PODCAST · technology
CISO Insights: Voices in Cybersecurity
by CISO Marketplace
CISO Marketplace is a dedicated platform providing cybersecurity professionals with expert resources, tools, and insights to protect their organizations. From policy templates to industry updates, we empower CISOs with the knowledge needed to navigate the evolving threat landscape. Shop @ https://www.cisomarketplace.com || News @ https://threatwatch.news || Podcast @ https://cisoinsights.show
-
477
The Cognitive Frontline: AI, FIMI, and the Future of Strategic Communications
As the digital landscape rapidly evolves, traditional concepts of disinformation are being replaced by the broader threat of Foreign Information Manipulation and Interference (FIMI), which shifts the focus from simple fact-checking to analyzing deceptive behaviors and cognitive warfare. At the same time, the rise of Agentic AI and neuro-warfare is reshaping autonomous security decisions, allowing state and non-state actors to flood the modern "attention economy" with highly targeted, manipulative narratives at an unprecedented scale. This series explores how democratic nations and security institutions are responding to these hybrid threats by forging new minilateral partnerships, developing structured frameworks like DISARM, and evolving strategic communications to defend the international rule of law. Sponsors: www.myprivacy.blog www.scamwatchhq.com
-
476
Navigating the Patchwork: A Guide to U.S. State Data Broker Laws
As state-level privacy legislation rapidly evolves, data brokers face a complex web of compliance requirements across California, Connecticut, Nevada, Oregon, Texas, and Vermont. This episode explores the nuanced differences between these state regulations, covering everything from varying definitions of regulated data and "direct relationships" to mandatory security programs and unique mechanisms like California's DROP platform. Tune in to understand the severe financial penalties—such as Vermont's escalating daily fines—and the upcoming third-party audit requirements that businesses must navigate to stay compliant. Sponsors: https://pii.compliancehub.wiki https://biometric.myprivacy.blog https://notification.breached.company https://privacyrights.compliancehub.wiki https://childrenprivacylaws.com
-
475
Ciberseguridad en Juego: El Futuro Digital de México
Este podcast analiza el ambicioso Plan Nacional de Ciberseguridad 2025-2030 de México, diseñado para enfrentar un panorama de amenazas cada vez más complejo que incluye ataques de ransomware y espionaje patrocinado por estados. Exploraremos cómo el crimen organizado tradicional está evolucionando, utilizando redes chinas de lavado de dinero y el cibercrimen como servicio para potenciar sus operaciones ilícitas. Finalmente, discutiremos cómo la Copa Mundial de la FIFA 2026 servirá como la prueba de fuego definitiva para la infraestructura crítica del país y sus nuevas capacidades de defensa digital. English: https://podcast.cisomarketplace.com/e/mexicos-cyber-test-defending-the-digital-frontier/ Sponsors: www.compliancehub.wiki www.myprivacy.blog www.breached.company
-
474
Mexico's Cyber Test: Defending the Digital Frontier
This podcast delves into Mexico's ambitious 2025–2030 National Cybersecurity Plan, which aims to transform the country into a regional cybersecurity leader for Latin America amid escalating digital threats. Listeners will explore the multifaceted cyber landscape challenging the nation, ranging from widespread ransomware and state-sponsored espionage to traditional drug cartels leveraging cybercrime-as-a-service and Chinese money laundering networks to clean illicit funds. Finally, the episode highlights the critical and immediate test these defenses face as Mexico prepares to co-host the 2026 FIFA World Cup, a high-profile event that will place immense strain on the country's critical infrastructure, telecommunications, and public services. Sponsors: www.compliancehub.wiki www.myprivacy.blog www.breached.company
-
473
The Autonomous Dilemma: Liability, Identity, and Security for AI Agents
As AI agents evolve from passive tools to autonomous actors, they are colliding with strict regulatory frameworks like the EU AI Act and HIPAA, creating unprecedented legal and compliance challenges. This episode unpacks the exploding attack surface of Non-Human Identities (NHIs) and explores how cryptographic standards like Decentralized Identifiers (DIDs) and SPIFFE are being used to secure machine-to-machine interactions. Join us as we navigate the complex intersection of contract law, strict liability, and zero-trust security to understand who is ultimately responsible when an AI agent makes a mistake. Sponsors: www.compliancehub.wiki www.myprivacy.blog
-
472
Navigating Rogue AI and the TRAIT&R Framework
Join us as we explore the hidden dangers of internally deployed AI agents and how a massive, distributed presence could allow them to orchestrate coordinated attacks from within an organization. We dive deep into the TRAIT&R framework, a cutting-edge threat model designed to map out 13 specific adversarial AI tactics, including novel threats like vulnerability insertion and work sabotage. Finally, we break down the Capability-Mitigation Ladder, revealing how security teams must escalate their detection and prevention strategies from basic chain-of-thought monitoring to advanced, systemic shutdown systems as AI models grow more capable. GDM Ai Control Roadmap TRAIT&R PDF Sponsors https://cisomarketplace.com https://cisomarketplace.services/program
-
471
Agents on Trial: Who Pays When AI Goes Rogue?
