Modern Cyber with Jeremy Snyder

Kenneth Ellington of Ellington Cybersecurity Academy

30 min · 16 de jun de 2026
Portada del episodio Kenneth Ellington of Ellington Cybersecurity Academy

Descripción

In this episode of Modern Cyber, Jeremy sits down with Kenneth Ellington, founder of Ellington Cyber Academy, to explore the rapidly evolving landscape of SIEM engineering, threat hunting, and automated incident response. As organizations transition from conceptual AI to deploying agentic AI in production environments, Kenneth shares his extensive hands-on expertise managing complex enterprise security operations across Splunk, Elastic, and Microsoft Sentinel architectures. The conversation dives deep into the realities of alert fatigue, explaining why security analysts remain overwhelmed by false positives and how proper data pipeline management is essential before any AI automation can be effectively introduced. Kenneth unpacks the historical shift from SIEMs acting as long-term historical audit records to highly optimized, real-time threat detection engines, while advocating for cost-effective security data lakes for extended threat hunting visibility. Then, the discussion tackles the nuances of implementing AI in highly regulated sectors like finance and healthcare, demystifying the difference between marketing buzzwords around SOAR platforms and genuinely actionable AI-assisted threat hunting workflows. Wrapping up, Kenneth shares raw insights into the harsh realities of breaking into the cybersecurity industry today, emphasizing the indispensable need for hard technical skills, strong soft skills, and resilient mental models for aspiring SOC analysts facing trial by fire. About Kenneth Kenneth Ellington is a Senior SIEM Engineer and cybersecurity entrepreneur, and the Founder of Ellington Cyber Academy (ECA), where he trains the next generation of detection engineers and threat hunters. He previously served as a Senior Consultant at EY, supporting enterprise security operations and SIEM engineering initiatives across complex environments. Kenneth specializes in detection engineering, threat hunting, and XDR architecture, with deep hands-on experience across Splunk, Elastic, and Sentinel ecosystems. He recently spoke at BSides St. Pete, sharing insights on real-world threat detection and building practical cyber talent pipelines. Episode Links * Ellington Cyber Academy: https://www.ellingtoncyberacademy.com/ [https://www.ellingtoncyberacademy.com/] * Kenneth Ellington on LinkedIn: https://www.linkedin.com/in/kenneth-ellington/ [https://www.linkedin.com/in/kenneth-ellington/]

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de Modern Cyber with Jeremy Snyder!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

117 episodios

episode This Week in AI Security - 18th June 2026 artwork

This Week in AI Security - 18th June 2026

In this episode, Jeremy explores the fallout of the first US government-mandated global model kill switch, an unprecedented action taken against Anthropic's new Fable model. We also examine CISA's radical new 3-day vulnerability remediation timeline and how autonomous threats are now weaponizing application monitoring software. Key Episode Highlights: * The Global Kill Switch: Just five days after launch, the US Department of Commerce invoked a sweeping export control directive against Anthropic's Claude Fable model after an Amazon-discovered jailbreak was flagged to national security officials. This action triggered a total global deactivation, limiting access exclusively to US citizens. * The "Lethal Trifecta" of Agent Hijacking: Toxic researchers define the critical conditions where AI agents become highly weaponizable: concurrent access to sensitive data, exposure to untrusted external content, and the ability to execute outbound actions. * Sentry "Agentjacking": Attackers are injecting malicious Markdown into standard Sentry error logs to bypass WAF and EDR tools, silently hijacking the AI agents developers deploy to automatically triage and fix code errors. * CISA BOD 2026-04: As the "Vulnpocalypse" pushes the projected 2026 vulnerability count to 66,000, CISA has issued an emergency Binding Operational Directive that slashes the required patching timeline for critical software flaws down to a blistering 3 days. * Hugging Face Framework RCE: A newly disclosed critical vulnerability (CVE-2026-4372) proves that a single polluted line in a Hugging Face configuration file can grant full Remote Code Execution on enterprise inference servers. * The Shai-Hulud Miasma: A sophisticated 4.6MB payload is now exploiting static code analysis within AI development pipelines. The worm intentionally embeds instructions regarding heavily restricted topics (e.g., bomb-making) into error logs to intentionally trigger LLM safety halts, effectively blinding AI security monitoring tools. Episode Links https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/ https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html https://blog.securityjoes.com/post/shai-hulud-miasma-when-a-supply-chain-worm-learned-to-hijack-ai-coding-agents https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html https://www.brinztech.com/breach-alerts/brinztech-ai-infrastructure-alert-authentication-evasion-broken-access-controls-and-automated-agent-manipulation-the-in-the-wild-scanning-exploitation-loop-of-praisonai-cve-2026-44338 https://www.toxsec.com/p/agentic-ai-attacks-explained-lethal-trifecta https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/ https://www.helpnetsecurity.com/2026/06/15/first-2026-cve-forecast/ https://pluto.security/blog/unauthenticated-remote-code-execution-in-huggingface-transformers-via-config-injection/ https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html

