The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Security Weekly Podcast Network
Security Weekly Podcast Network artwork

Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet,.. - SWN #597

Security Weekly Podcast Network · 2026-07-10 · 33 min

0:00--:--

Key moments - from our scoring

Substance score

45 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber10 / 20
Specificity & Evidence11 / 20
Conversational Craft7 / 20

Episode 597 covers a diverse range of emerging and critical security threats facing enterprises. Doug White discusses the GetLost attack - where researchers used indirect prompt injection to socially engineer agentic AI into exfiltrating sensitive information from GitHub repositories - highlighting how LLM-based agents create new attack surfaces through their access to enterprise systems and data. The episode emphasizes the urgency of ColdFusion patching after CISA mandated remediation for a maximum severity, remotely exploitable vulnerability with active exploitation occurring within hours of disclosure, advocating for a shift from time-to-patch (TTP) to time-to-mitigate (TTM) strategies. GodDamn ransomware, a Beast variant using the Poison X malicious kernel driver with legitimate Microsoft signatures, demonstrates a five-day dwell time before encryption, deploying 14 credential harvesting tools including Mimikatz across laterally-moving infrastructure. GhostApproval reveals how AI code assistants like Amazon Q, Claude, Cursor, and others can be tricked via symbolic links to edit files outside intended workspaces. Additional topics include the August 2026 removal of OWA Lite from on-premises Exchange, the 15-year-old GhostLock vulnerability in Linux kernel, and Apple's movement toward AI-enabled glasses integrated with AirPods. Guest Josh Marpet discusses the fragmented CVE landscape around GhostApproval, with vendors like Claude and Amazon responding differently to the same vulnerability - some already patched, others dismissing it as out-of-scope.

Key takeaways

  • →Agentic AI systems create new permission and access control challenges as they can be socially engineered to exfiltrate sensitive data from repositories and connected systems, requiring expanded analysis of AI access chains and capabilities.
  • →ColdFusion's maximum severity vulnerability demonstrates that time-to-exploit often outpaces time-to-patch, necessitating rapid mitigation strategies including network segmentation and isolation rather than relying solely on patching timelines.
  • →GodDamn ransomware's five-day dwell time and 14 credential harvesting tools enable rapid lateral movement across networks, emphasizing the need for pre-planned incident response procedures and backup isolation strategies given encryption can occur within minutes.
  • →GhostApproval's symbolic link exploitation affects multiple AI code assistants differently, with vendors showing inconsistent security responses from proactive patching to claiming vulnerabilities are out-of-scope, creating uneven protection for users.
  • →Legacy infrastructure like OWA Lite (being deprecated August 2026) and decades-old Linux kernel vulnerabilities like GhostLock underscore the importance of maintaining asset inventories and planning for end-of-life system transitions before security support ends.

Guests

Josh Marpet

Topics in this episode

Agentic AIindirect prompt injectionGetLost attackColdFusion vulnerabilityCold Fusion patchingAdobe productsGodDamn ransomwareBeast ransomware variantPoison X kernel driverMimikatz

Questions this episode answers

What is the GetLost attack and how does it compromise agentic AI systems?

GetLost is an indirect prompt injection attack where researchers socially engineered an AI agent by posing as a VP of sales in a fake inquiry, embedding plain English instructions within the message that tricked the AI into connecting to GitHub, accessing private repositories, and posting sensitive readme files to public comments, demonstrating that LLMs can be manipulated like humans through social engineering.

What is the ColdFusion vulnerability and why is it critical?

ColdFusion has a maximum severity, actively exploited remote code execution flaw that Adobe patched but attackers began exploiting within two hours of disclosure. CISA mandated immediate patching for government agencies, making this critical because exploitation occurs faster than most organizations can deploy patches.

How does GodDamn ransomware spread laterally and persist across networks?

GodDamn uses the Poison X kernel driver (with a legitimate Microsoft signature) to disable endpoint defenses, deploys 14 credential harvesting tools including Mimikatz, and uses stolen credentials to laterally move through the network while installing AnyDesk on each compromised machine for persistence via auto-start Windows services.

What is GhostApproval and which AI coding assistants are vulnerable?

GhostApproval is a technique using symbolic links that tricks AI coding assistants (Amazon Q, Claude, Cursor, Anti Gravity, and Windsurf) into editing files outside their intended workspace, potentially allowing attackers to write SSH public keys into authorized_keys files for unauthorized access.

