Modern Cyber with Jeremy Snyder

Rich Mogull of Cloud Security Alliance

48 min · 27 de may de 2026
Portada del episodio Rich Mogull of Cloud Security Alliance

Descripción

In this episode of Modern Cyber, host Jeremy sits down with Rich Mogull, the Chief Analyst at the Cloud Security Alliance (CSA). Jeremy and Rich dive straight into the realities of AI-powered engineering, dissecting the risks and rewards of developer tool integrations like code copilots. They walk through the core architectures of Large Language Models (LLMs), outlining how non-determinism and the collapse of traditional control and data planes trigger modern security threats like indirect prompt injection. Rich offers a detailed breakdown of the high-profile AWS Amazon Q outage, analyzing how over-automation and over-provisioned privileges can lead to catastrophic environment tear-downs when the "human-in-the-loop" goes for coffee. Finally, the conversation shifts to Rich’s recent concept of "Core Collapse"—an astrophysics analogy for how AI-fueled offensive velocity creates a math problem of combinatorial complexity that human defenders cannot match alone. Learn how to combat this threat through goal-based permissions, deterministic guardrails, Zero Trust architectures, and proactive technical upskilling. About Rich Rich is the Chief Analyst at the Cloud Security Alliance where he focuses on leading-edge cloud and AI security research and implementation. He has over 25 years of security experience, with over 15 years of focusing on cloud and emerging technologies. Prior to joining the CSA full time Rich frequently collaborated with CSA as the principle course designer of the CCSK training class, primary author of the Guidance, and developer of the Cloud Security Maturity Model, among other projects. As Researcher and CEO of Securosis, RIch taught cloud security and incident response at Black Hat for over 10 years, developed the free Cloud Security Lab a Week (CloudSLAW) project, and actively works on developing hands-on cloud security techniques. Rich also founded DisruptOps, a cloud security startup acquired by FireMon where he became the SVP of Cloud Security. Prior to founding Securosis and DisruptOps, Rich was a Research Vice President at Gartner on the security team. Prior to his seven years at Gartner, Rich worked as an independent consultant, web application developer, software development manager at the University of Colorado, and systems and network administrator. Rich is the Security Editor of TidBITS and a frequent contributor to industry publications. He is a frequent industry speaker at events including the RSA Security Conference, Black Hat, and DefCon, and has spoken on every continent except Antarctica (where he's happy to speak for free -- assuming travel is covered). Episode Links: * Rich Mogull's CSA Profile: https://cloudsecurityalliance.org/profiles/rich-mogull [https://cloudsecurityalliance.org/profiles/rich-mogull] * Rich Mogull's "Core Collapse" Blog Post: https://cloudsecurityalliance.org/blog/2026/02/26/core-collapse#_ [https://cloudsecurityalliance.org/blog/2026/02/26/core-collapse#_]

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de Modern Cyber with Jeremy Snyder!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

118 episodios

episode Taylor Hersom of Eden Dta artwork

Taylor Hersom of Eden Dta

In this episode of Modern Cyber, Jeremy is joined by Taylor Hersom, Founder of Eden Data, to explore the critical intersection of cybersecurity, compliance, and enterprise growth. They discuss why startups often overinvest in technical security tools while underinvesting in the actual foundation of customer trust. Taylor unpacks how compliance frameworks like SOC 2 and ISO 27001 act as a powerful "trust escrow" for businesses and explains the complex nuances of the Cybersecurity Maturity Model Certification (CMMC) for government contractors and their subcontractors. The conversation also tackles the escalating challenge of shadow IT driven by AI tools, the urgent need for structured AI governance, and why the cybersecurity industry must shift away from relying on static employee policies toward implementing automated technical controls that eliminate human error entirely. About Taylor Hersom Taylor is the Founder of Eden Data, a modern cybersecurity firm recently acquired by Riveron, where it now plays a key role in expanding the firm’s risk advisory platform. A former Deloitte leader and CISO, Taylor brings deep expertise in governance and compliance frameworks, including SOC 2, ISO 27001, and HIPAA. Since founding Eden Data, he has helped hundreds of startups and scaleups—including Nooks AI, Zendesk, Bitly, and Kindbody—navigate everything from early-stage compliance to IPO readiness. He has earned Partner of the Year awards four years in a row from Drata. With his background, Taylor speaks to the evolving intersection of cybersecurity, compliance, and enterprise growth, showing how trust can be a powerful driver of business success. Episode Links Eden Data: https://www.edendata.com/ [https://www.edendata.com/] Taylor Hersom on LinkedIn: https://www.linkedin.com/in/taylorhersom/ [https://www.linkedin.com/in/taylorhersom/]

24 de jun de 202642 min
episode This Week in AI Security - 18th June 2026 artwork

