EPISODE · Jun 8, 2026 · 40 MIN
Minutes, Not Months: Inside the New Cyber Velocity Facing Federal Agencies
from The GIST of Govt IT · host Swish
48 hours. That's the time it took for a federal employee credentials to be stolen as a result of a phishing attack, to being listed on a dark web marketplace. In Episode 8 of The GIST of Govt IT, Brian and Sean sit down at Check Point's Engage Summit in DC with Yochai Corem, General Manager of Check Point's Exposure Management division, to unpack what happens when both sides of cyber warfare have agentic AI — and why the next three years will not be kind to defenders. Yochai shares why pen testing once a quarter is no longer relevant, how a single Chinese developer built an entire attack program in a week using an army of agents, and what Iranian threat actors targeting Israeli hospitals look like in real-time during active kinetic conflict. The conversation digs into agentic red teaming vs. automated red teaming (and why the difference matters), why "safe remediation" still keeps a human in the loop, how to use the firewalls, WAFs, and IPS you already own as compensating controls when patching takes weeks, and the under-discussed reality that government leaders must put their hands on the keyboard with AI. Plus: Yochai's family cookbook and other vibe-coding stories.RESOURCES MENTIONED IN THIS EPISODEFeatured Guest- Yochai Corem, GM, Exposure Management, Check Point- Corem Travel — Yochai's travel planning app Check Point- Check Point- Check Point Exposure Management- Check Point Engage Summit - Washington, DC Check Point's Exposure Management Acquisitions- Cyberint (now part of Check Point's external risk management)- Veriti (automated security control management)- Cyclops (now Check Point's CAASM offering)Exposure Management & CTEM Framework- Gartner Continuous Threat Exposure Management (CTEM) overview- CISA Known Exploited Vulnerabilities (KEV) Catalog Agentic AI & Red Teaming- OWASP Top 10 for LLM Applications- OWASP AIVSS — AI Vulnerability Scoring System for Agentic AI- MITRE ATLAS (Adversarial Threat Landscape for AI Systems)Threat Actor Tracking- Check Point Research (threat intelligence blog)- Check Point ThreatCloud AIConcepts & References- Air-gapped network security guidance (NIST SP 800-82)- IRGC (Iranian threat actor background — CISA advisory on CyberAv3ngers)Related Episodes- Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT Fight- Episode 6: Cupcakes & OODA Loops: Inside(r) Insights Into the New Federal AI Cyber Playbook- Episode 5: Vibe Hacking and Nation State Cyber ThreatsUpcoming Events- GIST 360 Breakfast Briefing at the National Press Club, July 14, 2026 - When the Perimeter Disappears The Hosts & Show- Swish - GIST 360 CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - [email protected] Applegate - [email protected] wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
Embed this episode
What this episode covers
48 hours. That's the time it took for a federal employee credentials to be stolen as a result of a phishing attack, to being listed on a dark web marketplace. In Episode 8 of The GIST of Govt IT, Brian and Sean sit down at Check Point's Engage Summit in DC with Yochai Corem, General Manager of Check Point's Exposure Management division, to unpack what happens when both sides of cyber warfare have agentic AI — and why the next three years will not be kind to defenders. Yochai shares why pen te...
NOW PLAYING
Minutes, Not Months: Inside the New Cyber Velocity Facing Federal Agencies
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.