basically: It's lets you do some things in the name of security research and defense that you can’t normally do with a regular GPT model. But you have to prove you’re a cybersecurity pro with good intentions to get access. On this bonus episode of Security Intelligence, Jeff Crume and Martin Keen join hos
Claude Mythos: Marketing hype or the end of cybersecurity?
Anthropic says its newest AI model, Claude Mythos, has found thousands of zero-day vulnerabilities across every major OS and web browser. It's so powerful, they won't release it publicly. Instead, they’re restricting access to a handful of trusted partners, who get to experiment with Mythos through a new initiative called Project Glasswing. Where does that leave the rest of us, who don’t get to t
The Claude Code source code leak: Takeaways for cybersecurity pros
What happens when one of the world’s most popular AI coding tools falls into the wrong hands? On this episode of Security Intelligence, Nick Bradley, Dave Bales and JR Rao discuss the Claude Code source code leak. Attackers are already using the opportunity to spread malware through fake repos, but the real question is how threat actors might use their newfound knowledge of Claude Code’s internals
RSA recap, the LiteLLM breach, and the quest to fix AI
LiteLLM is a nifty little Python library that gives you access to about 100 different AI services through one API. It gets an estimated 3.4 million downloads a day. And last week, it was turned into a Trojan horse, distributing infostealers to hundreds of thousands of devices. (At least, that’s what TeamPCP says—the hackers behind the LiteLLM breach and a slew of other high-profile software supply
Cryptocurrency: The most misunderstood technology in cybersecurity
Most cybersecurity pros only run into cryptocurrency when they’re dealing with ransomware gangs demanding payouts in Bitcoin. But what if crypto infrastructure were more than just a means of money laundering? In this episode of IBM’s Security Intelligence podcast, X-Force threat intelligence consultant Austin Zeizel makes the case that blockchain — the decentralized ledger underlying many cryptoc
Promptware, cloud security trends for 2026, and what the Xbox One hack means for cybersecurity
Follow the Security Intelligence podcast on your preferred platform → https://www.ibm.com/think/podcasts/security-intelligence Someone finally cracked the Xbox One after 13 years. Here’s why security pros should care. On this episode of Security Intelligence, panelists Ian Molloy, Seth Glasgow and Kimmie Farrington discuss the Xbox One hack presented at RE//verse 2026. More than just a neat stor
Perplexity Comet, agentic blabbering, and the shift-left failure
When agentic browsers like Perplexity Comet share their reasoning, they give cybercriminals valuable information. Plus: 40-year-old code liabilities, the failure of shift lift, and new X-Force research. Read more about “Slopoly” → https://www.ibm.com/think/x-force/slopoly-start-ai-enhanced-ransomware-attacks
The conference that changed our minds about AI
Follow the Security Intelligence podcast on your preferred platform → https://www.ibm.com/think/podcasts/security-intelligence Did you miss out on the [un]prompted AI security conference? So did most of us. Except our very own Dustin “Evil Mog” Heywood, who joins us today to share highlights from the event. And speaking of [un]prompted, we also discuss one of the biggest announcements to come out
Is your robot vacuum safe? Here’s why it matters
Can IAM handle AI? Find out → https://www.ibm.com/think/podcasts/security-intelligence A consumer just wanted to control his own personal robot vacuum with a PlayStation controller. He ended up controlling thousands of strangers’ vacuums, too. This week on Security Intelligence, we cover one of the wildest IoT security stories in recent memory: How one user accidentally built an army of 6,700 robo
The AI agent access problem: Can IAM handle AI?
AI agents are coming to the enterprise—but can we actually control them? On this bonus episode of Security Intelligence, IBM Fellow and CTO IBM Security Sridhar Muppidi helps us dig into the rise of agentic AI security risks, from generative AI systems with backend access to autonomous agents that can schedule meetings, call APIs and automate workflows — often with highly privileged access. Tradit
Exploits of public-facing apps are surging. Why?
Explore the Threat Intelligence Index 2026: https://www.ibm.com/reports/threat-intelligence#sipod For years, stolen credentials were king—the hacker’s attack vector of choice. Until now. The 2026 IBM X-Force Threat Intelligence Index reveals a surge in the exploitation of public-facing applications, overtaking identity-based attacks as the top initial access vector. Why are threat actors chang
Romance scams: How they work, how they win and what we do about
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence Valentine’s day might be over, but love is in the air. The love a scammer has for their victim’s wallet, that is. In this special episode of Security Intelligence, host Matt Kosinski sits down with Claire Nunez, Suja Viswesan, and Dave Bales to break down how modern romance scams actually work: from the “wrong number” t
OpenClaw and Claude Opus 4.6: Where is AI agent security headed?
