
Loading summary
A
This is Rich Stroffolino with the department of no. We have two fantastic guests on the show today. We're going to start out with Davi Ottenheimer, the principal over at Flying Penguin. I got to ask, what's been your priority this past week?
B
Well, it's been AI, AI, AI, even though I'd rather be working on quantum. So every time I try to go talk to people about preparedness so we can talk about real risks, I end up going back to talking about Mythos is a myth and the bubble is coming.
A
Maybe what you need to do is program like an anthropic skill that just pivots all AI conversations into Quantum and then two birds, one stone.
C
I don't know. I don't know.
A
Maybe. You know, I'm trying to help you out, Dabi. I'm trying to help you out.
B
Well, the bottom line is that there's a real risk of actual compromise. And then there's a discussion around how much you should pay people for tokens. And to me, they're two can't be connected.
A
All right, next up here we got Chris Ray field CTO over at Giga Home. Chris, gotta ask, what has been your priority this past week?
C
Chasing down all my wild ideas and vibing them out, Seeing what happens. You know, like we were talking about the. The Twitter bot that's making self deprecating humor and jokes about other people and quietly exiting the room.
A
The. The best, the best kind of humor.
C
It's the best use of time.
A
Yeah. And the best use of bots. All right, we've got a busy show. We're going to get into it right now. Let's run that opening and then we'll get into the news. First from the CISO series, it's department of no. Yes, indeed. Welcome to the department of know your Virtual Friday strategy meeting. A huge thanks to our sponsor Vanta for today for helping make the show possible. Remember, you can get involved in our YouTube chat live. We broadcast every Friday at 4pm Eastern. So please make sure you're joining us. Just like I saw CCL in our chat. Wishing us all happy Friday. Already in there. Glad to have some of the regulars in there as well. Or shoot us an email feedbackisoseries.com it's on the screen right now. That means you should read it, I guess, at your leisure. Before we jump into the news, just a quick disclaimer here that the opinions expressed on the show are in fact those of our guests, not necessarily those of their employer. We've got about 30 minutes. So let's jump right into it in our no or no segment first up here, coding agents trigger endpoint security rules. Claude code cursor and OpenAI codecs are starting to trigger the same endpoint security alerts that defenders use to catch real attackers. That's at least a according to the security firm Sophos, they're saying that the agents aren't malicious, at least from what they're seeing in all cases. In all cases. Now I saw the eyebrows, I saw the eyebrows already. But they're performing attacker like actions more often like accessing browser credentials, downloading files with built in system tools and creating startup scripts. In related news, China's national vulnerability database said it found security issues in several versions of Anthropic's clawed code, basically saying it could send back sensitive user information to remote servers. Anthropic is saying this is an anti abuse measure meant to prevent unauthorized sale, not a secret back door. But Davi, I'm curious from your perspective, do you want to know more about what these agents are doing to trigger these EDR systems or is this what you've come to expect from these types of agents here?
B
I've come to expect, I should say both. I've come to expect that they're going to do the wrong thing and that I also should be monitoring what they're doing. I think the crazy part to this is the tone the conversation that's being had. I mean they both agree that it's doing the wrong thing and Anthropic says doing the wrong thing is good for our purposes of preventing you from getting access to the tool telemetry around the location and saying that China is the location that's not supposed to have it. Is all everyone agreeing for opposite reasons? It's ridiculous. Anthropic shouldn't be monitoring you without letting you know they're monitoring you and egress monitoring on the end node and catching them at it. And them admitting it to me is tragedy. It's the longer we end up with these tools, the deeper they try to get embedded, the less we can trust them because they prove themselves untrustworthy. The local models, the transparency of open source has been repeatedly proving itself better than Frontier service.
A
And I am glad we, I mean just I'd say the past like two months I've seen so much of that conversation at least shifting into looking at that as a possibility across a wide variety of use cases. I'm looking at more individually. Obviously organizations have much different needs for that. But Chris, I'm Curious. From your perspective, was this something you wanted to double click on, learn a little bit more about? Or was it no, thanks for you.
C
Yeah, this is a no more, definitely no more. So, you know, coding agents are the new insider threat. I don't know if everyone's agreeing on that, but that's my stance. EDR was built to profile humans, not something that types 10,000 words a minute. You know, we know behavioral detection is baseline driven and agents are completely wrecking that baseline. So EDR learn to flag credential access and living off the land, you know, using cert util downloading through PowerShell and Bash. Because humans doing that at 2am is anomalous and likely abusive agents do it constantly and legitimately. The signal to noise ratio has just collapsed. That's no good.