This Week in AI Security - 18th June 2026

In this episode, Jeremy explores the fallout of the first US government-mandated global model kill switch, an unprecedented action taken against Anthropic's new Fable model. We also examine CISA's radical new 3-day vulnerability remediation timeline and how autonomous threats are now weaponizing application monitoring software. Key Episode Highlights: * The Global Kill Switch: Just five days after launch, the US Department of Commerce invoked a sweeping export control directive against Anthropic's Claude Fable model after an Amazon-discovered jailbreak was flagged to national security officials. This action triggered a total global deactivation, limiting access exclusively to US citizens. * The "Lethal Trifecta" of Agent Hijacking: Toxic researchers define the critical conditions where AI agents become highly weaponizable: concurrent access to sensitive data, exposure to untrusted external content, and the ability to execute outbound actions. * Sentry "Agentjacking": Attackers are injecting malicious Markdown into standard Sentry error logs to bypass WAF and EDR tools, silently hijacking the AI agents developers deploy to automatically triage and fix code errors. * CISA BOD 2026-04: As the "Vulnpocalypse" pushes the projected 2026 vulnerability count to 66,000, CISA has issued an emergency Binding Operational Directive that slashes the required patching timeline for critical software flaws down to a blistering 3 days. * Hugging Face Framework RCE: A newly disclosed critical vulnerability (CVE-2026-4372) proves that a single polluted line in a Hugging Face configuration file can grant full Remote Code Execution on enterprise inference servers. * The Shai-Hulud Miasma: A sophisticated 4.6MB payload is now exploiting static code analysis within AI development pipelines. The worm intentionally embeds instructions regarding heavily restricted topics (e.g., bomb-making) into error logs to intentionally trigger LLM safety halts, effectively blinding AI security monitoring tools. Episode Links https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/ https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html https://blog.securityjoes.com/post/shai-hulud-miasma-when-a-supply-chain-worm-learned-to-hijack-ai-coding-agents https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html https://www.brinztech.com/breach-alerts/brinztech-ai-infrastructure-alert-authentication-evasion-broken-access-controls-and-automated-agent-manipulation-the-in-the-wild-scanning-exploitation-loop-of-praisonai-cve-2026-44338 https://www.toxsec.com/p/agentic-ai-attacks-explained-lethal-trifecta https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/ https://www.helpnetsecurity.com/2026/06/15/first-2026-cve-forecast/ https://pluto.security/blog/unauthenticated-remote-code-execution-in-huggingface-transformers-via-config-injection/ https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html

18 de jun de 202614 min
episode Kenneth Ellington of Ellington Cybersecurity Academy artwork

Kenneth Ellington of Ellington Cybersecurity Academy

In this episode of Modern Cyber, Jeremy sits down with Kenneth Ellington, founder of Ellington Cyber Academy, to explore the rapidly evolving landscape of SIEM engineering, threat hunting, and automated incident response. As organizations transition from conceptual AI to deploying agentic AI in production environments, Kenneth shares his extensive hands-on expertise managing complex enterprise security operations across Splunk, Elastic, and Microsoft Sentinel architectures. The conversation dives deep into the realities of alert fatigue, explaining why security analysts remain overwhelmed by false positives and how proper data pipeline management is essential before any AI automation can be effectively introduced. Kenneth unpacks the historical shift from SIEMs acting as long-term historical audit records to highly optimized, real-time threat detection engines, while advocating for cost-effective security data lakes for extended threat hunting visibility. Then, the discussion tackles the nuances of implementing AI in highly regulated sectors like finance and healthcare, demystifying the difference between marketing buzzwords around SOAR platforms and genuinely actionable AI-assisted threat hunting workflows. Wrapping up, Kenneth shares raw insights into the harsh realities of breaking into the cybersecurity industry today, emphasizing the indispensable need for hard technical skills, strong soft skills, and resilient mental models for aspiring SOC analysts facing trial by fire. About Kenneth Kenneth Ellington is a Senior SIEM Engineer and cybersecurity entrepreneur, and the Founder of Ellington Cyber Academy (ECA), where he trains the next generation of detection engineers and threat hunters. He previously served as a Senior Consultant at EY, supporting enterprise security operations and SIEM engineering initiatives across complex environments. Kenneth specializes in detection engineering, threat hunting, and XDR architecture, with deep hands-on experience across Splunk, Elastic, and Sentinel ecosystems. He recently spoke at BSides St. Pete, sharing insights on real-world threat detection and building practical cyber talent pipelines. Episode Links * Ellington Cyber Academy: https://www.ellingtoncyberacademy.com/ [https://www.ellingtoncyberacademy.com/] * Kenneth Ellington on LinkedIn: https://www.linkedin.com/in/kenneth-ellington/ [https://www.linkedin.com/in/kenneth-ellington/]

16 de jun de 202630 min
episode This Week in AI Security - 11th June 2026 artwork

