
Hosted by TruStory FM
Cyber Sentries explores the critical convergence of AI, cloud, and cybersecurity, diving deep into how these three pillars are actively redefining the modern Security Operations Center (SOC).
31 episodes · publishes monthly · latest 2026-06-03 · ~32 min/episode
Rank
#38
Substance
86.4
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#38 of 6183
Substance
Top 1%
outscores 99% of the index
Cyber Sentries: AI Insight to Cloud Security ranks #38 on The B2B Podcast Index with a substance score of 86.4 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Ferry is a credible security researcher with 7-8 years red team experience and institutional backing from GitGuardian, giving him legitimate operational exposure. He demonstrates hands-on exploit knowledge and vulnerability responsibly disclosed to vendors. However, he is a researcher rather than an operator who has built or scaled agentic systems in production, limiting his ability to speak to operational trade-offs operators actually face when implementing these mitigations.
Averaged across 5 recently scored episodes, with cited evidence.
The episode packs substantial technical depth with concrete vulnerability analysis, real-world supply chain attacks, and layered security implications. Ferry moves beyond platitudes by detailing the smithery.ai path traversal exploit, token scope issues, and the proliferation of identities problem in agentic systems. However, some discussion circles back to familiar fundamentals (least privilege, observability) that reduce novelty density in the latter half.
“They had a small configuration file you need to add in your code repository. In the parsing of that configuration file, there was a vulnerability that is well known and called a path traversal. Basically, you could change the path of the repository on their infrastructure and get access to pretty much everything you wanted.”
“This token was poorly scoped and gave access to the whole API of Fly.io, which includes code execution on any machine they host.”
Ferry brings fresh perspective on how rapid AI adoption (MCP → Skills pivot) compresses security maturity cycles and shows the inadequacy of OAuth as a silver bullet for agent identity problems. The framing of behavioral/context-aware authorization as a gap is thoughtful. However, the core arguments about secrets management, supply chain risk, and privilege creep are well-established security tropes applied to a new domain rather than fundamentally novel frameworks.
“When you have a new technology coming out, everyone wants to take their share of the treasure and wants to go as fast as possible to provide new services leveraging those technologies.”
“I don't think we solve anything with OAuth in MCP. I mean, we solve the issue MCP had. But we've been using OAuth for years... The real issue we have is that systems, agents, and things like this come with a lot of identities.”
Ferry is a credible security researcher with 7-8 years red team experience and institutional backing from GitGuardian, giving him legitimate operational exposure. He demonstrates hands-on exploit knowledge and vulnerability responsibly disclosed to vendors. However, he is a researcher rather than an operator who has built or scaled agentic systems in production, limiting his ability to speak to operational trade-offs operators actually face when implementing these mitigations.
“I've worked as a red teamer for around seven or eight years in a great French consulting company. That's really where I learned about offensive security and things like this.”
“I documented what could have been a pretty severe supply chain attack in MCP servers in June or July last year, if I remember correctly, with a vulnerability chain in the smithery.ai MCP hosting platform.”
Episode is rich with concrete examples: smithery.ai path traversal exploit with named hosting provider (Fly.io), 4,000 MCP servers hosting scale, CodeRabbit breach via same vector weeks later, Salesloft/Drift supply chain attack with OAuth token exfiltration, GitHub MCP prompt injection attack making repos public, mcp.json files leaking 1,200 valid secrets in three months. Ferry names specific infrastructure components, timelines (June 2025 smithery discovery), and measurable metrics throughout.
“When I exploited this vulnerability, there were a little bit more than 4,000 different MCP servers hosted on smithery.”
“over the last three months, 1,200 valid secrets - secrets that we could prove valid - were leaked in a file named mcp.json.”
Host asks solid foundational questions (how you got into security, what you found, recommendations) and occasionally probes deeper (clarifying responsible disclosure, questioning whether OAuth solves the problem). However, follow-ups often accept Ferry's answers without pushing back or asking for implementation specifics. Richards misses opportunities to challenge Ferry on whether the fundamentals advice is actionable at scale, or to request concrete examples of observability solutions mentioned. The conversation lacks productive tension.
“Can you share what you're seeing out in the field? What are the new ways we're seeing attacks, especially around MCP servers and things like that?”
“Is the answer just: use better authentication protocols, OAuth or something like that? Or is the challenge deeper than that?”
First period on the Index - history builds from here.
10 scored on substance · 31 tracked in total.
Beyond the Token: How to Secure Agent Identity Across the Full Permission Chain with Jasson Casey
2026-06-03 · 35 min
People-Pleasers: Why AI Agents Go Rogue and How to Govern Them at Scale with Shreyans Mehta
2026-05-06 · 31 min
Five Seconds to Fraud: Detecting AI Deepfakes Before They Strike with Ben Colman
2026-04-01 · 29 min
Built Fast, Broken Faster: MCP & AI App Security - with GitGuardian’s Gaetan Ferry
2026-03-04 · 39 min
Identity in the AI Era: Managing Enterprise Risk in the Age of AI with Jasson Casey
2026-02-04 · 39 min
Security Data Pipelines: How to Cut SIEM Costs and Noise with Dina Kamal
2026-01-14 · 33 min
Securing AI Agents: How to Stop Credential Leaks and Protect Non‑Human Identities with Idan Gour
2025-12-10 · 33 min
AI Compliance Security: How Modular Systems Transform Enterprise Risk Management with Richa Kaul
2025-11-12 · 31 min
AI Governance Essentials: Navigating Security and Compliance in Enterprise AI with Walter Haydock
2025-10-08 · 31 min
Distributed AI Security: How Enterprise Systems Are Evolving for AI Integration with Mark Fussell
2025-09-10 · 30 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/cyber-sentries-ai-insight-to-cloud-security" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/cyber-sentries-ai-insight-to-cloud-security/badge.svg" alt="Ranked #9 on The B2B Podcast Index" width="360" height="136" />
</a>Track Cyber Sentries: AI Insight to Cloud Security's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.