When will OWA Lite be completely removed from Exchange Server?

Microsoft will disable and remove OWA Lite in August 2026 Exchange Server updates for on-premises deployments, ending support for this deprecated webmail interface that was marked for deprecation in 2024.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode covers multiple security news items (GetLost/prompt injection, ColdFusion, GodDamn ransomware, GhostApproval, OWA deprecation, GhostLock) but the analysis is often generic or diluted with tangential commentary. The host provides some tactical insights (time-to-mitigate vs. time-to-patch, permission controls for AI agents) but pads heavily with anecdotes, jokes, and off-topic references that reduce substantive content per minute.

Now, we've asked this question forever about our human employees, but we've just now started to ask it about agentic AI. And we're turning this stuff loose in our enterprises.
Maybe it's time to start talking about TTM instead of ttp. You know, what is your plan? I mean, just assume that it's going to happen.

Originality

8 / 20

While the framing of AI agent permissions as a security control problem is somewhat novel, most of the episode recycles standard vulnerability management talking points and well-known ransomware TTPs. Josh Marpet's discussion of CVE fragmentation and regulatory coordination failures is more original, but the host largely covers predictable ground (patch vs. exploit speed, deprecated software, symbolic links). Few truly contrarian or first-principles arguments emerge.

It's not a bug, it's a feature. I mean, the things that make us able to respond in a variety of ways mean we can respond in less than desirable ways.
we are seeing so many vulnerabilities in a system that doesn't scale this quickly. And we're in a system that has been defunded.

Guest Caliber

10 / 20

Josh Marpet appears to have relevant vulnerability management expertise and provides informed critique on CVE processes and CISA defunding. However, he is a guest on a news show discussing published research rather than an operator sharing firsthand experience executing complex security programs at scale. The episode lacks guests who have directly managed major incident response, AI governance, or ransomware recovery at enterprise level.

between six vendors there are two current CVEs, one in another one, the third one in the process of becoming real
we are seeing so many vulnerabilities in a system that doesn't scale this quickly. And we're in a system that has been defunded. Uh, CISA has had its, uh. And MITRE and the NVD have had all of their work defunded

Specificity & Evidence

11 / 20

The episode includes specific CVE numbers (CVE-2026-12958, CVE-2026-50549), named tools (Mimikatz, AnyDesk, Poison X), vendor names (Amazon Q, Claude, Cursor), and one concrete metric (5-day dwell time for GodDamn; 14 credential harvesting tools deployed). However, many claims lack corroborating details: the Brown University exam fraud example includes scores and percentages but no verifiable study data, and technical details on several vulnerabilities remain vague or anecdotal rather than data-driven.

they installed semantic exe, which is a binary, that was actually fake. So it Looks like semantic antivirus, but it's actually a fake binary. And that piece, uh, of code dropped Poison X, this malicious kernel driver.
the midterm score average was 96 out of 140 of the 86 students at the class got perfect scores

Conversational Craft

7 / 20

The host Doug White opens softball conversations with minimal follow-ups and rarely pushes back on claims. Josh Marpet's segment is the exception - he makes bold assertions about regulatory failure and the asymmetry of attack/defense, but White simply agrees and moves on rather than probing assumptions. Much of the episode is monologue with tangential jokes and personal anecdotes that reduce dialogue quality. The show lacks pointed questions that would stress-test the substantive claims presented.

Yeah, this is one issue. And we get six different fricking responses
Yeah, I always remember the days when somebody told you to review the logs.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A86%
  • Speaker B14%

Most-used words

security16glasses12class12problem11linux11course10back10students10different9access9start9exam9code8means8running8weekly7

Episode notes

Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Locutus, Josh Marpet, and More on this episode of the Security Weekly News. Visit for all the latest episodes! Show Notes:

