The Cyber Resilience Brief: A SafeBreach Podcast

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

25 min · 15. juli 2026
Billede af episoden Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

Beskrivelse

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.

Kommentarer

0

Vær den første til at kommentere

Tilmeld dig nu og bliv en del af The Cyber Resilience Brief: A SafeBreach Podcast-fællesskabet!

Kom i gang

1 måned kun 9 kr.

Derefter 99 kr. / måned · Opsig når som helst

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

Alle episoder

69 episoder

Billede af episoden Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now. Read more on our blog: https://www.safebreach.com/blog/teampcp-supply-chain-attacks-fbi-flash-alert-20260702-01-safebreach-coverage/ [https://www.safebreach.com/blog/teampcp-supply-chain-attacks-fbi-flash-alert-20260702-01-safebreach-coverage/] #cybersecurity #infosec #CISO #supplychainsecurity #TeamPCP #CICD #BAS #SafeBreach

5. juli 202617 min
Billede af episoden Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning. Read the full Five Eyes statement on the CISA website: https://www.cisa.gov/news-events/news/five-eyes-cyber-security-agencies-statement [https://www.cisa.gov/news-events/news/five-eyes-cyber-security-agencies-statement] #cybersecurity #infosec #CISO #FiveEyes #CISA #NSA #GCHQ #adversarialexposurevalidation #cyberresilience #SafeBreach

1. juli 202618 min