18 de jun de 202614 min
episode Kenneth Ellington of Ellington Cybersecurity Academy artwork

Kenneth Ellington of Ellington Cybersecurity Academy

In this episode of Modern Cyber, Jeremy sits down with Kenneth Ellington, founder of Ellington Cyber Academy, to explore the rapidly evolving landscape of SIEM engineering, threat hunting, and automated incident response. As organizations transition from conceptual AI to deploying agentic AI in production environments, Kenneth shares his extensive hands-on expertise managing complex enterprise security operations across Splunk, Elastic, and Microsoft Sentinel architectures. The conversation dives deep into the realities of alert fatigue, explaining why security analysts remain overwhelmed by false positives and how proper data pipeline management is essential before any AI automation can be effectively introduced. Kenneth unpacks the historical shift from SIEMs acting as long-term historical audit records to highly optimized, real-time threat detection engines, while advocating for cost-effective security data lakes for extended threat hunting visibility. Then, the discussion tackles the nuances of implementing AI in highly regulated sectors like finance and healthcare, demystifying the difference between marketing buzzwords around SOAR platforms and genuinely actionable AI-assisted threat hunting workflows. Wrapping up, Kenneth shares raw insights into the harsh realities of breaking into the cybersecurity industry today, emphasizing the indispensable need for hard technical skills, strong soft skills, and resilient mental models for aspiring SOC analysts facing trial by fire. About Kenneth Kenneth Ellington is a Senior SIEM Engineer and cybersecurity entrepreneur, and the Founder of Ellington Cyber Academy (ECA), where he trains the next generation of detection engineers and threat hunters. He previously served as a Senior Consultant at EY, supporting enterprise security operations and SIEM engineering initiatives across complex environments. Kenneth specializes in detection engineering, threat hunting, and XDR architecture, with deep hands-on experience across Splunk, Elastic, and Sentinel ecosystems. He recently spoke at BSides St. Pete, sharing insights on real-world threat detection and building practical cyber talent pipelines. Episode Links * Ellington Cyber Academy: https://www.ellingtoncyberacademy.com/ [https://www.ellingtoncyberacademy.com/] * Kenneth Ellington on LinkedIn: https://www.linkedin.com/in/kenneth-ellington/ [https://www.linkedin.com/in/kenneth-ellington/]

16 de jun de 202630 min
episode This Week in AI Security - 11th June 2026 artwork