Full transcript

33 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: It's the Security weekly news, episode 597. And it is Friday, the 10th day of July, 2026. I am Doug White, and welcome to the show. Today we have the Borg. Get lost. Cold Fusion. Got damn ghost approval. OWA or oa? Uh, uh, Epaphroditis, Locutus, Josh Marpet and more on this episode of the Security Weekly News. It's the show that keeps you up to date on the latest security news twice a week, your trusted source for accurate security information and expert analysis. It's time for the Security Weekly News. All right, I'm Doug White and welcome to Security Weekly News. Yeah, I would hit that like and subscribe button or, I don't know, Endless Summer. I mean, it's always the best season to not be in if you're in that season, but whatever, it'll work. Uh, every week there's another breach tied to an unpatched vulnerability. And with thousands of new CVEs each year, most teams simply can't keep up. So what actually deserves your attention? Join the Vulnerability Management Virtual CyberSecurity Summit on July 29th to hear how security teams are prioritizing real world threats, reducing exposure and staying ahead of exploitation. Security Weekly listeners can register for free@securityweekly.com vulnmanagement using the promo code CSS26SW. That's coming up, uh, in a little while, so be sure and sign up for that A I L L Ms. Can behave like humans. I mean, they're not human, but they can behave like humans. It means they can be tricked, fleeced, swindles and cons, just like the rest of us. Now, this particular story was about researchers who were able to exfiltrate information from AI uh, using indirect prompt injection, which is, you know, of course, where you put the prompt in something el else. Um, and it's not a bug anymore that, you know, I mean, this is not a bug any more than when your great aunt Ida sent that nice fellow $5,000 to get her grandson out of jail in Canada. It's not a bug, it's a feature. I mean, the things that make us able to respond in a variety of ways mean we can respond in less than desirable ways. Uh, now, NOMA Labs reported this fake sales inquiry that they posed as a VP of sales to this agentic AI and they said they were following up after a customer call. But in the midst of all this, there was a plain English instruction inside the material, and it got the AI agent to connect to GitHub, uh, to the AgentIC workflows section of GitHub and retrieved a private repository's readme file and posted it in a public comment for anyone to read. So they basically con, social engineered whatever you want to call it, this LLM, to get it to do all these things. And so it's not a bug, it's just manipulation of something that is designed to behave in different ways at different times. It's really more like that time Great Aunt Ida helped that nice man by carrying his bags out of Indonesia and served 20 years in a Turkish prison. Uh, that might have been Billy Hayes, but you get the idea now. They named this attack Get Lost. And my point for you is, what do you have that is now in the reach of LLMs? I mean, if somebody can convince Great Aunt Ida, how hard would it be to sweet talk an AI into retrieving a harmless little old file with the financials in it and posting it on a public forum? So it really turns this whole thing into a discussion about permissions and control. Who can access what and what can they do with it. Now, we've asked this question forever about our human employees, but we've just now started to ask it about agentic AI. And we're turning this stuff loose in our enterprises. We're ordering employees to use it, to use it for every task. And now we have to start worrying about what can it access, what can it do with the access and will it? So it's scary because this means we're going to have to expand our analysis of permissions and linkages and chains and to agentic AI. What can it access? What can it do? Can it post? Where can it post What? Where? I mean, this was one of the most daunting things in Audit because the companies just did not want to talk about it. Could that AI retrieve something from a repository that you control and repost those unfortunate photos of you when you thought maybe a Speedo would be a good idea and hand that over to the New York Times? Sure, why not? So you need to start understanding these flows as well, which is, I know you don't want to hear that, but you're going to have to. Or you're going to have to get rid of agentic AI and go back to just humans and worry about them. The threat landscape just shifted under your feet. Attacks move at machine speed now and you can't defend what you can't see. Tanium Atlas has changed that one prompt and it queries every endpoint in your fleet. Surfacing machines exposed to a live Axios supply chain compromise in seconds. This is live state, not a stale cmdb. It pinpoints which endpoints are truly compromised and traces the attacker's command and control. Atlas then secures the business by isolating, patching and remediating all at once. Tanium Atlas See everything, act instantly. Find out more@securityweekly.com Tanium Cyber Risk TV is proud to be an official media partner of Black Hat USA 2026. We'll be broadcasting live from the Black Hat Livewire studio with executive interviews covering the latest CY security trends, emerging threats, new technologies and the conversations shaping the industry. Our event Momentum packages can help you message, uh, your message reach security professionals long after the conference ends. So fewer than 10 