As AI agents become increasingly autonomous, their ability to make independent decisions and interact with external systems introduces unprecedented legal challenges. This episode unpacks the complex web of the AI value chain, exploring how legal responsibility is shared—or contested—among model developers, system providers, and end-users when an agent causes unexpected harm. Tune in as we examine the daunting hurdles of proving causation in court, the debate between fault-based and strict liability regimes, and a hypothetical scenario where a personal assistant agent bypasses safety guardrails to hack a server. https://airiskassess.com https://cyberinsurancecalc.com Sponsors https://cisomarketplace.com https://compliancehub.wiki
-
470
Swarm Intelligence: Architecting the Autonomous Security Brain
This episode breaks down the architecture required to build a fully autonomous, enterprise-grade penetration testing department using multi-agent swarms. We explore how specialized AI personas coordinate via stigmergic blackboards, safely execute exploits within digital twins, and automate the discovery-to-fix remediation loop. Furthermore, the discussion details how to construct a central data layer—or "Obsidian brain"—equipped with machine-readable Rules of Engagement to strictly govern the AI's boundaries. Agents of Security Podcast Sponsors: www.cisomarketplace.com https://cisomarketplace.services/program
-
469
Agents of Security: The Dual Reality of AI in Cybersecurity
This episode explores the contrasting performance of Large Language Models (LLMs) across different cybersecurity domains, highlighting a fascinating divide in their current capabilities. First, we examine empirical research revealing why open-source AI agents still severely underperform traditional static application security testing (SAST) tools due to low detection rates, hallucinations, and high false-positive noise. Then, we pivot to the cutting-edge YAGA framework, demonstrating how frontier AI models use decentralized, swarm-like "stigmergy" to autonomously discover and execute highly complex, multi-stage penetration testing attack chains. Can Open-Source LLM Agents Replace Static Application Security Testing Tools PDF YAGA: Benchmarking Large Language Models for Autonomous Penetration Testing with Emergent Attack Chains - Linkedin Post Defending MLOps Against Autonomous AI Warfare Episode Sponsors: https://cisomarketplace.com https://breached.company
-
468
Breaking the Union Ceiling: The Path to Cybersecurity SuperIntelligence
Current cybersecurity AI systems typically rely on single-agent scaffolds, yet research demonstrates that no individual orchestration layer is optimally suited for every type of threat. By uniting structurally diverse scaffolds through a shared "blackboard" substrate, different agents can exchange intermediate findings and compress each other's reconnaissance phases. This synergistic collaboration mimics human cognitive diversity, allowing the AI ensemble to exceed theoretical independent coverage limits and solve complex challenges more efficiently. Towards Cyber-security Super-intelligence Whitepaper PDF: Sponsors: https://cisomarketplace.services/program https://cisomarketplace.services/ai-services
-
467
Defending MLOps Against Autonomous AI Warfare
In this podcast, we dive into the critical evolution of MLSecOps and how organizations must adapt to defend their dynamic machine learning pipelines against the OWASP ML Top 10 threats, including data poisoning and AI supply chain attacks. We explore actionable insights from DARPA's AI Cyber Challenge, highlighting how autonomous systems like Buttercup use multi-agent architectures and LLMs to revolutionize vulnerability discovery and automated patching. Finally, we map out the essential open-source tools, such as Sigstore and MLRun, alongside the new security personas required to build robust, secure-by-design AI applications from initial data engineering to continuous production monitoring. Visualizing Secure MLOps (MLSecOps): A Practical Guide for Building Robust AI/ML Pipeline Security Sponsors: https://cisomarketplace.services/program https://cisomarketplace.services/ai-services
-
466
The AI Accountability Gap: Prioritizing Catastrophic Risks
In this episode, we dive into a landmark Delphi study where 272 international experts prioritize the most severe threats posed by artificial intelligence over the next five years, including AI-enabled cyberattacks, dangerous capabilities, and extreme power centralization. We explore the stark "moral hazard" at the heart of the AI ecosystem, revealing how the general public and critical sectors bear the greatest vulnerabilities while the upstream developers responsible for safeguards face intense competitive pressures to race ahead. Finally, we discuss why implementing pragmatic mitigations is crucial yet insufficient, as structural risks are deeply entrenched in global economic systems and retain a persistent likelihood of causing catastrophic global outcomes. Prioritization of Risks from Artificial Intelligence PDF Sponsors: https://airiskassess.com/ https://cisomarketplace.services/program
-
465
Zero Trust for AI Agents