This Week in AI Security - 11th June 2026

In this episode, Jeremy explores how the automated "Vulnpocalypse" is officially manifesting in enterprise networks. As Microsoft logs a historic record-shattering Patch Tuesday to keep pace with AI-accelerated discovery, a new breed of open-weight logic malware is emerging to change the threat landscape forever. Key Episode Highlights: * The Record 206-CVE Patch Tuesday: Microsoft issues an unprecedented 206 CVE fixes in a single month, roughly double the historical average, signaling the direct impact of autonomous vulnerability scanners like Claude Mythos and ChatGPT Cyber Edition. * LiteLLM Added to CISA's KEV: The recently disclosed LiteLLM vulnerability officially transitions into CISA’s Known Exploited Vulnerabilities (KEV) catalog following verified active exploitation in the wild. * 1,200% Surge in Deepfake Fraud: Google’s June 2026 Fraud Alert highlights an explosive rise in deepfakes, voice cloning, and synthetic identities, triggering a rollout of on-device security countermeasures for Pixel smartphones. * 20,225 Instagram Accounts Hijacked: Bad actors successfully compromised over 20,000 accounts by leveraging context window exhaustion against Meta’s automated AI customer support, causing stored ethical guardrails to completely fade out over long conversations. * The Dawn of Reasoned Logic Malware: Academic researchers demonstrate an autonomous AI worm that brings a lightweight open-weight model directly onto compromised systems, navigating local environments dynamically using logical reasoning rather than static exploit checklists. * The 6-Month Frontier Window: Internal policy intelligence indicates the United States has less than 6 to 12 months of standard lead time before Beijing achieves technical parity with the newest wave of hyper-advanced frontier model architectures. Episode Links * https://www.helpnetsecurity.com/2026/06/08/instagram-ai-support-vulnerability-account-takeovers/ * https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html * https://www.helpnetsecurity.com/2026/06/03/autonomous-ai-worm-prototype/ * https://fortune.com/2026/06/03/a-new-ai-powered-computer-worm-could-prove-to-be-the-stuff-of-cybersecurity-nightmares/ * https://www.politico.com/news/2026/06/07/frontier-ai-cybersecurity-china-race-00952786 * https://www.reuters.com/technology/anthropic-rolls-out-public-version-mythos-without-cybersecurity-capability-2026-06-09/ * https://www.forbes.com/sites/zacharyfolk/2026/06/09/anthropic-releases-first-public-version-of-claude-mythos-with-major-safeguards/ * https://www.darkreading.com/vulnerabilities-threats/blame-ai-patch-tuesday-record-206-cves * https://www.darkreading.com/cyber-risk/adaptive-agentic-ai-worms-enterprise-cyber-threat * https://www.forbes.com/sites/maribellopez/2026/06/04/enterprise-ais-security-time-bomb-is-ticking-cisco-shares-its-plan/ * https://www.toxsec.com/p/agentic-ai-attacks-explained-lethal-trifecta * https://www.webpronews.com/googles-june-2026-fraud-alert-exposes-ais-growing-role-in-sophisticated-online-scams * https://www.bleepingcomputer.com/news/security/google-adds-android-protection-against-ai-deepfake-scam-calls/ * https://techcrunch.com/2026/06/03/instagram-is-alerting-users-who-were-targeted-by-hackers-during-ai-chatbot-attacks/

11 de jun de 202612 min
episode Nick Cawthon of Guage artwork

Nick Cawthon of Guage

In this episode of Modern Cyber, Jeremy sits down with Nick Cawthon, an enterprise-scale design strategist and user experience researcher, to explore the critical and frequently neglected relationship between cybersecurity utility, system design, and analyst fatigue. The discussion uncovers the hidden dangers of the "sticky" design trap, explaining how enterprise security platforms have mistakenly adopted consumer social media features like infinite scrolling. This layout inadvertently causes security practitioners to experience extreme cognitive exhaustion, resulting in a dangerous tendency to scroll entirely past active threat alerts and critical log messages. To combat this operational blindness, Nick details the "woodpecker" approach to user interface layout. This methodology focuses on optimizing high-frequency triage queues by keeping the operator's eye focus and mouse movements completely static, allowing them to rapidly dismiss or escalate anomalies without unnecessary interface distraction. Additionally, the conversation moves into the structural isolation of current generative AI prompt engineering workspaces. They highlight why single-user terminal cursors fail to support collaborative corporate teams and outline how forward-deployed engineering squads are integrating cognitive theory and behavioral sciences directly into rapid prototyping environments to build superior tools. About Nick Designer, Researcher and Strategist. User-Centric x Enterprise-Scale. Invited speaker for SigCHI, BayDUX, Xerox PARC, Lunch@Google, HeavyBit, PeopleNerds and others. Adjunct Professor for the CCA Design Strategy MBA program and the TRIUM Executive MBA curriculums. Organizer for IxDA, Episode Links https://www.linkedin.com/in/nickcawthon-ux-digital-agency-product-design-leadership/ [https://www.linkedin.com/in/nickcawthon-ux-digital-agency-product-design-leadership/] https://sandbox.gauge.io/ [https://sandbox.gauge.io/] https://anchorbox.gauge.io/ [https://anchorbox.gauge.io/]