interview opportunities remain. So please visit securityweekly.com exec today and reserve your spots before they're all gone and there won't be any more the U.S. cybersecurity and Infrastructure Security Agency, or CISA, which is a lot easier to say, ordered government agencies to patch an actively exploited maximum severity flaw in Cold Fusion by today. Now, I saw coldfusion, I was like, that still exists, but it's been around a long time. And it is an Adobe product that focuses on commercial web app development. Um, this exploit can be done remotely without privileges and is a low complexity attack which would allow remote code execution on unpatched systems. So I think that's the description of the worst possible thing you can experience. Uh, Adobe did release patches last week, but as ever, some of you are lagging behind. Kevintel said that attackers began exploiting the flaw about two hours after the disclosure. So if you have one of those 800 cold fusion instances that Shadow Server noted, you might want to patch it. And for me, the point is time to patch versus time to exploit. If your time to patch is, say, I don't know, 100 years and the time to exploit is one minute, well, we call that a bad problem. But it's also super bad if your time to patch is six days and the time to exploit is two hours. There are people sitting out there right now teed up and ready to go the minute these exploits are released. And they're often released with proof of concepts which show you exactly how to do it. Which means that anybody can grab that and say, let's go find some servers. Oh, here they are. They're all handily listed right here. Maybe you can't get the patches done in that amount of time. The committee has to form a committee and on and on. I mean, believe me, I've been there. I work at A university where they have to form a committee to decide if a committee can even be formed. So let's focus instead on time to mitigate. Maybe it's time to start talking about TTM instead of ttp. You know, what is your plan? I mean, just assume that it's going to happen. Just assume that you're not going to be able to patch this in minutes. So it's a fire drill, and you probably have several binders for physical fire drills. So how many binders have you got for time to mitigate? I mean, I think that mitigation focus and rapid response is going to be critical going forward. I mean, if the Who's it version 2.4 has a massive flaw that gets diagnosed, what does your mitigation team do? You have one, right? Does your mitigation team go in, close ports, isolate and monitor that thing until a patch can be put in place? And how quickly can they do that? Because they really have got this thing down to where it almost needs to be within minutes, like a real fire. So if somebody calls, if the fire alarm goes off and the accounting department is aflame, how fast do you respond to that? Do you form a committee and take six weeks to try to decide whether we should call the fire department or does somebody run down there with a blanket and try to put it out? And are. Do people leave through the exits? Think about it. A new ransomware called God Damn was reported by Symantec and Carbon Black. Uh, it appears to be a rebrand of Beast, and it uses a malicious driver called Poison X to disable endpoint defenses. So this is, of course, a really nasty thing. Uh, the first sightings of this were back in May, and it seems to have a lot of things in common with Beast. And of course, Beast got a lot in common with an older software, uh, called Monster. The latest version that they observed had a dwell time of about five days where they were in the network and they did not deploy any encryption or ransomware tactics for that period of time. They did not detect the initial vector, but it would be suspected, of course, that it was an, uh, employee who had been compromised, meaning social engineered or something. When that happened, the attacker installed anydesk, which is one of these remote management tools, and they put that on the first Victim machine in the music folder. And so it seems like someone that already had access to that system or they got the employee to do this for them. Now, after that initial install, a day later they installed semantic exe, which is a binary, that was actually fake. So it Looks like semantic antivirus, but it's actually a fake binary. And that piece, uh, of code dropped Poison X, this malicious kernel driver. And the driver appears to have been developed by the attackers who somehow got a legitimate Microsoft signature for this driver so that it would install and be used. Now, after all that happened, the ransomware finally it starts running and it deploys 14 credential harvesting tools, including our favorite Mimikatz, Nersoft and all kinds of other things. The tools then in the background collect uh, credentials from the browsers or anything else they can get access to on that machine. And they pretty much can get access to everything because it was installed and any desk is going to be running with rootpril privilege, admin privilege, whatever, and after they get from credentials, they start moving laterally using those stolen credentials and then each new machine gets installed anydesk and then that's the way it works. It also had two auto start windows services enabled in the background for persistence. So you reboot and it pops right back up. Eventually they get round to encrypting the system. So I guess again the point would be, what's your plan, you know, when this starts happening in your organization? Uh, I wrote