S0:E27 — The Agentic Ransomware Story That Wasn't episode artwork

EPISODE · Sep 4, 2026 · 33 MIN

S0:E27 — The Agentic Ransomware Story That Wasn't

from Breach Please

Palo Alto's Unit 42 published a report describing a fully automated, agentic AI ransomware attack, complete with an 80-page lessons-learned document the attackers supposedly left behind for the victim. It got picked up and ran with by outlets looking for the AI-apocalypse angle. Jess and Jake go through what the report actually says versus what got exaggerated in the retelling, and call out the pattern of vendors using AI-attack framing to sell their own AI-defense product.Second half: a stolen API key with no spending cap burned through hundreds of thousands of dollars in usage before anyone noticed. Jess and Jake use it to talk through exposure management, reachability analysis, and toxic combinations, why chasing CVSS criticals alone is the wrong way to prioritize vulnerability management, and where AI can actually help defenders instead of just generating more hype.In this episode:Unit 42's "agentic ransomware" report: what checks out and what's marketing spinWhy "the threat actor used AI" doesn't mean the defense should be AI-shapedPractical advice for stakeholders asking "how do I defend against AI-driven attacks"Toxic combinations and why prioritizing by CVSS score alone failsA stolen API key with no spending cap and the usage spike that followedExposure management, reachability analysis, and where AI genuinely helps defendersAdam Shostack's updated threat modeling book and his PHANTOM-B threat model frameworkShow notes:Unit 42 report: https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/The Register coverage: https://www.theregister.com/security/2026/09/02/ai-agents-carried-out-every-step-of-this-ransomware-attack-then-left-the-victim-an-80-page-security-audit/5294009API key incident (The Register): https://www.theregister.com/security/2026/09/01/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-noticed-for-weeks/5293730Threat Modeling, 2nd Edition (preorder): https://www.amazon.com/Threat-Modeling-Designing-Adam-Shostack/dp/1394413327PHANTOM-B whitepaper: https://shostack.org/files/papers/PHANTOM-B_Whitepaper_Shostack.pdfBreach Please is a production of JWJH Media LLC. The opinions of our hosts are their own. Nothing in this episode is legal, financial, or security advice. Do your homework before pointing anything we said at prod.

Episode metadata supplied by the publisher feed · Published Sep 4, 2026

Embed this episode

Ready to play

S0:E27 — The Agentic Ransomware Story That Wasn't

0:00 33:45

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Breach Please?

This episode is 33 minutes long.

When was this Breach Please episode published?

This episode was published on September 4, 2026.

Can I download this Breach Please episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!