A
And your organization spent the last six months telling you you should be having your agents do that as much as possible too. Right?
C
Right now we're dealing with the alert fatigue if the EDR is not handling it well. Now, there are obvious fixes, right? Allow list the agents, but this recreates the exact blind spot that attackers want you to have. If your sock tunes out the cloud code or the cursor behavior, a prompt injection agent becomes a pre trusted attack tool.
A
Yeah, that becomes such already a big target and all of a sudden becomes, oh, it's just the open door behind the gate. Right. So yeah, wow.
C
In my head I'm thinking the solution here is obvious, but no one's going to use it. You should sandbox everything. If it can't touch it, it's not going to do anything malicious. You're not going to have to disambiguate whether it should have done that. It's sandboxed, but no one's going to run that in a sandbox.
B
I will say the open source sandboxes are arriving. I've written, written one myself. And here we go. You get a harness, the agents running a harness the same way you would run a virtual machine on top of a hypervisor. You're going to run agents on top of the harness. And that harness becomes your trusted gateway where the vendors can't do what they want because you've got them into a place that you can control them. You've harnessed the horse and they can give you whatever horse they want, but you own the harness.
C
All right, make sure you share that with me. I want to see this thing.
A
We'll put it in the show notes. Davi, share it with us. We'll put in the show notes Let everybody see it. All right, we got to move on to our next story here. Bad epoll flaw allows root access on Linux and Android, which I'd like to point out is also Linux. This flaw, named Bad epolle, lets local attackers with no special privileges gain full root access on affected systems. The flaw was missed by AI but found by a human security researcher. The flaw affects the Linux kernels e Pulse system, a core feature used to efficiently manage multiple network connections and file events. Because this is a fundamental part of the Linux kernel, there is no practical workaround other than patching vulnerable systems, which is probably a pretty good workaround. Security updates are already available and users are urged to install them as soon as possible. Hey, let's raise a glass here, humans. We can still find things. Chris, do you want to know more about major flaw, you know, a flaw in a major Linux kernel subsystem, or is this a patch it, move on situation for you?
C
This is both. So I want to know more. You know, privilege escalation bugs are the most boring vulnerabilities that we have, but they're also the ones that decide whether the phishing email becomes a resume generating event. So no more briefly, but then patch and move on.
A
Davi, what about for you? I saw you were amused there.
B
Well, I resonate with that. I mean, patch and Forget and we've 10 years ago we've gotten to the point where we patch and move on, but now it's interesting because as you say, a human found it and not mytho. So the good news is that one of the most looked at fuzzed subsystems, one of the most scrutinized code bases in existence, had a human look at it and find something. And that's good because humans still find stuff. But the bad news is these claims made by AI are just continuously disproven and they're not delivering the things that they told us would be delivered on a silver platter on our front door on July 6th. So I think it's a patch and move on, but it's also to recognize the fact that we've repeatedly proven the way things work hasn't changed dramatically.
A
Yeah, I think that kind of grounding context, always useful in our age of breathless hype. Always a good thing to keep in mind here. Next up here, GitHub, the ultimate attack surface. Here, researchers at Noma Security released a proof of concept for a flaw called Gitlost that could allow an unauthenticated attacker to create a GitHub issue in a public repository and then Pull data from an organization's private repositories. When an agent workflow with read access triggers an is on triggers on issue assignments, an attacker could embed hidden plain text English commands to exfiltrate private data, which the agent can't distinguish from trusted system instructions. It just says, hey, here's some instructions here. In other news, Datadog Security Labs reports that attackers are quietly mapping corporate GitHub environments by using old dormant accounts that look a lot less suspicious than brand new ones. Some of these accounts were created years ago and then have been left unused until they were brought back for automated scraping. Davi agents doing what people tell them to do is both expected behavior and also a hard thing to stop. Do you want to know more about either of these two approaches here, or are both of these just the iron price we have to Pay for using GitHub at this point?