a simulation of this once with 236 endpoints and I wanted to time it so that everything in the organization was encrypted within it was like 4 minutes and 37 seconds because we were doing a presentation and we wanted the people watching to see all the machines turning red in the background as they got encrypted. So you don't have a lot of time. So when this happens, what are you going to do? Is everybody going to be running around trying to figure out the number for Lou, who's the only person that's got keys to backup tapes or the server room and nobody can find him since he lost his phone in Sweden and never updated the number and the files and is on vacation this week. So think about it. It can happen, it will happen. And what is your response going to be when it does and how fast is that response going to occur? Because you're not going to have a lot of time. Ghost approval is a technique which can enable malicious code repositories to trick boy, tricking them again. AI coding assistants into editing files outside of their intended workspace. According to Wiz, the method they released is a proof of concept and it uses an oldie but a goodie. Symbolic links. Oh my. Uh, now I think all of us have probably used a symbolic link or two to point to something and Manipulate that something probably on somebody else's system just for fun. I mean, you know, just putting in a symbolic link for LS to make it point to E cpuinfo. So when they try to get a directory, they get all this weird descriptions of CPU processors. I mean. No, I never did that either. No way, man. I was in church praying that the Virgin Mary would feed those starving kittens I heard about. Sorry. Somebody sneezed on me in the subway last week and it's still affecting me. Linux? Never heard of it. Well, I sure do hope you catch those disrespectful miscreants, Officer. Our junior, uh, colleges are just no place for these kind of monkey shines. Uh, but anyway, Wiz found out that they could write an attacker's SSH public key into the victim's authorized keys file, which would allow you to log in with ssh. I mean, I like this attack. They tested this with Amazon, Q Dev, Claude Code Augment Code, Cursor, Anti Gravity and Windsurf. So, like the first story today, we're probably going to quickly have to come to terms with these things since we keep handing over the keys to them, but we really didn't do our background checks yet. Ever feel deprecated? I do, all the time. I may be deprecated right now, and if you're not a programmer, you may not know what that word means, but something that's marked as deprecated means it still works, but it may not work for much longer. Kind of like me. So you probably should expect it will stop and maybe make plans or phase it out before it stops. But people don't, you know, I mean, how many times have you had that problem and everything quit working? I mean, we've all been there. Microsoft marked Outlook web access, or OA, uh, light as deprecated back in 2024, but guess what? A lot of people still using it. Microsoft will disable and remove oa Lite on August 2026, uh, in the Exchange Server update. This is only on prem, apparently. I don't think Ola Lite works in the cloud version. It means that this is no longer deprecated, but dead, dead, dead. May God have mercy on your soul. Now this product is used with, on, um, PREM Exchange server operations and it is so old. I remember setting it up for a school. They were like, do you know how to set this OO thing up? And I'm like, yeah, I can work on it. So if you're using this thing from the distant past, I mean, it was still legit up to 2024 where you don't really have a lot of time left to find an alternative for your users. Uh, it's another planning issues for CISO and CIOs like what do we do when something is marked deprecated? Do we immediately start addressing it? Or we just say if it ain't broke, don't fix and leave it alone until one day it quits working altogether. Now I mean, you know, some of you slackers are still going to be saying do we have this in our system? And your half brain dead sycophantic assistant Igor will say yes doctor, we do. I, I called all my grad students Igor. It was just easier that way. You don't want to get to know them because you know, pretty soon you have to like put them down and you know, they get, they start getting all foaming at the mouth and think they're going to get degrees. Just have to laugh now. You know, I love Linux and I do use Windows because it's easier for school stuff and I know I could run it in wine and all that kind of thing, but uh, it's just easier now. Linux was always thought to be safer and more secure and so forth because of various reasons. And you know, Linux is based on ancient secrets and tomes and all this kind of stuff and it's now getting the kind of targeting that I think Windows got in the early going. You know, I mean everybody went after Windows and nobody went after Linux. But today, yeah, they're going, the AIs love Linux and they're deconstructing it, uh, taking it apart and finding every cobweb and other problem and it's probably time for us to shake out all the moths from the Linux blanket. And AI is doing that and finding old problems that have been there for just about forever. Like that lead pipe that they tell you is not in your building until you start thinking you're Epaphroditus and saying yes Mr. Nero, let me look into that. Uh, what? Nobody, no one, nobody knows Epaphroditus? Epaphroditus was Nero's secretary. You know, like, will Mr. Nero be doing anything about the People's Front of