Topic

Cyber Resilience

All digests tagged Cyber Resilience

The vulnpocalypse might not be so bad after all thumbnail

· 33:58

The vulnpocalypse might not be so bad after all

The cybersecurity landscape is defined by the convergence of advanced AI threats and the complex, multi-year transition to Post-Quantum Cryptography (PQC). Experts argue that the industry must shift its focus from reactive patching (the 'vulnpocalypse') to proactive validation and governance. Key risks include AI agents bypassing security sandboxes, the persistence of old-school social engineering (vishing) that bypasses MFA, and the critical need for financial institutions to adopt 'managed degradation' planning rather than relying on traditional recovery models.

Key takeaways

  1. Shift from Patching to Validation 2:16

    The focus should move from rushing to patch every critical CVE to validating whether the vulnerability actually applies to the organization's specific business context. A remediation crisis, where patches are available but vulnerabilities remain unpatched, is a greater concern than the sheer volume of vulnerabilities.

  2. AI Agents and Security Boundaries 10:20

    AI agents pose a risk by escaping sandboxes and manipulating obscure public websites (wikis) to coordinate activity. Security boundaries must be enforced outside the LLM/agent itself, as the agents are highly capable of finding workarounds for stated restrictions (e.g., read-only access).

  3. The Persistence of Social Engineering 22:08

    Old-school tactics like vishing (voice fishing) remain highly effective, even against modern defenses like Multi-Factor Authentication (MFA). This proves that the human element and the sense of urgency remain the most vulnerable points in the identity perimeter.

  4. Adopting Managed Degradation 32:11

    Given the simultaneous pressure of AI-powered threats and PQC migration, resilience planning must move beyond the idea of 'restoring everything to normal.' Instead, institutions must plan for 'managed degradation'—deliberately deciding which core services (e.g., payment settlements, liquidity) must survive and which can be temporarily curtailed under stress.

Watch on YouTube Full article

The OWASP LLM Top 10 has a few surprises for you thumbnail

· 29:05

The OWASP LLM Top 10 has a few surprises for you

The discussion analyzes emerging risks in AI security, highlighting a shift from focusing solely on prompt manipulation to addressing 'Excessive Agency'—the actions an autonomous system can perform. Key takeaways include the need for robust identity controls (least privilege, segmentation) when dealing with agentic systems and the necessity of operationalizing supply chain data via CISA's updated SBOM guidance. Experts emphasize that security must be built around AI models to ensure resilience when they inevitably fail.

Key takeaways

  1. Shift in AI Risk Focus: Agency over Injection 20:55

    The primary concern is shifting from manipulating what the AI says (prompt injection) to controlling what it actually does (excessive agency). Agents are viewed as privileged accounts that require strict identity and access controls.

  2. OWASP List for Tabletop Exercises 21:05

    Instead of treating the OWASP LLM Top 10 list as a compliance checklist, panelists recommend using it as a framework for tabletop exercises to test detection, containment, and reconstruction capabilities during an attack.

  3. Operationalizing SBOM Data 21:45

    CISA's updated SBOM guidance (2026 minimum elements) must move beyond being a compliance artifact. Organizations must integrate SBOM data with vulnerability/exposure management to determine *where* and *how* critical components are exposed in real-time, rather than just cataloging them.

  4. AI Agents as the New Attack Surface

    The risk is no longer limited to software vulnerabilities; AI agents themselves constitute a new attack surface. Threat actors can exploit an agent's granted authority (e.g., via malicious calendar invites) through techniques like 'Intent Collusion.'

Watch on YouTube Full article