B
That has no iron price. I mean, I would put it as you can't bundle everything together. It's not that you follow every instruction. There's supposed to be a thing called authorization, and the person authorized to give you the instructions should matter. There should be data channels, control channel separation. There should be boundaries around who is authorized. So if agents are following internal or specific keyed, even encrypted signatures, signed instruction skills that have some library, there's all kinds of things you can put in place to say this is trusted and that's not trusted. So the principle that agents just do what they're told comes from a place that says you haven't built any trust boundaries that are reasonable. So they're reading stuff and doing it. That's ridiculous. That's not how security is supposed to work. And I think very good example of this bleeds into the. The whole datadog report, which is time is supposed to mean something like old versus new. That's not even a trust boundary that we can rely on. One of the things that Openclaw really bothered me about was claiming that they had 30,000 stars suddenly in a day, from what? Look at the accounts. You know, how old were those accounts? Were they more than a day old? Were they 30 days old? I use time to try to figure out how much fraud there is. I don't use it as a boundary by which I would trust somebody or not. So it's actually the inverse.
A
Yeah, I saw that. The idea that markers that we've had for trust, like reevaluating those, and it's interesting to say time. I just saw someone recently saying that text or graphics or any of those Things used to be markers of trust because no one would put the time in to do them otherwise. And now that is completely already was over indexed and now completely is over indexed. Chris, I'm curious for you. Which of these two kind of stood out for you? Or is it a no thanks on both of them for you?
C
Get lost is a no more. Prompt injection is just SQL in the trench coat. We have worse tooling to figure it out. We're mixing untrusted data with trusted instructions, like you said, in the same channel. Nobody's taking the time to figure out or finding a shift equivalent to parameterized queries. That's the primitive that we're missing.
B
Yeah, and the reverse is true, too. When Fable was announced and they said, we've got these guardrails in place, I said, decode this base 64 text. And it wouldn't do it. And it dropped me out because the text inside it accused me of attacking it. And I said, it's just text, just give me the text. But it was trying to do the opposite, which was over control everything as an attack because it had no way of knowing that this was just data. I kept saying, it's just data. It's not a control.
C
Trust me. My grandma gave it to me.
B
Yeah, and reinventing sleeper cells just seems weird to me. Or sleeper agents. Like we don't know that things lay around and then resurface. That's the whole basis of a lot of the fraud on the Internet since forever.
A
All right, our last know or no story here and probably my favorite story of the week here. Video cables. They're going to leak your data. Researchers at Shandong University demonstrated an air gap defeat called Trogepix, which tweaks on screen pixels in ways the eyes cannot perceive, so that the video cable carrying them radiates a faint radio signal that a near receiver can then decode. It obviously needs malware to already be present on the machine, but researchers tested saw speeds of up to 8.1Mbps. So usually we're talking like kilobits per second here with a lot of these weird air gap things. The researchers say their technique needs no admin rights and no hardware changes. And that user level malware can just draw on the screen. That's enough to kind of trigger this. Obviously you need to also have the receiver in place. But, Chris, as far as weird air gap defeats go, this one actually, I mean, they all seem pretty ingenious to me. When you have like, rotating hard drives that make sounds, that make Morse code, that you can decrypt or like exfiltrate with is always fascinating to me. But I know these are more useful for James Bond style fantasy capers than necessarily real work here, but is there anything here you want to know more about?
C
No, thanks.
A
This is seeing somebody do magic in
C
front of you for the first time, or maybe the second and third time. It's a party trick. That's what it is. Because it starts with assume malware is already on the box, at which point your air gap has already failed. Right.
A
Yeah, that. That is always. That is always the thing. I mean, I guess there is. There is a world in which, you know, you have a. Something weird supply chain. I can get something on. This one was interesting to me because it didn't actually require the machine to be completely owned, but you still need to get something on the machine. So you're. You're 100% right here. Davi. Don't. Don't. Amazing. Randy. This for me, is this. Is this, is this magic? Have we seen? Is there a guy behind a curtain? Is the all powerful Oz have no clothes, etc. Metaphors that I'm mangling. What are your thoughts?
B
Well, two parts of me react to this one, you know, I like to be in the historian frame mind. And I think saying that a cable as an antenna is like, what do you think antennas are like? Of course it's intent. Like you took a piece of metal and you made an antenna out of it. Like, what are you trying to. I don't understand. That's what they are. But the other part of me is like, okay, I think hidden to this. And this reminds me of an Israeli presentation years ago about printers. And they could like read the flashes from miles away of the scanner, the multi, I believe.