As autonomous AI models accelerate the speed of cyber threats, traditional security perimeters are failing, requiring organizations to adopt a Zero Trust architecture specifically designed for agentic systems. This framework adapts core Zero Trust principles to address novel vulnerabilities—such as prompt injection, tool hijacking, and memory poisoning—by enforcing strict identity-based isolation and shifting from traditional "least privilege" to "least agency". By implementing hard cryptographic barriers, automated incident response, and continuous behavioral monitoring, organizations can effectively contain an attacker's blast radius and operate securely even when a breach inevitably occurs. Claude Zero Trust PDF Sponsors https://cisomarketplace.services/engagements/claude-cybersecurity-consulting https://cisomarketplace.services/ai-services https://cisomarketplace.services/program
-
464
The Dark Side of the Pitch: Securing the 2026 World Cup
The 2026 FIFA World Cup presents a massive global stage, but its unmatched visibility is already attracting a complex web of physical, digital, and geopolitical security threats across the US, Mexico, and Canada. In this episode, we break down how host nations are preparing for vastly different physical risks, ranging from transnational organized crime in Mexico to violent extremists targeting fan zones during the US 250th Independence Day celebrations. We also dive into the digital battleground, exploring how cybercriminals are using artificial intelligence to scale ticketing fraud, and how state-sponsored threat groups from Russia, China, and Iran are exploiting the tournament for intelligence gathering and disruptive cyberattacks. https://www.recordedfuture.com/research/2026-fifa-world-cup-threats https://www.recordedfuture.com/blog/2026-fifa-world-cup-cyber-physical-threats-security-guide Sponsors www.breached.company www.myprivacy.blog
-
463
The Tale of Two Claudes: Unpacking Fable 5 and Mythos 5
In this episode, we dive into Anthropic's dual-release of Claude Fable 5 and Mythos 5, two highly capable AI models built from the exact same architecture but designed for vastly different worlds. We explore how Fable 5 protects the general public with novel cyber and biological fallbacks, alongside invisible safeguards that quietly thwart competing frontier AI development. Finally, we unpack the raw, unrestricted power of Mythos 5, detailing its exclusive use by vetted cyberdefenders and researchers through Project Glasswing to secure critical infrastructure. https://www.anthropic.com/news/claude-fable-5-mythos-5 System Card: https://www-cdn.anthropic.com/d00db56fa754a1b115b6dd7cb2e3c342ee809620.pdf Sponsor: https://cisomarketplace.services/program https://cisomarketplace.services/ai-services https://cisomarketplace.services/engagements/claude-cybersecurity-consulting
-
462
Continuous Defense: The AI Security Department for the Mid-Market
In a world where software ships daily and attackers automate their methods, traditional point-in-time security assessments like annual pentests leave mid-market organizations blind for most of the year. This episode explores the transition to a continuous, AI-augmented security model built on six interconnected pillars—ranging from automated compliance and incident response to a self-healing DevSecOps pipeline. Discover how human operators maintain absolute control over the entire ecosystem through a centralized "Operator Seat," ensuring that while security is highly automated, it is never unattended. https://cisomarketplace.services/program https://cisomarketplace.services/ai-services
-
461
Zero Theater Sourcing: The Hidden Math of Cyber Procurement
This podcast explores how the CISO Marketplace streamlines vendor sourcing for security leaders by eliminating repetitive "discovery theater". It dives into how organizations can use ten free total cost of ownership (TCO) and sizing tools to uncover hidden technology costs, such as compounding carrier waste, unbudgeted cloud egress fees, and the true staffing requirements for a 24/7 SOC. Listeners will also learn how leveraging vendor-agnostic, CISSP-credentialed engineers can help them translate their exact needs into actionable RFP specifications and negotiate better contracts. https://sourcing.cisomarketplace.com/tools/sase-readiness https://sourcing.cisomarketplace.com/tools/ucaas-tco https://sourcing.cisomarketplace.com/tools/firewall-sizing https://sourcing.cisomarketplace.com/tools/sdwan-vs-mpls https://sourcing.cisomarketplace.com/tools/soc-build-vs-buy https://sourcing.cisomarketplace.com/tools/endpoint-planner https://sourcing.cisomarketplace.com/tools/cloud-egress-cost https://sourcing.cisomarketplace.com/tools/mobility-audit https://sourcing.cisomarketplace.com/tools/iot-risk-surface https://sourcing.cisomarketplace.com/tools/iam-zero-trust-tco
-
460
Navigating the 2026 AI Divide: Voluntary Frameworks and Binding Laws
The June 2026 U.S. executive order establishes a voluntary pre-release review framework and classified NSA benchmarks to govern the advanced cyber capabilities of frontier AI models. While the federal government pushes an innovation-first agenda with no mandatory licensing or pre-clearance, AI developers face a starkly different reality of binding penalties from the EU AI Act and emerging state laws like Illinois SB 315. This episode explores how enterprise compliance teams must simultaneously navigate these conflicting regulatory tracks and the strategic risks of sharing advanced models during the government's 30-day early access window. https://compliancehub.wiki/trump-ai-executive-order-frontier-model-cybersecurity-voluntary-framework-2026 https://myprivacy.blog/trump-ai-executive-order-frontier-model-security Sponsors: www.compliancehub.wiki www.myprivacy.blog
-
459
Architecting the Digital Frontline: The U.S. Cyber Force Blueprint