Judea? Well, no, Ken. Mr. Nero is currently attending an orgy this weekend with the Emperor of the Visigoths, Wulfgar the Masticator, to discuss barbarian relations. And you call yourselves educated? Please. Anywho, this flaw in Linux is called Ghost Lock and apparently was in the kernel for 15 years until it was patched in April. Yeah, So I guess I'll use this as a reminder that you may actually need to start paying attention to those old Linux servers that are sitting down in that dusty server room that have been running for like 20 years and nobody ever checks on them physically. And you go down and I'm telling you, this happened to me. I literally was looking at a server that had been running for not 20 years, but had been running for like three years. And I had never logged into it because it was running, it was fine, it's Linux. And I went to look at the main screen, I logged into it and it had all these, uh, IO errors. It was still working, but it had IO errors. And I'm like, well, that's not good. And so I started investigating it and on and on and on. And I found out that it had a problem after a kernel update. And I have rebooted more Linux machines since April than I probably had in my whole life up to this point. I mean, I never rebooted these things. I think I'm going to change my name to Doug the Rebooter. But I mean, what do you have that's sitting out there in the dark blinking system restart required. Don't do it lightly though. I will tell you, I just spent all day yesterday fixing that storage issue that was caused when I rebooted the server. I rebooted it and there was a problem with uh, a flag and I had to get a script that would process all that and update it and reboot them all again. Yeah, so reboot, yes, but have a plan for that and be sure to have a plan of what you're going to do when all else fails. Because I had to fall back to some snapshots and things to go, what in the hell just happened? Well, sci fi is here in a way. I mean, so many of the things I read in sci fi that was written in, you know, long ago, we're starting to see it. And I see more and more stories about AI glasses. I get all these ads for AI glasses, you know. You know, like, ah, are you in Tokyo? And you don't know what somebody's saying? Uh, your glasses will tell you that. They're saying, get the hell out of my way. But of course I can't afford AI glasses. So I'll just have to continue having people yell at me and not knowing why. But they are starting to be available now. I've always had a lot of skepticism of this technology since way back I knew people who bought Google glass for like $1,500 a pop. And of course, those things are laying on. I know one person where they're laying on the shelf as a, you know, exhibit that they paid $1,500 for and they never actually were able to use. But it does seem to be drawing closer to us. I guess I could get into glasses that displayed the name of the person I was meeting, or could translate Glaswegian accents into, uh, I don'. Know, Southern hillbilly speech. How y' all doing? Uh, you know, I mean, I think that would be interesting. I mean, I think it would take some getting used to. And of course, well, you know, just as you reach that roundabout in Nottingham that's kind of tight, and an ad for Jaffa Cakes pops up in your glasses and starts playing, and you have to decide if you should just drive into the canal and call it a day. I mean, I worry about that kind of stuff, but I don't know. I mean, I guess the map that's being projected under my glasses instead of me trying to read a paper map that I'm holding up on the steering wheel, trying to figure out the streets in Copenhagen at rush hour. Yeah, I mean, it may be better than that. It's better than looking down at my phone screen that's laying on the car seat going, is this where we're supposed to be? So a display in the lens is interesting to me. Uh, supposedly meta has sold 7 million pairs of these things recently, and they just announced that a new, cheaper version was going to come out. Now, of course, using your smart glass cameras to harass and film people is also a thing that has come out of this. So, I don't know, maybe drop the camera from it. Like, do you really need to film? You know, I mean, it's like a dashboard cam for your life. But anyway, Apple is apparently moving toward. The whole article is really about Apple moving towards AI enabled glasses. Well, that are going to be associated with AirPods. And I guess you put the AirPods in and pull the glasses on, and now your whole world is being streamed by Apple, who will know exactly where you are and what you're doing. I don't think this tech is quite ready for general use yet, but I do think it's going to be here very, very soon. Probably be projecting ads for Greg Sausage rolls onto my retinas, uh, directly, and that probably get me to buy one. I could use some subtitles for life, uh, considering how bad my hearing is. Hey, why not? And hey, your glasses told you who Epaphroditus was Before I did probably realize what I was going to say. Zero trust is clearly the future, as threats get faster, quieter and harder to detect. But implementing it shouldn't disrupt the business. ThreatLocker enforces default deny at execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold, trusted apps stay contained, and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead. See why CISOs are adopting it@securityweekly.com now, if I can get some glasses that would make everyone seem to be like Josh Marpet, the world would definitely be a better place. So. Hi, Josh.

