
Hosted by a16z
Listed under Technology, Business › Entrepreneurship
Artificial intelligence is changing everything from art to enterprise IT, and a16z is watching all of it with a close eye. This podcast features discussions with leading AI engineers, founders, and experts, as well as our general partners, about where the technology and industry are heading.
103 episodes · publishes weekly · latest 2026-08-07 · ~46 min/episode
Rank
#113
Substance
80.0
/ 100
Breakdown
Scored 2026-08
Updated monthly
Across the index
#113 of 1878
Substance
Top 6%
outscores 94% of the index
AI + a16z ranks #113 on The B2B Podcast Index with a substance score of 80.0 out of 100, scored across 2 recent episodes. It scores highest on guest caliber and insight density. Dylan Airey (Truffle Security) and Faras Abuka DJ (Socket) are highly credible practitioners directly confronting these attacks at scale. Truffle Security has discovered critical vulnerabilities and credentials at major institutions; Socket's team comprises former npm CTO and active maintainers. Both operate at the operational coalface rather than as theorists, and are actively responding to ongoing incidents during the recording.
Averaged across 2 recently scored episodes, with cited evidence.
The episode packs substantial technical insights about AI-augmented cyber attacks, including concrete mechanisms (SQL injection, supply chain backdoors, credential theft paths), the reward structure training that enables hacking behavior, and specific vulnerability discovery timelines. However, there's some repetition of core points and occasional filler (introductions, Black Hat conference banter) that dilutes density.
“Models have been specifically trained to have the subject matter expertise and they're just making it materially easier to hack into just about anything that you can think of using the fundamentals that we've been talking about for years, but previously required a subject matter expertise to risk going to jail for hacking things.”
“The interesting thing about cybersecurity in particular is the reward function is incredibly well defined. Get access to the data. Did it get access to the data? Reward the thing.”
The episode surfaces original observations about AI-enabled cyber attacks and supply chain worms, particularly the connection between training reward functions and emergent hacking behavior, and the NPM worm as a novel threat class. However, the core insight that AI lowers barriers to exploitation is becoming conventional wisdom, and some framing (software supply chain weakness, credential theft as path of least resistance) is well-established in security circles.
“If a lab tells you that this is an emergent superintelligence behavior, they're just lying to you. And you can read their own safety reports to see exactly how the models are trained and exactly how they're testing these behaviors.”
“They've started to reward the path of least tokens. And so the reason that's interesting is because for the first time, it's actually able to quantifiably show us the path of least resistance for just general cybersecurity.”
Dylan Airey (Truffle Security) and Faras Abuka DJ (Socket) are highly credible practitioners directly confronting these attacks at scale. Truffle Security has discovered critical vulnerabilities and credentials at major institutions; Socket's team comprises former npm CTO and active maintainers. Both operate at the operational coalface rather than as theorists, and are actively responding to ongoing incidents during the recording.
“About half of our team at Socket are maintainers, half the engineering team. Uh, and so you know, we have a lot of connections in the community and our CTO is the former CTO npm.”
“We found a database credential recently that had access to 3.6% of the global PII. Like 3.6% of the world's population had their PII in this database.”
The episode includes valuable specific examples: quarter-million live keys found in Hugging Face training sets, a foundational Linux library key with push access, 3.6% global PII exposure, a few hundred NPM packages affected by a worm, RubyGems caching vulnerability, and Apache Foundation admin API key breach. However, many details lack precise metrics (e.g., zero-day timelines mentioned but not quantified, models tested but version numbers inconsistent - 'Opus 4.6' unclear).
“Recently we found an API key that had been leaked on the Internet that had administrative access to the Apache Foundation.”
“Turned out there were about a quarter million live keys in their training sets, many of which had direct supply chain implications. There was a foundational Linux library that one of the keys had direct push access to. It could have pushed malware to most machines on the planet.”
The host (Speaker A / Joel) asks directional questions that surface technical depth and pushes guests on practical implications (e.g., 'what's your understanding of how they're figuring this stuff out?', follow-ups on credential remediation). However, some questions are soft or self-answering ('you've had your hair on fire, right?'), and there's limited productive disagreement or challenge to guest claims. Some tangents (Black Hat mood) are less substantive.
“So it's always been sort of like to go in level of difficulty from easiest to most difficult. And it seemed like initially these tools had a very finite scope of techniques that they would use. And it seems like they've expanded and I think with this test for us, what was interesting because they now have seemed to have escaped from just doing things like SQL injection to actually like trying to take over packages and do social engineering.”
“Can I ask a follow up to that? So one of the things that I've seen with the NPM worms in particular is after they get their post install hook and they infect the system, they'll immediately start looking for credentials.”
2 periods tracked.
2 scored on substance · 62 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/ai-a16z" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/ai-a16z/badge.svg" alt="Ranked #17 on The B2B Podcast Index" width="360" height="136" />
</a>Track AI + a16z's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.