A
Ben Gurion University.
B
Yeah, yeah. So the hidden point here is that the intelligence agencies have to your point, actually earlier, you're already failed at the air gap because it's easy to get in. What's actually being expressed here is that it's very, very hard to get out without getting caught. Getting in is so easy. Everyone gets in with no problem. And I can say from personal experience, it is trivial to break in. But breaking out for some reason has always been much, much, much more difficult. So every time I see a story like this, says we have a way to break out at 8Mbps, I go, I might actually be able to use that because I have a hard time getting out without getting caught. And I think that's the underlying piece here, is that they could save spy lives if they have a better way of expo.
A
Thank you for redeeming slightly this story for me. I know they're trivial. I will never stop presenting these on the show folks. So please if you have a favorite one feedback CISO series.com I want to know your favorite weird air gap defeat. Please let me know. I love these and I will never stop loving them. All right, before we move on to our next, some of our deeper dive discussions have to spend a few moments now and thank our sponsor for today and that is Vanta. Your team just added its 67th AI tool and unfortunately also your 67th security blind spot. The good news? The Vanta Agent works like a GRC engineer in the background finding every app your team uses, scoring the risk and drafting fixes for you. Vanta is the platform used by over 16,000 fast moving companies like Ramp Cursor and Harvey who are shaping the future with AI and staying ahead of AI risk. Get started at vanta.com headlines all right, let's dive into it here. Davi we're going to the Quantum realm here France to stop certifying products without Quantum, they're saying safe encryption here. The country's cybersecurity agency anssi has announced that it would stop certifying security products that lack quantum resistant encryption, a move that will force government bodies and critical operators to shift away from older systems, or at least older approaches here. Sami Susui, the ANSSI chief of staff and I apologize to the French language, stated that at a recent Quantum conference that the agency would Halt certifications from 2027 and that businesses should be buying only Quantum Safe's product by 2030. That should be, not must be. ANSSI approval is required for encryption use in the French government agencies and critical infrastructure. So this does carry some significant weight to it here. Dabi We've been following the quantum hardening efforts for a few years now. NIS quantum resistant protocols that are algorithms that they put out the slow rollout we've seen to things like secure messaging apps have kind of been the first adopters of those that I saw. I'm curious, what does it say when France is ready to pull the trigger on this across their government infrastructure networks?
B
Well, congratulations to France. I think they're doing the right thing and they're doing it very effectively because they know that procurement is a very powerful lever and they're doing it in a way that establishes the EU can control their own destiny. Unlike a lot of the discussion around cloud and sovereignty and data migration stuff, this is a clear case of where a country can decide we're going to do the right thing. We're going to make people safe. The harvest now, decrypt later is real. And we got to move on this. This, this is not exotic. This is like, we knew MD5 was broken, we knew SHA1 was broken, we knew TLS was broken. We got to move and have agility. And France is saying the time is now. The US used to be a leader in this space, but that's obviously off the table. So we're seeing the European Union do more and better and faster, and France is showing us how it's done. They're doing the right thing and they're doing it. And 2027, I think, is, I've said for a few years now, is probably the reasonable target for a lot of this movement. 2029 feels a bit late to me, but we couldn't say that because we didn't have the proof. And of course, there's a lot of academic science going on about when the breaks will occur. But the harvest now is the part like right now, the harvest now is the part that's dangerous because if people have a break in three years, they've definitely been harvesting for the last three years before they have the break.
A
Yeah, this is, I don't know when it happened, but we are, we, we have firmly moved to the when, not if, portion when it comes to quantum here. And, and this, to your point, like helping solve that procurement problem, France can take their lumps and, and kind of do the, you know, do the, do the hard work to get that. And, and even if on their end, building out workflows. I'm curious, Chris, from your perspective here, what kind of signal should this be sending both to other countries and to organizations that France has put in 2027 on the calendar here?
C
Yeah, so France has taken the harvest now, decrypt later from the conference, slide into a procurement deadline. And we know deadlines are the only things that have ever moved. Cryptography, you mentioned MD5, SHA1, TLS, those deprecations dragged on for what, 10 years until browsers and PCI set a hard date Certification leverage is how you move a market. So that's the signal right there. You know, Davi, you already mentioned this. Right. The exposure window is open and has been open. State secrets, health data infrastructure designs, they have secrecy, lifetimes of decades. If an adversary is recording that traffic today, waiting for quantum computer before migrating, you know, by definition that's, that's too long. We're going to see Y2K times 100, you know the, the panic and, and fear. The an. What is it? SSSI slaughtering anssi.