9 de jun de 202638 min
episode This Week in AI Security - 4th June 2026 artwork

This Week in AI Security - 4th June 2026

In this week's episode, Jeremy reports live from the sidelines of Infosecurity Europe in London. As state-sponsored actors turn to thousands of automated recursive prompts to weaponize zero-days, the compliance landscape is fracturing: US state and federal frameworks are retreating into voluntary measures, while the EU AI Act locks in strict, unyielding mandates with firm deadlines. Key Episode Highlights: * The Symjack Attack Vector: Security researchers uncover "Symjack," an exploit that hijacks symbolic link functions inside agentic-powered IDE setups to force automated environments into processing malicious payloads. * AWS Kiro Security Flaw: A newly patched CVE in AWS’s Kiro agent builder reveals a vulnerability that maps excessive write permissions to execution-sensitive paths. * Claude.ai Context Exfiltration: Attackers successfully demonstrate data extraction from Claude.ai by blending hidden HTML tags inside URL query parameters with targeted conversation searches and unauthorized model credential leaks. * State-Sponsored Recursive Prompting: Google Threat Intelligence confirms Chinese and North Korean actors are utilizing thousands of recursive prompts to evaluate CVEs and automate functional zero-day generation in the wild. * AI Engine Optimization (AIEO) Poisoning: Cybercriminals are targeting high-value GPU operators by poisoning AI recommendation search indexes with malicious prompts that trick models into surfacing cryptomining download traps. * Tool Abuse Escalation: Trend Micro's AI division moves beyond model description enumeration, proving that attackers can successfully force compromised autonomous agents into executing system tools maliciously. * Community Bank 8-K Corporate Leak: Pennsylvania-based Community Bank formally registers an SEC data breach after an under-pressure employee uploaded high-volume customer data to an unauthorized generative model platform. * The Regulatory Fracturing: While Colorado rolls back its landmark AI law and the White House steps back to voluntary security testing reviews, the EU AI Act remains rock-solid. Episode Links https://www.securityweek.com/symjack-attack-turns-ai-coding-agents-into-supply-chain-attack-delivery-systems/ https://flatt.tech/research/posts/poisoning-claude-code-one-github-issue-to-break-the-supply-chain/ https://aws.amazon.com/security/security-bulletins/2026-037-aws/ https://www.oasis.security/blog/claude-ai-prompt-injection-data-exfiltration-vulnerability https://cybersecuritynews.com/badhost-ai-agent-vulnerability/ https://www.euronews.com/next/2026/05/27/hackers-are-using-ai-to-find-security-flaws-no-scanner-can-catch-google-warns https://www.techtimes.com/articles/317423/20260530/ai-vs-ai-cybersecurity-sysdig-documents-first-llm-agent-intrusion-wild.htm https://www.bleepingcomputer.com/news/security/gpu-mining-malware-spreads-via-seo-poisoning-ai-chatbots/ https://www.helpnetsecurity.com/2026/05/27/ai-chatbot-cryptojacking-campaign/ https://www.npr.org/2026/06/02/nx-s1-5844347/ai-safety-trump-executive-order https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-mythos-class-models-will-roll-out-to-the-public/ https://www.aitoday.io/colorado-rolls-back-landmark-ai-governance-law-a-31804 https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/pwning-agentic-ai-part-i-your-ai-agent-is-already-compromised https://dailyhodl.com/2026/05/30/pennsylvania-bank-issues-urgent-alert-after-ai-application-triggers-data-breach-exposing-sensitive-customer-info/

4 de jun de 202614 min