Nudge SecurityHuge thanks to our sponsor, Nudge Security. Here's a question that might make you sweat. How many AI agents are running in your org right now? Not sure? You're not alone. But Nudge Security has good news. Nudge Security now includes AI agent discovery in addition to day one discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries. That is n u d g e
Cybersecurity podcast ads
13 ads from 13 brands on Cybersecurity podcasts.
| Play | Brand | Podcast |
|---|---|---|
EasyOptOutsSpeaking of tools, I wanted to mention the sponsor of this podcast, EasyOptOuts. Now, this isn't just your regular sponsor who just pays good money and ends up, um, on a podcast. Like, we have had EasyOptOuts on here for many years. They're just run by a couple guys. They've been shown by Consumer Reports to be one of the most effective, tied with Optery. But unlike Optery, their plans are $20 a year. There's no, like, tiered subscription model. It's meant to be extremely accessible to people, which is how I think it should be. It's already asking a lot for someone to have to pay to be removed from these sites that they never opted into using in the first place. But EasyOptOuts will opt you out of all of these random people-searching websites on your behalf. You can upload as much or as little information as you want to make it easier for them to find your information, and they work all around the US. They have business plans, so you can also get some discounts at scale. Go visit EasyOptOuts and get started for $20 a year down in the description. Again, I don't think they can make this a better value. They are one of the most effective services out there. Thank you, EasyOptOuts, as always, for sponsoring us, and now back to OpenAI's rogue agents. | ||
KnowBe4Huge thanks to our sponsor, KnowBe4. Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's face, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native security awareness training fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at knowbe4.com. That is k n o w b e the number four dot com. | ||
ThreatDownHuge thanks to our sponsor, ThreatDown. SMBs face enterprise-level AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented legacy tools with proactive 24/7 MDR that scales with your business. ThreatDown, enterprise-grade defense built for businesses like yours. | ||
addy.ioQuick one, go into your email inbox right now and type in unsubscribe. However, many hundreds of results you just got, that's how many companies have your real email address. So the moment any of them gets breached or quietly sells you out, it's your real inbox eating the spam, the trackers, and the hackers forever. addy.io is designed to fix this entire problem. The whole idea is you stop giving out your real email address and instead hand every single site its own alias that just forwards to the inbox you already have. Think like Apple Hide My Email, except it's open source and you can bring it to any email inbox. And my favorite part is that once you get all your accounts using an email alias, you can always swap the email provider behind the scenes, like moving from Gmail to a private email provider without needing to update every single account's email. And it's possible because you're really just putting Addy in front of your email. It's like your email bodyguard. This also offers a lot of protection. If a site starts to spam you, or you show up in a data breach, or you realize they sold your data because that one specific alias suddenly started getting junk, you just deactivate the alias. It's fully open source, so you're not trusting a black box. And you can even self-host the entire thing if you're that kind of person, which I know many of you are. It's on F-Droid, there are browser extensions and mobile apps so you can spin up a fresh alias right as you're signing up for something. And if you want to go all in, you can even use it with your own custom alias. It's free to start and they have a crazy generous free plan to get started. Visit addy.io or just check them out down in the description. And thank you guys for sponsoring us. Now back to the video. | ||
ProwlerThis week's show is brought to you by Prowler. Uh and of course Prowler does uh you know cloud security checks, cloud security remediation, uh and it's open source. It's based on open source project, but there is of course a paid version and uh Prowler's founder Toni de la Fuente will join us later in this week's sponsor interview to talk about a few things. Some really interesting AI stuff actually. Uh one interesting thing is that uh Prowler's customers now are starting to use their own dashboards that they're creating from prompts. Uh Toni actually shared one of the prompts with me. It was on GitHub and then he's like I can you know he just said well I'll just set it public. So I've linked through to it in this week's show notes, but you can build a dashboard now from a prompt which is just amazing. Kind of annoying to all of those people who wasted all of those dev hours building dashboards pre-AI, but anyway. Um so yeah we talked to him about that and just about how people are using AI to interact with tools uh like Prowler. Uh interesting chat coming up later. | ||
PindropHuge thanks to our sponsor, Pindrop. A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction, this happened. Deepfake video, AI voice, completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. So, go to pindrop.com, that is p i n d r o p .com, and start verifying. | ||