A
Yes.
C
Their pricing in the recording, not the computer.
B
Yeah. And I just want to say this wasn't like consensus, this wasn't like a framework, this wasn't like a pledge. This was like they said we're slamming the door and we're going to move on this executive decision made and that positions France as clear leadership decision in a clear technology space that has a clear line and that's what we needed. Just like as you say, PCI DSS. We had the two year slip on deprecation of TLS 1.0 and that was terrible that the banks could push back and there was a lot of negotiation and that came late because the people at risk, that's what it's all about, are unprotected. And so the harvesting now is going into places like health data, diplomatic cables, state records, all the stuff that you want to be protecting. You need to start like yesterday. 2025 is really when this should have started. 2027 is two years late. So I think France is doing the right thing by showing people how it's done. And I will say I do this for a living. So I'm tracking all of Europe and the progression and I've seen a giant leap from 20% on the server side, people getting on board and I'm tracking 80 some protocols. But on the web, one protocol, SMTP mail is another protocol. I've seen 20 to 30% jump, 10% jump in people who have turned on post quantum algorithms.
A
Yeah. David, your point about this being not a study. When I first saw this headline I was like okay, well this is going to be the most hang ringing statement of a statement of intent to form a focus group to look at. Like I'm so used to those announcements from everybody and I was like oh no, this is like a, like it's like a thing like that's, that's going to be presumably enforced. Obviously things can change, but mandatory. Yeah, yeah, that's very meaningful from what I'm saying. And CCL in our chat here was, was saying here, didn't Google announce something like this back a few months? I mean we're, we're again we're seeing private industry quite a bit again. I've been kind of surprised by how vocal some of these obviously the first two I think of are Apple and Signal were very forward saying they were doing this with a lot of their messaging apps. I knew Google, I Don't know the exact timeline for what they're doing with it, but.
B
Yeah, but there's three things here. One, again, I can go deep, but just go to pqprobe.com if you want to know more. But I can tell you, for example, that people say they turn it on, but they only turn it on in one place and it's not very transparent. So they turn it on on their website and they don't turn it on on mail. So Google will say that they turned it on, but then you go look at all the Gmail and you don't see it and you say, where is it on? If it's supposed to be on show proof, I should be able to test it and see it out front. And then second, when they say they turn it on, you don't know to what degree. And there's not like studied science yet. So I've tried to demystify a lot of that. Just like with the other migrations, like, it should be very clear to people that if you put on, you know, a certain level of strength, it's sufficient. It's. There's multiple levels, multiple ways that you can turn it on. And it has to be something that's agreed to. So there needs to be. You need to boil that down. So first is, are they turning it on in all the places that matter internally, especially not just on the outside? And then are they turning it on in a way that is consistent with guidelines? Second, and the third is a lot of people are pointing at each other and saying, well, who's doing it first? And when should I go? And oh, Google's doing it by 2029. And that's for me, it's a lot of nonsense. We know the dates, we know the risks. Stop looking at each other and saying, can we be in a herd that's late? Start being one of the people that's turning on the protections for the sake of the people who would be harmed if their data was lost.
A
All right, next up here, Jade Puffer ransomware uses or used AI agent to automate an entire attack. Researchers at Sysdig have identified what they believe to be the first documented case of ransomware operation conducted entirely by an LLM agent. The ransomware named Jade Puffer Quality ransomware name folks used an agent for reconnaissance, credential theft, lateral movement, persistence, privilege escalation and data encryption. It also adapted to failures during the intrusion in real time retrying failed steps within refined parameters. In about 30 seconds or so, Jade Puffer gained initial access to the target by exploiting a vulnerability in Lang Flow which we have talked about on the show previously. Sir, this may not be the first absolute case. It seems to be the first one that we know about. I think it's interesting. Five years ago, this would idea to me would have seemed like science fiction year ago. An inevitability. I guess we're here now. Chris, from your perspective, are you assuming this is going to be a de facto way to run a ransomware operation next year? And I guess, how do we get ready for that?