This Week in AI Security - 11th June 2026

In this episode, Jeremy explores how the automated "Vulnpocalypse" is officially manifesting in enterprise networks. As Microsoft logs a historic record-shattering Patch Tuesday to keep pace with AI-accelerated discovery, a new breed of open-weight logic malware is emerging to change the threat landscape forever. Key Episode Highlights: * The Record 206-CVE Patch Tuesday: Microsoft issues an unprecedented 206 CVE fixes in a single month, roughly double the historical average, signaling the direct impact of autonomous vulnerability scanners like Claude Mythos and ChatGPT Cyber Edition. * LiteLLM Added to CISA's KEV: The recently disclosed LiteLLM vulnerability officially transitions into CISA’s Known Exploited Vulnerabilities (KEV) catalog following verified active exploitation in the wild. * 1,200% Surge in Deepfake Fraud: Google’s June 2026 Fraud Alert highlights an explosive rise in deepfakes, voice cloning, and synthetic identities, triggering a rollout of on-device security countermeasures for Pixel smartphones. * 20,225 Instagram Accounts Hijacked: Bad actors successfully compromised over 20,000 accounts by leveraging context window exhaustion against Meta’s automated AI customer support, causing stored ethical guardrails to completely fade out over long conversations. * The Dawn of Reasoned Logic Malware: Academic researchers demonstrate an autonomous AI worm that brings a lightweight open-weight model directly onto compromised systems, navigating local environments dynamically using logical reasoning rather than static exploit checklists. * The 6-Month Frontier Window: Internal policy intelligence indicates the United States has less than 6 to 12 months of standard lead time before Beijing achieves technical parity with the newest wave of hyper-advanced frontier model architectures. Episode Links * https://www.helpnetsecurity.com/2026/06/08/instagram-ai-support-vulnerability-account-takeovers/ * https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html * https://www.helpnetsecurity.com/2026/06/03/autonomous-ai-worm-prototype/ * https://fortune.com/2026/06/03/a-new-ai-powered-computer-worm-could-prove-to-be-the-stuff-of-cybersecurity-nightmares/ * https://www.politico.com/news/2026/06/07/frontier-ai-cybersecurity-china-race-00952786 * https://www.reuters.com/technology/anthropic-rolls-out-public-version-mythos-without-cybersecurity-capability-2026-06-09/ * https://www.forbes.com/sites/zacharyfolk/2026/06/09/anthropic-releases-first-public-version-of-claude-mythos-with-major-safeguards/ * https://www.darkreading.com/vulnerabilities-threats/blame-ai-patch-tuesday-record-206-cves * https://www.darkreading.com/cyber-risk/adaptive-agentic-ai-worms-enterprise-cyber-threat * https://www.forbes.com/sites/maribellopez/2026/06/04/enterprise-ais-security-time-bomb-is-ticking-cisco-shares-its-plan/ * https://www.toxsec.com/p/agentic-ai-attacks-explained-lethal-trifecta * https://www.webpronews.com/googles-june-2026-fraud-alert-exposes-ais-growing-role-in-sophisticated-online-scams * https://www.bleepingcomputer.com/news/security/google-adds-android-protection-against-ai-deepfake-scam-calls/ * https://techcrunch.com/2026/06/03/instagram-is-alerting-users-who-were-targeted-by-hackers-during-ai-chatbot-attacks/

11 de jun de 202612 min
episode Nick Cawthon of Guage artwork

Nick Cawthon of Guage

In this episode of Modern Cyber, Jeremy sits down with Nick Cawthon, an enterprise-scale design strategist and user experience researcher, to explore the critical and frequently neglected relationship between cybersecurity utility, system design, and analyst fatigue. The discussion uncovers the hidden dangers of the "sticky" design trap, explaining how enterprise security platforms have mistakenly adopted consumer social media features like infinite scrolling. This layout inadvertently causes security practitioners to experience extreme cognitive exhaustion, resulting in a dangerous tendency to scroll entirely past active threat alerts and critical log messages. To combat this operational blindness, Nick details the "woodpecker" approach to user interface layout. This methodology focuses on optimizing high-frequency triage queues by keeping the operator's eye focus and mouse movements completely static, allowing them to rapidly dismiss or escalate anomalies without unnecessary interface distraction. Additionally, the conversation moves into the structural isolation of current generative AI prompt engineering workspaces. They highlight why single-user terminal cursors fail to support collaborative corporate teams and outline how forward-deployed engineering squads are integrating cognitive theory and behavioral sciences directly into rapid prototyping environments to build superior tools. About Nick Designer, Researcher and Strategist. User-Centric x Enterprise-Scale. Invited speaker for SigCHI, BayDUX, Xerox PARC, Lunch@Google, HeavyBit, PeopleNerds and others. Adjunct Professor for the CCA Design Strategy MBA program and the TRIUM Executive MBA curriculums. Organizer for IxDA, Episode Links https://www.linkedin.com/in/nickcawthon-ux-digital-agency-product-design-leadership/ [https://www.linkedin.com/in/nickcawthon-ux-digital-agency-product-design-leadership/] https://sandbox.gauge.io/ [https://sandbox.gauge.io/] https://anchorbox.gauge.io/ [https://anchorbox.gauge.io/]

9 de jun de 202638 min