CohesityOur show today brought to you by Cohesity. This is really important stuff. If you listen to this show, you know how sadly prevalent cyber attacks and breaches are. Uh, but there's some advice here from a company that helps you with resilience. This is Cohesity and it's I think uh, boy, if nothing else from the show, this might be the most important piece of advice. After a major cyber attack, recovering everything all at once, which is your natural impulse, isn't always the fastest path back to business. It's not always the right thing to do. Let me let me explain. Once you've been breached, once you've had a cyber attack, once you're down from ransomware, the immediate priority shouldn't be let's get back up and running. It should be restoring a trusted operating core. All right. Just the minimum systems, data and processes that you need to keep critical operations running. Cohesity has a name for it. They call it the MVC, the minimum viable company. And they will help you determine that to prepare a framework for this. They will help you define it, protect it, and recover the things that matter the most first. This is really valuable advice. MVC, it helps organizations identify those are the essential applications, the essential data, the people, the processes required so that you can serve customers, you can maintain communications, protect revenue, meet those critical obligations. And we've seen in the real world examples where companies, you know, struggle to get it all up and running again and they fail. The MVC from Cohesity provides a clear recovery target so that your team can focus resources where they're going to have the greatest business impact. Do you know what that would be today? You might have some idea, but this makes it very explicit. And and when you restore this trusted operating core first, you don't have to, you know, be in a situation where you're just completely out of touch with customers. You can reduce your downtime. You can accelerate the recovery. Everything will happen faster after that. Most importantly, you can maintain continuity while your broader restoration efforts continue because cyber resilience isn't just about getting the systems back online. It's about keeping the business operating when disruption strikes. Learn | ||
DoppelThis portion of Security Now brought to you by Doppel. AI has made social engineering attacks more convincing than ever. My Doppels, my doubles, my doppelgangers sound and look just like me. And don't think they can't do it with you. It only took, I think it was 15 seconds of my voice to duplicate it. AI has made social engineering attacks more convincing than ever. From phishing emails that look like the real thing. You've seen those fake websites. But it gets even more sophisticated with deepfakes and impersonation. You saw maybe the story was six months ago about the CFO, the chief financial officer who wrote a big check because he thought he was on a Zoom call with the chairman of the board, the board of directors, the president of the company. He saw them. They were in a Zoom call. Except they were all deepfakes, but it fooled him. It's becoming harder and harder to tell what's real from what's designed to deceive. And that's why organizations need more than a collection of point solutions. You need a unified approach to stop these attacks before they reach your people. You need Doppel. Doppel is an AI-native social engineering defense platform. Doppel strengthens human risk management by training employees to recognize deception. It provides digital risk protection across every channel and delivers agentic email security that doesn't just score the inbox, but takes down the attacker infrastructure behind the message. You heard me right. They actually take it down. So, not only is that message blocked, but they can never send another one. Doppel protects against the entire social engineering attack chain. With one comprehensive platform, you get digital risk protection which detects threats across multiple channels, links alerts into a real-time threat graph. You can see what's going on. It's like radar for attacks. It uses AI-driven infrastructure disruption. AI, this is so cool. AI-driven infrastructure disruption to stop attacks at the source. And the insights. It has phishing simulations and security awareness training. So your employees are getting trained on what's happening right now. It strengthens your defenses through next-generation training and testing. Then they've got this great email security which inspects every message, traces it back when it says this is malicious to the attacker infrastructure behind it and helps take that infrastructure down so the campaign can't target your organization again. It does it all automatically. Doppel also offers best-in-class integrations and partnerships so you don't get rid of your existing stack. It works right alongside all the stuff you know, use, and trust. You're going to love Doppel. Join hundreds of companies already using Doppel to protect their brand and people from social engineering attacks. Doppel: outpacing what's next in social engineering. You can learn more at doppel.com. That's D-O-P-P-E-L.com. | ||
ThreatLockervery very fine controls to prevent AI applications and their users from receiving unnecessary administrative privileges while giving them the privileges they actually need. This is zero trust done right. But it's not just zero trust for endpoints. It's zero trust network access and zero trust cloud access. Those policies are vital nowadays to restrict resources to authorized users, approved devices, permitted applications. And the best thing about ThreatLocker, it works on Windows, Mac, Linux, everywhere you are. It provides the best US-based support engineer to engineer 24/7. That's why organizations like JetBlue trust ThreatLocker, Heathrow Airport, the Indianapolis Colts. The Port of Vancouver relies on ThreatLocker to keep the ships moving. Ask Jack Thompson. He's director of information security, risk, and compliance for the Indianapolis Colts. He said, quote, "With ThreatLocker, we have the ability to centralize disparate elements in the security stack." End quote. And