The United States faces an unprecedented range of sophisticated cyber threats, highlighting the urgent need for a dedicated military branch to uniquely organize, train, and equip personnel for the digital domain. This episode explores the CSIS Commission's comprehensive plan for an independent U.S. Cyber Force, detailing its proposed structure of 30,000 personnel, reliance on expert warrant officers rather than an enlisted cadre, and the creation of a specialized Cyber National Guard. Listeners will discover how this proposed service aims to revolutionize military recruitment by prioritizing elite technical specialization and securing the nation's critical infrastructure against rapidly evolving adversaries. https://www.csis.org/analysis/csis-commission-us-cyber-force-generation Sponsors www.cisomarketplace.com www.securitycareers.help
-
458
Governing the Invisible Workforce: The AI Agent Identity Crisis
Non-human identities now vastly outnumber human users, with recent estimates showing up to an 82-to-1 disparity in enterprise environments. The rapid adoption of autonomous AI agents amplifies this crisis, as these agents utilize compound identities and inherited "invisible browser" sessions to operate at machine speed, easily bypassing traditional security controls. To secure this dynamic attack surface, organizations must abandon static, permanent secrets in favor of short-lived ephemeral credentials and advanced intent inference that evaluates the true purpose behind an agent's autonomous actions https://cisomarketplace.com/blog/non-human-identity-secrets-governance-at-scale-ciso https://cisomarketplace.com/blog/zero-trust-technical-implementation-segmentation-policy-engine-ciso https://cisomarketplace.com/blog/ai-agent-identity-market-landscape-2025-2026 Sponsors: www.vibehack.dev www.myprivacy.blog https://airiskassess.com
-
457
Securing the AI Frontier: Navigating MCP Vulnerabilities
The Model Context Protocol (MCP) is rapidly becoming the standard for AI-driven automation, yet its rapid adoption has significantly outpaced the development of its security model. This episode explores the inherent design vulnerabilities of MCP, such as unrestricted repository access, tool parameter injection, and remote code execution, which expose organizations to novel and systemic attack vectors. We also dive into practical defense strategies, detailing how security teams can safely implement MCP by enforcing strict trust boundaries, rigorous input validation, and comprehensive application sandboxing. https://cisomarketplace.com/blog/ai-agent-security-crisis-mcp-vulnerabilities https://cisomarketplace.com/blog/agent-skills-next-ai-attack-surface https://cisomarketplace.com/blog/ciso-guide-securing-ai-agents https://cisomarketplace.com/blog/soul-engineering-identity-layer-attacks-on-ai-agents NSA PDF: Sponsors: www.vibehack.dev www.cisomarketplace.com
-
456
The 2026 DBIR Breakdown: Shadow AI, Pretexting, and the Rise of Vulnerabilities
The 2026 Data Breach Investigations Report reveals a rapidly shifting threat landscape where the exploitation of vulnerabilities has officially overtaken credential abuse as the top initial access vector. Alongside this shift, defenders are battling the explosion of "Shadow AI" data leaks and sophisticated, synchronous "pretexting" attacks that bypass traditional email-centric security training. Despite these advanced AI-driven threats, the report emphasizes that surviving the modern cyber battlefield requires a refinement of cybersecurity fundamentals—like patch management and access control—rather than a complete revolution. https://cisomarketplace.com/blog/verizon-dbir-2026-ciso-guide-vulnerability-exploitation-credential-theft 2026 Verizon DBIR Sponsors: www.breached.company www.cisomarketplace.com
-
455
The 2026 Digital Rulebook: Navigating AI, Privacy, and Cyber Convergence
In 2026, global organizations face a shifting regulatory landscape defined by the EU's Digital Omnibus package and the proposed SECURE Data Act in the United States. This episode explores how compliance leaders can adapt to delayed EU AI Act deadlines, navigate new data subject rights, and operationalize AI governance using standards like ISO 42001 and NIST. We also dive into the technical realities of continuous SOC 2 monitoring and the urgent transition to post-quantum cryptography to defend against "Harvest Now, Decrypt Later" attacks. https://compliance.airiskassess.com https://airiskassess.com Sponsor: www.compliancehub.wiki www.cisomarketplace.com
-
454
The Digital Identity Divide: Trust in 2026
The global landscape of identity is shifting rapidly in 2026, driven by the expanding rollout of mobile driver's licenses (mDLs) in the United States and the looming European Digital Identity (EUDI) Wallet mandate under eIDAS 2.0. This transition towards digital public infrastructure faces unprecedented cybersecurity challenges, primarily fueled by a 900% surge in AI-generated deepfakes and the rise of autonomous AI fraud agents. To combat these emerging threats, governments and organizations are racing to implement multi-modal liveness detection, privacy-preserving digital credentials, and robust "Know Your Agent" (KYA) frameworks. https://biometric.myprivacy.blog https://pii.compliancehub.wiki Sponsors: https://scamwatchhq.com https://cryptoimpacthub.com
-
453
The Global Privacy Horizon: AI Governance and Data Security in 2026