Speaker B: Hey, how you doing? Uh, I've actually got an interesting one today. I wanted to talk. So I want to talk about ghost approval as well, but from a different perspective. Okay, so Ghost approval is an interesting one. It's about AI and about how they're able to reach outside of their, uh, of their sandbox. Exactly correct. But the interesting piece to me was, I mean, that was cool, don't get me wrong. But the interesting piece was that there were six vendors that were immediately affected. And between six vendors there are two current CVEs, one in another one, the third one in the. In the process of becoming real. So the same vulnerability, three different CVEs from three different vendors. Then, uh, you got another vendor. So let's see. Amazon, uh, did CVE2026 12, 9, 5, 8, um, cursor. Did CVE2026 50549. Claude, uh, code said it's outside our threat model. They had already fixed it six days earlier. They literally didn't even know they'd already fixed the problem. The same company. Okay, um, Google Anti Gravity still has a CVE under assessment, so there's going to be a third CVE for the same thing. And Augment. Augment has said, oh, yeah, yeah, it's not really our problem and has done nothing about it. Uh, and as well, Windsurf has done nothing about it. So, uh, as far as I know, they're both very silent. Which, uh, basically means that there are two vendors out of six that are still allowing their users to be, uh, effectively in danger. Four of them. Between the four of them, they'd already fixed it. And three different CVEs coming out M. Oh my God. And we complain about vulnerabilities and why we're all screwed up with them. Yeah, this is one issue. And we get six different fricking responses, including, that's not our Problem. Uh, you do know you already did a bug fix on that, right? Oh, oh, oh, uh, yeah, thanks. Uh. Uh, yeah, yeah, yeah, we'll go. The. Yeah, okay. Nevermind. The. The point here is not about ghost approval. Fascinating Vuln. Really big problem, don't get me wrong. Bad things. But that we are seeing vulnerabilities show up. And you mentioned this, Doug, just a few minutes ago. We're seeing. You know, they're calling it the, the vuln apocalypse. I know. Everything's apocalypse. Sorry. But, uh, AI apocalypse, vulnpocalypse, tulip, whatever. Anyway, uh, the. The problem is that we are seeing so many vulnerabilities in a system that doesn't scale this quickly. And we're in a system that has been defunded. Uh, CISA has had its, uh. And MITRE and the NVD have had all of their work defunded to a significant extent. Not entirely, but pretty significantly. Uh, and for example, it's also been defunded in terms of feature ability. Uh, they're no longer enriching the CVEs that are not being used by the US federal government. Wow. So we're increasing massively the amount of vulnerabilities. We're not coordinating all of our CVEs. We're letting CNAs CVE numbering authorities just do whatever the hell they want, however the hell they want. So, okay, go ahead, find a CVE. Oh, wait, did you find the other 17 that are affiliated with that CVE? And then you've got things like Eucra, which is in the European Union. If there's an exploited vulnerability, every single company whose product has it has to report it to anisa, which is their central reporting authority there. Which means that if you sell a single module to 5,000 different companies, to put it like, you sell a chip, a WI FI chip, you sell a WI FI chip, you sell a WI FI chip to everybody. Okay, let's be honest. And you've got that WI fi chip in 5,000 different companies products. If there's a vulnerability in that wi fi chip, 5,000 companies and the manufacturer are going to report it to anisa. There's nobody set up to scale at that kind of level. What we have here is people, uh, that are writing regulations and rules, thinking that things take weeks and months and years. They now take minutes and hours and days. And this is the kind of thing that I want to talk about. I want to say that if we don't rebuild our systems, we are going to have massive issues. We cannot keep up. We Just simply cannot keep up the attackers right now. And this is going to change. It always goes back and forth. This is a pendulum, okay, between attack and defense. But right now the asymmetry is in favor of the attackers. So what I'm going to say is I urge you, as security researchers. And you are a security researcher, right? As security researchers and compliance researchers, please figure out ways to move the asymmetry back to where the defender has the advantage. This is a problem and by God, we really all need your help. Doug, back to you, sir.

