Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents episode artwork

EPISODE · Jun 18, 2026 · 45 MIN

Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

from The Cyber Threat Perspective · host SecurIT360

AI agents can search the web, manipulate files, run commands, make API requests, access cloud platforms, and operate fully autonomously. They are powerful, they are here, and most organizations have no security controls around them whatsoever.In this episode, Brad and Spencer break down the five major AI agent risk categories security teams need to understand right now, using Simon Willison's "lethal trifecta" as a framework and building on it with two additional risk areas they see in the field.In this episode:- What an AI agent actually is and why the definition matters before you can secure it - What AI agents are capable of: files, commands, APIs, memory, cloud access, and autonomous execution - The lethal trifecta: access to private data, exposure to untrusted content, and external communication - Risk category 1: Access to private data - why agents inherit your permissions and why that is dangerous - Risk category 2: Exposure to untrusted content and prompt injection attacks - Risk category 3: External communication and data exfiltration (including a real canary token experiment) - Risk category 4: Privileged access and limiting blast radius with least privilege identities - Risk category 5: Autonomous actions, approval gates, rate limits, and kill switches - Why backups, rollback plans, and recovery playbooks are more important than ever in an AI agent worldResources mentioned:- Simon Willison's lethal trifecta post (June 2025): https://simonwillison.net - Zach Korman's ContinuumCon sandbox escape workshop: https://continuumcon.com/schedule/ - offsec.blog | securit360.comNeed a pen test before end of year? Q3 slots are filling up fast. Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Episode metadata supplied by the publisher feed · Published Jun 18, 2026

Embed this episode

AI agents can search the web, manipulate files, run commands, make API requests, access cloud platforms, and operate fully autonomously. They are powerful, they are here, and most organizations have no security controls around them whatsoever. In this episode, Brad and Spencer break down the five major AI agent risk categories security teams need to understand right now, using Simon Willison's "lethal trifecta" as a framework and building on it with two additional risk areas they see in the f...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

0:00 45:56

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Cyber Threat Perspective?

This episode is 45 minutes long.

When was this The Cyber Threat Perspective episode published?

This episode was published on June 18, 2026.

Can I download this The Cyber Threat Perspective episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!