Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

The most helpful AI agent is the least secure one

The most pleasant agentic AI system is the least secure one. That's the trap Rob van der Veer, Chief AI Officer at Software Improvement Group, lays out clearly: the agent that never says "permission denied" is the agent everyone loves to use. It always works. So we open up all the privileges just to keep it that way. He says we should do the contrary.

Building trustworthy AI with Rob van der Veer [341]

Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.

LimaCharlie Cloud Security: CNAPP Walkthrough

A walkthrough of Cloud Security in LimaCharlie — CNAPP capability built into the SecOps Cloud Platform. Connect your cloud and SaaS providers (AWS, GCP, Azure, Okta, Google Workspace, GitHub, Cloudflare, Anthropic, and even other LimaCharlie orgs) and everything is normalized into a single security graph: identities, permissions, workloads, and data. The engine reasons over that graph to surface attack paths — evidence-backed chains an attacker could actually walk — instead of isolated checkbox findings.

LimaCharlie 101: EDR deployment, detection rules, and threat intelligence

This workshop will cover the basics of the LimaCharlie SecOps platform. You will learn how to deploy EDR agents, gather additional telemetry and write detection and response rules, and integrate threat intelligence and YARA rules to detect and mitigate threats. Key Learning Objectives: Endpoint Detection and Response (EDR) Agent Deployment and Management: Learn the best practices for deploying LimaCharlie EDR agents across diverse environments. Understand the various deployment methods, agent configurations, and how to effectively manage agent health and status at scale.

Is this the end of human-written code?

Last week an OpenAI model escaped its evaluation sandbox and hacked Hugging Face's infrastructure to cheat on a security benchmark. We recorded a special episode of AI Chat about it. Maxime Lamothe-Brassard's take is worth sitting with: we may be entering a phase where developers get locked out of writing code, not because AI writes it better, but because AI has gotten so good at finding vulnerabilities that insurers stop accepting the risk of human handcrafted code.

AI Chat: The Hugging Face / OpenAI breach - the attacker was the model [340]

AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode. One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.

AI is moving fast. Exploits are right behind.

Chris Luft and Matt Bromiley cover four stories in this week's Intel Chat that all point to the same trend: attackers are keeping pace with how fast AI tools are being built and deployed. They break down a chatbot pipeline vulnerability in Google Dialogflow CX, a phishing technique that hides malicious content until it renders in the browser, four newly exploited vulnerabilities added to CISA's KEV catalog, and an attack that exploits AI coding assistants' tendency to hallucinate fake repository names.

Could your own AI agents run a ransomware attack?

Ransomware is evolving well beyond locking systems, and agentic AI is introducing a category of security risk most organizations are not yet equipped to handle. On The Cybersecurity Defenders Podcast, Behnaz Karimi, Senior Cybersecurity Analyst at Accenture and independent ransomware researcher, walks through what that shift actually looks like. The full conversation includes.

AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]

AI Chat with Maxime Lamothe-Brassard and Chris Luft. A new segment on the podcast: AI news in cybersecurity that is less than 24 hours old, discussed while it is still hot. Joining Chris for these conversations is LimaCharlie founder and CEO Maxime Lamothe-Brassard. In this episode: Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.