Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now.

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational — the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS—an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments.

Ep. 64 - The Mythos Hype Index: What AI Really Did to the Zero-Day Curve

Every CISO is asking it: now that frontier models like Claude Mythos and ChatGPT 5.5 have real offensive cyber capability, are zero days surging? Host Tova Dvorin and SafeBreach offensive engineer Adrian Culley dig into the mid-2026 data — GTIG, Mandiant M-Trends, Rapid7, AISI — and find the curve moved in shape, not volume. Inside: the two AI "firsts" (Big Sleep and a 2FA-bypass exploit), why commercial spyware explains the rebound, the negative-seven-day time-to-exploit, and why defender deployment is the real bottleneck.

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning.

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational—the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now.

The FBI Just Issued an Alert on TeamPCP. Here's How They Get In

The FBI just issued a FLASH alert on TeamPCP — the group behind a wave of software supply chain attacks that compromised widely-used developer and security tools, harvesting cloud credentials, SSH keys, and Kubernetes secrets at scale. Tova Dvorin and Adrian Culley break down how TeamPCP operates with an APT's patience, and the open question the FBI alert doesn't answer: is a nation-state pulling the strings? Full breakdown on The Cyber Resilience Brief.

The Five Eyes Just Said AI Is Breaking Every Assumption in Your Security Program

The Five Eyes just put a number on something most security teams haven't priced in: AI is shrinking the gap between "vulnerability" and "actively exploited" faster than patch cycles can keep up. Adrian Culley and Tova Dvorin explain why CVSS scores alone can't tell you what's actually reachable in your environment — and why attack path validation is becoming the only way to know.