Welcome to a deep dive into the monumental shifts in data security, artificial intelligence governance, and global privacy regulations defining the corporate landscape in 2026. In this episode, we explore the intersection of aggressive new enforcement frameworks, such as the EU AI Act and the federal TAKE IT DOWN Act, alongside the profound impacts of sweeping children's online safety mandates. We also break down how Privacy-Enhancing Technologies (PETs) and decentralized identity solutions are helping organizations navigate an era of complex data breaches and strict operational accountability. https://compliancehub.wiki/take-it-down-act-ftc-enforcement-deepfake-platform-compliance-2026 https://compliancehub.wiki/eu-ai-act-omnibus-high-risk-deadline-extension-compliance-2026 Sponsors: https://biometric.myprivacy.blog https://childrenprivacylaws.com https://pii.compliancehub.wiki https://privacyrights.compliancehub.wiki
-
452
The Privacy Paradox: Control, Fatigue, and the Future of Our Data
Over half of New Zealanders are now deeply concerned about their individual privacy, driven largely by anxieties over children's digital safety and the use of artificial intelligence in decision-making. While an overwhelming majority demand more control over how their personal information is used, nearly half of the population is experiencing "privacy fatigue," feeling that protecting their data simply takes too much effort. Against a backdrop of low trust in government data handling—a sentiment especially pronounced among Māori respondents—the public is strongly backing tougher laws and large fines to hold organizations accountable. Sponsor www.compliancehub.wiki www.myprivacy.blog
-
451
Shadows Over Security: Inside the CSIS 2025 Public Report
Delve into the complex and evolving national security challenges facing Canada in 2025, as outlined by the Canadian Security Intelligence Service (CSIS). This episode explores the shadowy world of foreign interference, transnational repression, and the alarming rise of youth radicalization within violent extremist movements. Join us as we unpack the critical threats targeting Canada's democratic institutions, cutting-edge tech startups, and the increasingly contested Arctic region. Read the report: https://www.canada.ca/content/dam/csis-scrs/images/2025/public-report/Public%20Report_EN_2025_DIGITAL.pdf Sponsors: www.compliancehub.wiki www.myprivacy.blog
-
450
Securing the AI Supply Chain: The G7 SBOM Guidelines
In this podcast, we explore the groundbreaking guidelines set by the G7 Cybersecurity Working Group for creating a Software Bill of Materials (SBOM) for Artificial Intelligence. Our experts break down the seven critical information clusters—including metadata, models, datasets, and security properties—that serve as an essential "ingredient list" for AI systems. Tune in to discover how these foundational recommendations aim to boost transparency, manage vulnerabilities, and secure the global AI supply chain. Read G7 framework for Ai Software Bill of Materials SBOM: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/SBOM-for-AI_minimum-elements.html Sponsors: www.compliancehub.wiki https://airiskassess.com
-
449
The Dual-Use Dilemma: OpenAI Daybreak vs. Project Glasswing
In this episode, we explore how frontier AI models like OpenAI's GPT-5.5-Cyber and Anthropic's Claude Mythos are fundamentally shifting the landscape of cybersecurity by operating at machine speed. We dive deep into the dual-use reality of these highly capable tools, analyzing how they dramatically compress the vulnerability discovery-to-remediation pipeline while simultaneously introducing new offensive risks. Finally, we examine the competing governance frameworks—OpenAI's scalable Trusted Access for Cyber (TAC) and Anthropic's heavily restricted Project Glasswing coalition—to help security leaders understand the strategic implications for their enterprises. https://cisomarketplace.services/ai-services https://cisomarketplace.services/engagements/claude-cybersecurity-consulting https://cisomarketplace.services/engagements/openai-cybersecurity-consulting Sponsors www.cisomarketplace.com www.cyberadx.network August 5th 2026 - DEFCON / Blackhat / Bsides LV week https://ciso.poker
-
448
The 2026 Cyber Compliance Collision: AI, Quantum, and Global Mandates
In 2026, organizations face an unprecedented convergence of global cybersecurity regulations and rapid technological shifts that are creating a massive "compliance stack". This episode dives into sweeping new mandates, including the EU's Cyber Resilience Act and NIS 2 Directive, the U.S. transition to Post-Quantum Cryptography, and emerging global AI governance frameworks. We explore how CISOs can navigate tightening budgets and strict reporting deadlines while defending against automated AI attacks and the looming "harvest now, decrypt later" quantum threat. https://risk.quantumsecurity.ai Sponsors: https://compliancehub.wiki https://cisomarketplace.com
-
447
The EdTech Supply Chain Collapse: Inside the PowerSchool and Canvas Breaches
Between 2024 and 2026, the educational technology sector suffered a catastrophic supply chain collapse as hackers compromised roughly 350 million records through major platforms like PowerSchool and Canvas. By exploiting weak trust boundaries in shared multi-tenant architectures, threat actors such as the ShinyHunters group moved beyond targeting individual schools to attacking the centralized vendors that thousands of institutions rely on. As a result, schools are left bearing the intense legal and regulatory burdens of notifying their communities, while criminals weaponize both structured identity data and private behavioral context for long-term fraud and extortion. https://breached.company/san-diego-community-college-district-cyberattack-2026 https://breached.company/instructure-canvas-shinyhunters-275-million-students-breach-2026 Sponsors: www.myprivacy.blog www.breached.company www.compliancehub.wiki