with that centralization, you get observability. You can see what's going on and you can control it. ThreatLocker gets constant praise, constant industry awards. Uh, as an example, they were just recognized as a strong performer in the January 26 Gartner Peer Insights Voice of the Consumer for Endpoint Protection Platforms, ranked number one in application control by PeerSpot, winner of the best zero trust security solutions at the 2025 TIC Awards, and on and on and on. You can see it all at the website threatlocker.com/twit. Don't forget that part. AI governance requires more than just an acceptable use policy. ThreatLocker gives security teams the technical controls to define which AI tools are approved, who and what can access them, and how those tools are allowed to interact with business systems and data. If you're listening to this show and you're thinking, "What do I do to protect myself?" Visit threatlocker.com/twit to get a free 30-day trial and learn more about how ThreatLocker can help mitigate unknown threats and ensure compliance. That's threatlocker.com/twit. And if you're listening to this show and saying, "What do I do?" That's the first step. We thank him so much for supporting Security Now. Steve, | ||
TLPBLACKThis episode of the podcast is sponsored by TLP Black. For all your threat intelligence information needs, threat hunting needs, check out tlpblack.net. tlpblack.net. | ||
Material SecurityWe'll get back to the show floor in just a minute with Steve and the panel, but first let's talk about our sponsor for this episode of Security Now, Material, the cloud workspace security platform built for lean security teams. Managing security in the cloud workspace is hard. Phishing is far from the only way in, but today's email security stops at the perimeter and new attacks are hard to detect with siloed email data and identity security tools. Material protects the email and the files and the accounts that live in Google Workspace or Microsoft 365 because effective email security today needs to do more than just block phishing and other inbound attacks. It needs to provide visibility and defense across the workspace threat surface. Material ingests your settings, your contents, your logs. It gives you holistic visibility into threats and risks across the workspace along with the tools to automatically remediate them. Material delivers comprehensive workspace security by correlating signals and driving automated remediations across the environment. You get phishing protection, of course, and email security which combine advanced AI detections with threat research and user-reported automation. You get detection and protection of sensitive data across inboxes and shared files. And you get account threat detection and response with comprehensive control over access and authentication of people and third-party apps. Material empowers organizations to rapidly mature their ability to detect and stop breaches with step-up authentication for sensitive content, blast radius visualization for accounts, and the ability to detect and respond to threats and risk across the cloud workspace. Material enables organizations to scale their security, but you don't have to scale your team. Material drives operational efficiency with its simple API-based implementation and flexible, automated, and one-click remediations for email, file, and account issues. It includes an AI agent that automates user reporting triage and response. Material protects the entire workspace for the cost of email security with a simple and transparent pricing model. Secure your inbox and your entire cloud workspace without adding more toil to your day or costs to your balance sheet. See material.security to learn more or book a demo. That's material.security. We thank them so much for supporting Security Now. | ||
XBOWThis episode of Security Now brought to you by XBOW, X B O W. AI has changed the pace of everything from how software develops to how it gets attacked. We're seeing it here on the show floor. Engineering teams are moving faster than ever, creating more and more applications, but security just hasn't kept up. Pen testing is still one of the most trusted ways to understand real exploitable risk. But in an AI-driven world, it can become a bottleneck. Security teams are forced to choose between slowing down development to stay secure or moving fast and accepting gaps in coverage. XBOW eliminates that trade-off. X B O W, XBOW is an autonomous offensive security platform that runs continuous AI-driven pen testing, mirroring real-world attacks. XBOW doesn't just scan for vulnerabilities. It discovers exploits and validates them. So, you're only dealing with issues that actually matter. And that means dramatically fewer false positives and a clear view into real attack paths. With XBOW, tests run in hours, not weeks. You get complete visibility into how an attacker would move through your systems and the ability to uncover issues that traditional tools miss, including zero-days and novel attack paths. XBOW's results speak for themselves. Ask the application security lead at Seznam.cz. He says, quote, "Even right now, after 1 year, I don't know any other company that is at least close to XBOW in terms of agentic pen testing." The result is predictable cost, consistent quality, and stronger security without slowing down your engineers. XBOW helps security teams keep pace with and cover more apps more often with the resources they already have. Founded by the team behind Microsoft Copilot and already trusted by companies ranging from fast-growing startups to Fortune 500 enterprises, XBOW is quickly becoming a mission-critical layer in modern security stacks. Go to xbow.com to start a pentest today. That's XBOW, E X B O W, xbow.com. We thank them so much for supporting us at Black Hat. And now back to Security Now. |