Are enterprises moving too fast with AI—and breaking security in the process? In this episode of Security Intelligence, host Matt Kosinski is joined by Sridhar Muppidi, Nick Bradley and Jeff Crume to unpack a pivotal moment in cybersecurity. The panel dives into the rapid rise of AI agents and the growing risks of shadow AI in the enterprise, comparing open-source agent platforms like OpenClaw wit
What cybersecurity pros need to know about OpenClaw and Moltbook
OpenClaw and Moltbook are extremely cool. They're also extremely dangerous. And they tell us just how far AI agent security has to go. In this episode of Security Intelligence, Dave McGinnis, Seth Glasgow and Evelyn Anderson unpack how locally run AI agents are becoming a brand-new attack surface, and why defenders may be underestimating the risks. From misconfigured agent databases leaking API ke
John Henry vs. the chatbot: Can humans outsmart AI scam artists?
Do you think you could get scammed by a chatbot? Neither did IBM Chief People Hacker Stephanie Carruthers—until she went toe to toe with one. In this episode of Security Intelligence, we take you inside the John Henry Competition at DEF CON 2024, where Carruthers competed with an AI-powered vishing bot to see who was the better con artist. The results just might surprise you. Along the way, we exp
The newest AI malware vs. 40 years of hacker culture
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence AI-generated malware has officially arrived. But does it matter all that much? This week on Security Intelligence, Suja Viswesan, Dave Bales and Dustin Heywood join us to discuss VoidLink, which might just be the first thoroughly documented case of a malware framework generated with significant AI help. The question is:
Most cybersecurity training doesn’t work. Can we change that?
AI has changed the speed of cyberattacks. But it hasn’t changed the most important variable: people. In this episode of Security Intelligence, panelists Jake Paulson, Stephanie Carruthers and Matt Cerny dig into how AI-driven threats—phishing, deepfakes and disinformation—are reshaping the cyberthreat landscape. Organizations, too, are adopting AI tools to help detect these attacks. But even in th
Ransomware whack-a-mole, AI agents as insider threats and how to hack a humanoid robot
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence Between LockBit, RansomHub and BlackSuit, law enforcement racked up some big wins against ransomware gangs last year. So why aren’t the attacks letting up? In this episode of Security Intelligence, panelists JR Rao, Jeff Crume and Michelle Alavarez unpack what the state of ransomware in 2025 really looked like, and why
A new take on bug bounties, AI red teams and our New Year’s resolutions
Say your cloud storage service gets hacked. Say the attackers broke in by exploiting a vulnerability in an open-source library your organization used to build the service. Who owns that vulnerability? Microsoft is trying to clear some of the smog obscuring the software supply chain by expanding its bug bounty program to include some third-party code that affects it services. In this episode of Se
Why it costs so much to get hacked in America
Why does it cost so much more to get hacked in the United States than anywhere else in the world? In this special bonus episode of Security Intelligence, we sit down with Michelle Alvarez, Manager of Strategic Threat Analysis at IBM X-Force, for a deep dive into IBM’s 2025 Cost of a Data Breach report—and one of its most surprising findings: global breach costs are falling, but US breach costs jus
Cybersecurity’s Year in Review: ClickFix Attacks, Vibecoding Vulnerabilities & Shadow Agents
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence In this special year-end episode of Security Intelligence, we reflect on 2025, a year of new attack methods (ClickFix), new vulnerabilities (vibecoding) and new worries on the horizon (shadow agents). From hijacked AI agents to massive supply chain breaches, 2025 forced security leaders to confront a sobering reality: t
AI browser bans and the top software flaws of 2025
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence AI browsers are neat—but are they more trouble than they’re worth? In this episode of Security Intelligence, Austin Zeizel, Evelyn Anderson and Ryan Anschutz discuss Gartner’s recent advisory warning organizations to ban AI browsers from the workplace for the time being. Is there anything we can do to make them safe en
React2Shell makes waves, WormGPT falls flat and the latest threat to your Gmail account
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence Just how big a deal is React2Shell? Depending on who you ask, it’s either a Log4Shell-level event or just another average, everyday application security vulnerability. Patch and move on. This week, on Security Intelligence, panelists Sridhar Muppidi, Claire Nuñez and Ian Molloy weigh in on the contentious debate React2S
Your house might be a botnet, your devs are leaking secrets and poems are breaking your AI guardrails
One of the most common tips for avoiding online scams is to only shop at reputable retailers. But what happens when those very retailers are turned into social engineering vectors? In this week's episode of Security Intelligence, host Matt Kosinski and panelists Bryan Clark, Michelle Alvarez and Dave Bales talk about the streaming devices that promise to let you watch all your favorite shows for f
Trawling the honeypot: What it’s like to discover a new malware strain
Being a malware reverse engineer isn’t always glamorous work. You spend a lot of time digging through junk emails. But when you find something in there—well, that’s a whole different story. On this episode of Security Intelligence, X-Force Malware Reverse Engineer Raymond Joseph Alfonso tells us about the time he discovered a curious new malware loader in the honeypot. And that leads to a bigger