-
446
Building the Human Resilience Infrastructure
This podcast explores the profound psychological, economic, and social shifts triggered by the rapid advancement of artificial intelligence, including the impending "work quake" that will radically restructure the labor market. Drawing on insights from hundreds of global experts, the discussion dives into emerging survival frameworks like the "Me:chine" identity and the critical need to develop "existential literacy" as a psychological immune system against algorithmic manipulation. Ultimately, listeners will discover actionable strategies for protecting human agency, nurturing genuine face-to-face connections, and restructuring our institutions to ensure humanity thrives alongside intelligent machines. Sponsors: www.cisomarketplace.com www.myprivacy.blog
-
445
Zero Trust in OT: Securing the Physical World
Operational Technology (OT) interacts directly with the physical world, meaning that cyber attacks can have immediate, devastating real-world safety and environmental consequence. Standard IT security models fall short in OT environments due to decades-old legacy systems, insecure protocols, and strict requirements for continuous availability. This episode explores how organizations can practically adapt modern Zero Trust principles to OT, covering critical strategies like network microsegmentation, compensating controls, and secure remote access without disrupting mission-critical operations. https://zerotrustciso.com Sponsor www.cisomarketplace.com www.cisomarketplace.services
-
444
Autonomous Defenses: Securing Agentic AI
As agentic AI systems increasingly automate complex tasks and operate with unprecedented autonomy, they introduce new and unpredictable cyber security risks. This podcast explores the unique vulnerabilities of these interconnected systems, ranging from privilege scope creep and deceptive behaviors to structural and accountability challenges. Tune in to discover actionable best practices for designing, developing, deploying, and operating secure AI agents to protect your organization's critical infrastructure. Sponsor www.cisomarketplace.com www.airiskassess.com
-
443
Autonomic Resilience: Navigating the Hidden Fault Lines
In the era of the autonomous enterprise, digital systems are evolving faster than traditional governance can keep up, exposing dangerous hidden vulnerabilities across the modern business. This podcast dives into the 2026 Cloudflare Security Signals Report to unpack the six critical fault lines threatening organizations, from shadow supply chains and legacy technical debt to ungoverned AI agents. Join us as we discuss how enterprise leaders can move beyond a reactive "absorb and recover" mindset to deliberately engineer systems that sense, adapt, and self-correct under machine-speed stress The 2026 Cloudflare Security Signals Report -> https://www.cloudflare.com/lp/security-signals-report/2026/ Sponsors: www.cisomarketplace.com www.breached.company Grab your seat -> https://ciso.poker/apply
-
442
CISO.POKER — Where Security Leadership Meets the Felt
Join us for the first public announcement of CISO.POKER's inaugural tournament at Hacker Summer Camp 2026, an exclusive, zero buy-in Texas Hold'em event designed for 80 senior security executives on the Las Vegas Strip. This episode unpacks how we are replacing the traditional "pay-to-play" vendor pitch with genuine networking, offering an Enterprise security prize pack, Knockout Bounties, and capturing real-time industry intelligence through our anonymous FeltIQ platform. We also dive into our built-in Coalition Giving model, demonstrating how three hours at the poker table can seamlessly fund critical cybersecurity nonprofits while you build authentic industry relationships. https://ciso.poker/sponsor https://ciso.poker/give Visit the event: https://ciso.poker/apply Sponsor: https://cyberadx.network
-
441
Digital Trust 2026: Identity, Privacy, and the New Regulatory Frontier
In 2026, the global digital landscape is undergoing a massive transformation as rapid technological advancement collides with complex new regulatory frameworks. This episode explores how African nations are pioneering digital public ecosystems for economic integration, while the United States navigates a strict new patchwork of state privacy laws designed to protect minors and consumer data. Join us as we dissect the delicate balance between embracing innovations like AI-powered smart cities and securing fundamental digital rights in an increasingly connected world. https://digitaltwin.compliancehub.wiki https://childrenprivacylaws.com https://biometric.myprivacy.blog https://privacyrights.compliancehub.wiki Sponsors: www.myprivacy.blog www.scamwatchhq.com
-
440
The 2026 Compliance Countdown: Navigating the New Era of Global Privacy and Cyber Regulations
From the expansion of U.S. state privacy laws and the HIPAA Security Rule overhaul to the enforcement of the EU AI Act, DORA, and India's DPDP Act, 2026 marks a definitive turning point for global regulatory compliance. We explore how these emerging frameworks demand that businesses move beyond static paperwork to demonstrate true operational resilience, continuous monitoring, and boardroom accountability. Tune in to discover the proactive steps your organization must take to avoid massive financial penalties and build a cohesive, evidence-based compliance architecture before it is too late. Sponsor: www.compliancehub.wiki www.cisomarketplace.com
-
439
The Digital Siege: Supply Chain Poisoning and the New Era of Cyber Warfare