C
Yes. To answer the first part of that, yes, this is going to become the de facto standard. Autonomous ransomware doesn't change the playbook, it changes the clock. So every control, or let's say most of the controls you have still work. You just have minutes instead of days at this point. If you look at it, the kill chain is identical to what we saw in the 2018, 2019, 2020 era of ransomware. Initial access via something that's on patch, credential theft, lateral movement, persistence, and then encryption. The victim here didn't lose the AI. It's a patch management issue. The fundamentals still matter. What I find most interesting about this, because I went to business school, so I can't turn off the business side of my brain. The economics support this. They say, yes, next year. This is the de facto model because ransomware as a service has already commoditized skill. The autonomous part of this, that's commoditizing the labor, which means the side channel effect of this is the soft middle, the SME, the SMB. Those who could previously hide behind not being worth the time are now dead center in the sights.
A
Yeah, I was thinking about the economics of this too. I was kind of thinking about it almost on the other side. I'll get into it in a second here. But Davi, where is your mind at when we're looking at jade puffer and agentic ransomware operations here?
C
Here?
B
Well, it's not just that a patch was missing. Generally it was. The lang flow was unpatched, if I remember correctly. And so it was actually the framework for building AI that was on. So it was like by trying to work with AI, you introduced a big problem because now AI is attacking the system that was supposed to be building AI. So it's, it's negligence within the AI industry itself that is being popped by the AI industry. And so that to me says like, we haven't moved at all in our, in our world. We're still doing the same thing. In other words, we should do the same basic hygiene and egress monitoring and, you know, agents. I guess another way of putting this is a lot of the hype about how the mythology around how machines will do things that have never been done before conveniently overlook the fact that the agents are trying to do what's been done before. That's what they do is they learn from what's been done before. So what they're doing is running playbooks. And humans are really good at. You look at any sports competition, look at FIFA, you look at super bowl, you look at, you know, what humans are good is trying to defeat playbooks. So I think that a better storytelling here is one. We don't really know that this was autonomous to begin with. Let's just assume it was, but there hasn't been a lot of proof of that. But let's just say it was autonomous as an attack. It's running a playbook. And you can basically change the assumptions and the playbook will fail. And one of the things you can do is actually be patched. One of the playbooks that you're supposed to be running that no one runs is to actually, actually do all the stuff you're supposed to do. So if you take your vitamins and eat your vegetables, boom, you're not going to be unhealthy.
A
Whoa. I think you're right up here with CCL in our chat here. Proactive defense and preventative controls. Only way that I can think of. I think that goes along with the Take your medicine. I, I just remember the, the, the economic I was thinking of is I. Ransomware has a major customer service component to it. And I do wonder if it's entirely agent driven. Does that make that better or worse? And what does that impact the ability to get paid? Is. Was. Was what the first thing I thought of I was because in the story they, they said, you know, the, the bot claimed or the, in the LLM documentation, which it spewed out a ton of documentation, said it used AES 256, it used 128 or something like, like. So it was. I'm wondering one if it like messes up the ability to decrypt the data. Does that impact anything? If you're going to have the negotiation handled over an LLM, if it's possibly better because it can do more natural language stuff, I'm not sure that that to me is the weird economics of that. I know that's probably not as big of a consideration as, oh, now all of a sudden every SME And SMB is open to be targeted. But that, that was kind of where my mind went to that in a weird way, I don't, you know, AI customer service.
C
I'm picking up what you're laying down.
A
Yeah, it's a minor point, but that's where my mind is at. All right, let's finish up the show here with our last discussion here about the UK Cyber Pledge and Cyber Shield here. So first up, part of the UK's big cyber reset here. They had announced this big cyber pledge. They were trying to get as many companies on the financial times stock exchange 350 onto it. This pledge would call companies to commit to making cybersecurity a board level responsibility Register for the NCSE's free early warning service and require a cyber essential certification in their supply chain. So some basic controls. This would all be voluntary and their companies are acting like it because only it seems like 15 firms on that 350 actually signed up to be part of the launch of the pledge. That is 4%. I did the math folks. But in other UK cybersecurity news, the NCSC laid out plans for a national scale sovereign defense capability they're calling Cyber Shield. I don't know if anything related to Europe I would call Shield. Otherwise Max Schrems will just show up and start suing you. But that's a separate issue. This model would pair red and blue AI agents across critical infrastructure and government IT systems to both proactively probe for weaknesses and defend them in real time. To show you where this is at in terms of feasibility, the NCSE said the government can't deliver this capability on its own and will need to be done in association or partnership with leading frontier AI capabilities, cyber defense organizations and academia. Which tells me there's a lot of work to do. After rolling this capability out to government networks, the NCSC said it plans to transition it to commercially scalable solutions. Davi, this Cyber Shield here, I don't know, it gave me like Star wars project in the 80s vibes here. It sounds great, but how you gonna do it? Like, I guess, how are we reading that the UK Cyber Reset is going given we, you know, Cyber Pledge not getting a ton of support from, from the big companies here. Cyber Shield seems very amorphous. How are you reading this stuff?