The dark web job market thrives, AI fraud rings rise and it’s holiday scam season
Do you think you’re too smart to fall for a Black Friday scam? Generative AI might knock you down a few pegs. On this episode of Security Intelligence, host Matt Kosinski and panelists Suja Viswesan, Dave McGinnis and Nick Bradley discuss how threat actors are using AI to turbocharge holiday scam season. Plus: IBM X-Force makes malware research tools public The dark web job market is thriving AI f
Anthropic stops AI spies, the new OWASP Top 10 and the rise of small-time ransomware
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence Anthropic says it disrupted a nearly fully autonomous espionage campaign carried out by AI agents. But some cybersecurity pros are skeptical of the framing. On the latest episode of Security Intelligence, host Matt Kosinski is joined by Ryan Anschutz, Evelyn Anderson, Seth Glasgow and Mixture of Experts podcast fixture
AI slop in cybersecurity, OT security fails and lessons from the Louvre heist
Explore the podcast → https://www.ibm.com/think/podcasts/security-intelligence Have we lost the plot when it comes to AI malware? This week, host Matt Kosinski and panelists Claire Nunez, Austin Zeizel and Dave Bales discuss the growing trend of cybersecurity pros pushing back on AI malware “research.” Is it all puffery? Genuine threat? Some secret third thing? Plus: How hackers are stealing rea
Android malware that acts like a person and AI agents that act like malware
What do AI agents, the stock market and behavior-based threat detection tools have in common? You’ll need to listen to this week’s episode of Security Intelligence to find out. Join host Matt Kosinski and panelists Sridhar Muppidi and Cris Thomas for a jam-packed conversation, including new ways to build malicious AI agents, a malware strain that types like a person, a social engineering scheme th
Is ChatGPT Atlas safe? Plus: invisible worms, ghost networks and the AWS outage
Is a safe AI browser even possible? On this week’s super spooky Halloween episode of Security Intelligence, host Matt Kosinski and panelists Suja Viswesan, J.R. Rao and Dave McGinnis discuss the terrifying security risks of ChatGPT Atlas. Plus: The ghost network spreading malware on YouTube, an invisible worm that drops a “Zombi” payload and AWS’s brush with the grave. (Notice a theme?) And stick
How to break into an office: A social engineering expert talks physical security
Could you break into an office armed with nothing more than a coffee-stained resume and some charisma? Meet someone who can. Today’s bonus episode of Security Intelligence features an in-depth interview with Stephanie Carruthers, Global Head of Cyber Range and Chief People Hacker at IBM X-Force. Stephanie shares the harrowing tale of one of her most daring physical security assessments. Along the
RIP Windows 10, automated code repair and battling the payroll pirates
Is Windows 10 dead?This week, panelists Michelle Alvarez, Sridhar Muppidi and Jeff Crume join host Bryan Clark to discuss support for Windows 10 coming to an end. We also talk AI use in SOCs, automated code repair and the battle against payroll pirates coming after your next paycheck. 00:00 – Introduction 01:10 – RIP Windows 10 08:38 – The future of SOCs 19:41 – AI code repair 31:27 – Plundering p
How to scam an AI agent, DDoS attack trends and busting cybersecurity myths
What does it take to trick an AI agent? Not a whole lot, it turns out. This week, panelists Nick Bradley, Claire Nuñez and Jeff Crume join host Matt Kosinski to discuss a couple of new methods for hijacking AI agents and breaking their guardrails. We also talk recent evolutions in DDoS attack trends, the legacy of zero trust and some glaring security flaws in an extremely popular AI training app.
The AI vulnerability apocalypse, a new strain of Petya and dumb cybersecurity rules
Subscribe to the IBM Think newsletter: https://www.ibm.com/account/reg/us-en/signup?formid=news-urx-52120 An AI security CEO thinks we’re six months away from an “AI vulnerability cataclysm.” Is this a legitimate threat, or just fear-mongering? On this week’s episode, host Matt Kosinski and panelists Cris Thomas, Suja Viswesan and Troy Bettencourt debate whether we're headed straight for an AI
AI ransomware, hiring fraud and the end of Scattered Lapsus$ Hunters
Has the most notorious cybercrime gang of the moment really hung up its keyboards? In this episode of Security Intelligence, host Matt Kosinski along with panelists Dave Bales, Michelle Alvarez and Sridhar Muppidi discuss Scattered Lapsus$ Hunters’ retirement announcement. They also discuss the ethics of ransomware research, software supply chain security lessons from the npm hack, the state of OT
Vibe hacking, HexStrike AI and the latest scheme from Scattered Lapsus$ Hunters
Have we made cybercrime too easy? In the very first episode of Security Intelligence, panelists Jeff Crume, Suja Viswesan and Nick Bradley join host Matt Kosinski to discuss the invention of vibe hacking and HexStrike AI, an offensive security framework that threat actors are co-opting to command their own AI agent armies. We also discuss Scattered Lapsus$ Hunters’ unconventional new ransom demand
Introducing Security Intelligence Podcast
Cybersecurity moves fast: Old vulnerabilities are patched as new exploits appear. Cybercrime gangs form and strike and fade, disappearing with millions of ransom dollars. What protected the organization yesterday might leave it hopelessly exposed today. At the same time, cybersecurity pros rely on core principles—like the CIA triad of infosec, the principle of least privilege, zero trust architect