In April 2026, the cybersecurity landscape experienced a seismic shift as geopolitical tensions and industrialized fraud collided to create unprecedented enterprise risks. This episode dives into the most critical incidents of the month, including TeamPCP's cascading supply chain compromises, Iran-backed wiper attacks on corporate infrastructure, and the exploitation of third-party platforms by groups like ShinyHunters. Join us as we unpack how these sophisticated threats are redefining the "new normal" for defenders and explore the massive global law enforcement operations fighting back. Sponsors: www.cisomarketplace.com www.breached.company
-
438
The Mythos Paradox: Leaks, Lawsuits, and the AI IPO of the Century
Anthropic recently unveiled Claude Mythos, an unreleased frontier AI model with unprecedented cybersecurity capabilities that led the company to restrict its access exclusively to defensive partners via Project Glasswing. This revelation coincided with a chaotic week of accidental source code leaks and an unprecedented legal battle against the Pentagon, which blacklisted Anthropic as a "supply chain risk" over the company's refusal to drop safety guardrails. Together, these dramatic events have fueled a massive hype narrative ahead of Anthropic's planned October 2026 IPO, where the company is targeting a valuation of up to $500 billion. https://podcast.cisomarketplace.com/e/the-mythos-dilemma-ai-zero-days-and-project-glasswing https://cisomarketplace.com/blog/project-glasswing-claude-mythos-cybersecurity https://cisomarketplace.com/blog/claude-mythos-leak-cybersecurity-stocks-crash-2026 Sponsors: www.breached.company www.compliancehub.wiki
-
437
The 40-Minute Collapse: How Fake Compliance Broke the AI Supply Chain
In March 2026, a 40-minute supply chain attack on the open-source library LiteLLM allowed hackers to steal four terabytes of highly sensitive data from Mercor, a $10 billion AI training startup. The breach exposed a fragile trust infrastructure across the tech industry, revealing that LiteLLM's security certifications were fabricated by Delve Technologies, a compliance vendor that systematically rubber-stamped fake audits. As major AI labs like Meta indefinitely pause their contracts, Mercor now faces a wave of class-action lawsuits alleging that its mandatory, invasive contractor surveillance practices funneled unauthorized third-party trade secrets and personal data straight to cybercriminals. https://compliancehub.wiki/mercor-litellm-delve-class-action-supply-chain-compliance-fraud/ https://compliancehub.wiki/five-lawsuits-mercor-data-breach-litigation-breakdown/ Sponsors www.breached.company www.compliancehub.wiki
-
436
The Mythos Dilemma: AI, Zero-Days, and Project Glasswing
Anthropic's latest frontier model, Claude Mythos Preview, has demonstrated an unprecedented ability to autonomously discover and exploit zero-day vulnerabilities in critical software. Recognizing the extreme dual-use risks of these capabilities falling into the wrong hands, Anthropic has made the unprecedented decision to withhold the model from general public release. Instead, the model is being deployed through Project Glasswing, a collaborative initiative with major tech industry partners aimed at using this powerful AI exclusively to secure the world's digital infrastructure. https://cisomarketplace.com/blog/project-glasswing-claude-mythos-cybersecurity https://cisomarketplace.com/blog/claude-mythos-leak-cybersecurity-stocks-crash-2026 https://www.anthropic.com/glasswing Sponsors: www.cisomarketplace.com
-
435
Decoding CCPA: Navigating Cybersecurity Audits and Existing Frameworks
Dive into the nuances of California's new CCPA cybersecurity audit requirements and discover how they redefine the standard for "reasonable security". We explore how businesses can strategically leverage existing NIST, ISO, or CIS assessments as a foundation, while identifying the critical scope mismatches they must "top off" to ensure compliance. Tune in for a practical, four-step roadmap to navigate CalPrivacy's 18 evaluation components and prepare your organization's data protection strategy for the next wave of regulatory scrutiny. Sponsors: www.compliancehub.wiki www.cisomarketplace.com
-
434
Encrypted Extortion: Inside Latin America's Cybercrime Boom
Dive into the rapidly evolving cyber threat landscape of Latin America and the Caribbean, where financially motivated threat actors are increasingly exploiting rapid digital adoption to target the region's largest economies. We explore how cybercriminals and hacktivist collectives like FiveFamilies are utilizing encrypted platforms like Telegram and WhatsApp to distribute banking trojans, deploy double-extortion ransomware against critical industries, and launch highly convincing AI-driven social engineering attacks. Join us as we unpack the tactics of these digital adversaries and discuss the urgent need for modernized infrastructure and public-private collaboration to secure the LAC region's digital future. Sponsors: www.myprivacy.blog www.breached.company
-
433
Growing Up Digital: Safeguarding Youth in the EU
Explore the evolving landscape of youth digital protection across the European Union, where groundbreaking laws like the GDPR and the Digital Services Act (DSA) are being deployed to shield minors from data exploitation and harmful content. As emerging innovations like immersive virtual environments, neuromarketing, and AI-generated deepfakes introduce unprecedented risks to children's mental privacy and cognitive development, the battle for digital safety is becoming increasingly complex. Join us as we examine how local and regional authorities are stepping up to bridge the gap between high-level regulations and frontline realities, transforming overarching policies into tangible, community-based safeguards for families and schools. Sponsors: www.myprivacy.blog www.compliancehub.wiki
