Security Weekly Podcast Network · 2026-09-11 · 35 min
Twenty-five years since 9/11, and we open by marking it properly - the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on. Then we get to work. Shift-left didn't fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request - so the earliest trust boundary isn't your first commit any more, it's the moment an agent gets context and authority. Most of us haven't moved our controls with it. Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every layer built to look too boring to escalate. When your analyst closes that alert as adware, they may have just closed three separate compromises. Google's threat tracker: a credential-harvesting campaign built and run in under six hours, with Markdown files as attacker playbooks. And malware carrying prompt-injection text designed to make your LLM scanner refuse to look at it - because a refusal that reads as "clean" is a free pass. A CVSS 10 in Gemini CLI that never touched the model.