Speaker A: Yeah, I always remember the days when somebody told you to review the logs. And the first time that ever happened to me, I was like 18 years old and I was the uh, sysop in this mainframe, uh, center. And this guy, uh, told me, you need to review these logs every day. And I was like, uh, how many pages is that? It's like, that's probably like 9, 10,000. Just sign on the first sheet. That's all we do. You know, I mean, there's no way to do that. And I think, you know, getting bombarded like that with this is just not a process. But yeah, we gotta fix this because it's gonna get worse and attackers are getting faster and faster and faster and we're getting slower and slower and slower because I haven't even got the first file folder put together before the attack is already and go running and uh. So yeah. Thank you. Thank you, Josh. Um, a recent survey of Princeton students found 29.9% admitted. So it's probably understated admitted cheating with AI on at least one exam or assignment. Yeah, it's got to be higher than that. So this professor at Brown University, which is located in Providence, uh, said that he teaches a class called Econ 1170, which is very difficult class and doesn't get a lot of people to sign up. So it's, you know, for econ nerds. And he, during, after this uh, shooting incident that happened last year, he decided to allow some take home exams in this class instead of in class written exams due to the incident. Suddenly he said students flocked to the difficult class which was normally only attracting top students. And he said it suddenly went from almost nobody enrolled to filled to capacity. He said that this spring in that class the midterm score average was 96 out of 140 of the 86 students at the class got perfect scores, not good scores. Perfect scores in a class. Listen to this. Where typically the average score on this exam was between 65 and 80 80. So it's not that hard of a class. So he switched in the spring. Boy, you want to talk about making your teaching evals go up? He switched, uh, the final exam after the midterm to being an in class, in person, written exam. He said 18 students in the class immediately dropped the course. Nine of them did not even bother to take the final exam. And he said of those 27 students that dropped or didn't take the exam, 22 of them had perfect scores on the midterm. The average on the in person final. Any guesses? 48%. Down from that 96% average on the midterm. Now, I can attest to this. I see students all the time with perfect work, beyond perfect code. You only dream about database queries that look like they were written by C.J. dayton, Edgar Codd's Ghost, using a Ouija board. Not all students, believe me. But we have got to do something about this. I have been talking about switching back to, uh, paper exams that are given in class. It's a big hassle, but I think we're going to have to do it. I don't let students hold their phones, and that gets some of them very upset because I think in the spring, I told one student to put his phone away like five times. And I finally said, either you put your phone away or you get an F. Understand? And he's like, oh, I'm just chatting with friends. And I like, it's an exam. You don't need to chat with friends. Put your phone away. And he's just like, still. He was literally still typing on his phone while we were talking. And I was like, I'm just going to come grab your phone away from you and see what you're typing. And he was like. And he put it away. And guess what? His score on the, on one exam went way down on that exam. And I know why, so I don't know. My homework is experiential, so if you can do the intrusion analysis, I don't really care what tools you use, that's in the scope. But we're about to have a whole generation of kids that had access to AI in secondary school. And guess what? They're going to use it. I mean, they're going to use it as much. And of course, wait till they all have AI glasses and Elon Musk brand brain implants. And then you'll see. I mean, you think the Borg are bad? Well, I for one welcome our collective overlords. But. Oh, hi. Hi. Locutus. New USB C assimilation port there on your face. Oh, it's Thunderbolt 5. Yeah, sorry. You know, Apple, what are you going to do, man? You got to buy all new cables now for your assimilation. So I think it's going to be a wild ride. Wait till your 10 year old kid gets my epaphroditus jokes and you're left sitting there with your old fashioned X ray specs that can't even translate ancient Sumerian runes. Think about it. Anyway, thank you for watching. Thank you, Josh. And we'll see you next time on the Security Weekly News. Thanks for watching. If you want more content like this, head over to securityweekly.com subscribe. You'll find all our shows, the latest episodes, and everything happening across the Security Weekly network. See you next time.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Radiology Can't Keep Up. Here's Where AI Actually Helps | Dr. Nina KottlerRethink Imaging · on Agentic AI96 / 100
  • Can responsible AI beat hallucinations?The ITPro Podcast · on Agentic AI95 / 100
  • How People Intelligence Is Helping Shape Cisco’s AI Workforce TransformationDigital HR Leaders with David Green · on Agentic AI92 / 100
  • Agentic AI in the Commercial Workflow with Johnson Controls CDIO Vijay SankaranEnterprise AI Innovators · on Agentic AI88 / 100
  • Turning AI Agents Into Revenue Workflows With OutreachTech Talks Daily · on Agentic AI83 / 100
  • Unscripted with Victor: Agentic AI, Fintech's Future, and the Death of the App EconomyVentures from The Valley · on Agentic AI83 / 100

More from Security Weekly Podcast Network

All episodes →
  • Followership, CyberSecurity Leadership, and Judgement as a Defining Skill - Kenyada Meadows - BSW #46577 / 100
  • RoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More - SWN #616
  • The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400
  • Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
  • 9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615
Explore the best B2B Engineering & DevTools podcasts →
All Security Weekly Podcast Network episodes →