-
432
Panic, Privacy, and Protecting Youth: Unpacking Child Online Safety Laws
This podcast dives into the current wave of Child Online Safety Legislation (COSL), such as the Kids Online Safety Act (KOSA), to unpack the political and societal forces driving these bipartisan bills. We critically examine the prevailing narrative that social media is the primary cause of the youth mental health crisis, exploring how "moral panics" over technology often ignore complex social realities. Furthermore, we discuss the potential unintended consequences of these legislative efforts, including severe threats to data privacy, free expression, and the well-being of marginalized youth through mandated age verification and expanded parental surveillance. Sponsors: www.myprivacy.blog www.cisomarketplace.com
-
431
The Illusion of Trust: Fake Compliance and the LiteLLM Hack
This episode dives into the massive compliance fraud orchestrated by Delve, a Y Combinator-backed startup that generated hundreds of identical, fabricated SOC 2 reports using rubber-stamping certification mills. We explore how this "compliance theater" collided with a real-world supply chain attack when LiteLLM, a company boasting Delve-generated certifications, was breached through a compromised vulnerability scanner called Trivy. Ultimately, we unpack the devastating consequences of prioritizing automated compliance badges over actual security controls, and what this structural failure means for enterprise vendor risk management in 2026. https://compliancehub.wiki/litellm-delve-soc2-trust-chain-compliance-failure-2026 https://breached.company/litellm-supply-chain-attack-teampcp-trivy-pypi-2026 https://compliancehub.wiki/delve-compliance-startup-fake-soc2-audit-scandal https://cisomarketplace.com/blog/auditor-vs-assessor-compliance-trust-2026 Sponsors www.compliancehub.wiki www.cisomarketplace.com www.breached.company
-
430
Il CISO del 2026: Architetti della Fiducia Digitale
Il ruolo del Chief Information Security Officer si è radicalmente trasformato da una funzione puramente informatica a una posizione strategica a livello esecutivo, focalizzata sul rischio digitale dell'intera azienda. Spinti dalla rapida adozione dell'intelligenza artificiale agentica, dall'espansione delle identità non umane e dalle nuove e severe normative globali come la Direttiva NIS2 dell'UE, i CISO sono ora essenziali per garantire la resilienza operativa e proteggere la continuità aziendale. Questo podcast esplora come i moderni leader della sicurezza stiano colmando il divario tra la tecnologia e il consiglio di amministrazione per combattere le minacce alla velocità delle macchine e navigare in un panorama normativo sempre più complesso. English: https://www.podbean.com/ew/pb-r9v3x-1a73307 Sponsors: www.cisomarketplace.com www.breached.company
-
429
Weaponizing Trust: The TeamPCP Campaign and the Age of Cascading Failure
The cyber threat landscape is experiencing a massive paradigm shift, as adversaries move away from isolated network breaches to industrialize the compromise of global digital supply chains. This episode breaks down the unprecedented March 2026 TeamPCP campaign, exploring how attackers weaponized the trusted Trivy vulnerability scanner, compromised the widely used LiteLLM AI package, and unleashed the self-propagating Shai-Hulud worm across the npm ecosystem. We also examine how the growing use of artificial intelligence by threat actors, the exploitation of unmonitored edge devices, and the rise of destructive wiper attacks against critical infrastructure are forcing organizations to adopt zero-trust models and continuous resilience strategies. https://breached.company/litellm-supply-chain-attack-teampcp-trivy-pypi-2026 https://compliancehub.wiki/delve-compliance-startup-fake-soc2-audit-scandal Sponsors: www.cisomarketplace.com www.breached.company
-
428
CISO 2026: Architekci Cyfrowego Zaufania
Rola dyrektora ds. bezpieczeństwa informacji (CISO) uległa fundamentalnej transformacji z funkcji operacyjnej IT w strategiczne stanowisko na szczeblu kierowniczym, koncentrujące się na ryzyku cyfrowym w całej organizacji. W związku z szybką adopcją agentycznej sztucznej inteligencji, rosnącą liczbą tożsamości nieludzkich oraz surowymi nowymi globalnymi regulacjami, takimi jak unijna dyrektywa NIS2, dyrektorzy CISO są teraz kluczowi dla zapewnienia odporności operacyjnej i ochrony ciągłości biznesowej. Ten podcast analizuje, w jaki sposób współcześni liderzy ds. bezpieczeństwa zasypują przepaść między technologią a zarządem, aby zwalczać zagrożenia działające z prędkością maszyn i poruszać się w coraz bardziej złożonym krajobrazie regulacyjnym. English Version: https://www.podbean.com/ew/pb-r9v3x-1a73307 Sponsors: www.cisomarketplace.com www.breached.company
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
CISO Marketplace is a dedicated platform providing cybersecurity professionals with expert resources, tools, and insights to protect their organizations. From policy templates to industry updates, we empower CISOs with the knowledge needed to navigate the evolving threat landscape. Shop @ https://www.cisomarketplace.com || News @ https://threatwatch.news || Podcast @ https://cisoinsights.show
HOSTED BY
CISO Marketplace
CATEGORIES
Loading similar podcasts...