B
You mean it didn't give you palantir in Iran 2026 vibes, you know, potato. So I think you bomb them to smithereens and nothing happens. I think the show itself so far, let me put it like this, France shows US how it should be done and get lost shows us how it shouldn't be done. And this is both not France and not gitlost. How would we propose autonomous agents with privileged access into critical infrastructure when you have GITLOS showing that agents are going to follow what of whatever instructions come in control or data can't tell the difference and you've just wired in a horrible vulnerability into your critical infrastructure and on top of that you've made things voluntary. I think the British are just totally out to lunch at this point. Like they don't get it. They, they the Brexit maybe had some sort of effect on their brains but they are falling behind in every possible way that I can see in the economy, in technology, in basic logic and reason. So this to me says look at what France is doing. Look at how they mandated the right thing and they're moving forward. And then look at how get lost popped agents and think about you didn't say anything or do anything to prevent that. So maybe you're on the wrong side in both.
A
This does remind me of like you know now to be fair, UK experienced some horrible retail manufacturing cyber attacks over the past year, right? Had major like had significant impacts on their gdp. Like so like I could understand why the need for a reset here but this seems to me like the like the reaction to the telcos assault Typhoon would be like what if we had less oversight like was was is like to make to lean into a voluntary scheme here. That to me doesn't make a lot of sense here. Chris does. Are you reading this any different than DAVI is at this point?
C
I think I am, but not contrarian.
A
Lay it out for us.
C
I'm hung up on this thought that I have which is spurred on by your Star wars comments. So your Star wars comparison, it cuts both ways. SDI never worked out as advertised but what it did do is it forced adversary spending and drove decades of R and D. So I'm thinking even if cyber shield under delivers on this national shield promise, institutionalizing the partnerships, the communication channels between government, frontier, AI labs, CNI operators, that may be the deliverable here that actually matters.
A
I hadn't thought about it that way. But yeah, even if reaching for this we won't get for it, playing that groundwork is valuable in and of itself, right?
C
Like shoot for the moon. If you come up short you're still among the stars. You know that whole thing
B
it was land a man on the moon so that you can bomb Russia with nukes.
A
That was the believe the I'm thinking more like we got Velcro, Dahvi, but sure. I mean, you know, no, building the
B
ICBMs, the Intercontinental Ballistic missiles was sort of the framework under which we were trying to get people to go to the moon. Because if you can hit the moon, you have the accuracy to actually bomb the place you're supposed to. Because if you've. Now we've revealed by looking at the historical research that Khrushchev is. One of his primary complaints was that when he fired the missiles, they'd be somehow 3,000km off range. They would accidentally hit Alaska when they were trying to hit something in, in the Gulag. So that's, you know, they needed accuracy. And how are you going to get people to focus on accuracy? Put a man on the moon. So that was the kind of the, the hidden history. But I think, I still think maybe I was too harsh on the uk, but I, I just feel like they're missing the whole point here. And we know this from the history of how things have been built to your point about Star wars and military history. Silicon Valley, for example, was built up around World War II to make the bombers was more effective. You know that there was a radar basically that they were doing research to make the bombers survive, more survivable when they bombed hospitals and civilians in Germany. And so that's Dresden being one of the perfect examples of that, where some 30,000 people died, not a huge amount, but still it was successful in the fact that they had more survivability in the B17s. And so if you want to do that again, then you basically have to fund it, but own it. You can't basically fund it and give it away. I think that's where people get confused. The success in Silicon Valley wasn't that they gave away the technology and people made their fortunes. It was that the technology was owned by the government, but it was designed and built by people who were in the tech sector. And I see in the Cyber Shield, the opposite, that they're like, we'll give you the money and then you actually get all the benefits and then we'll buy it back from you. And that's not going to work out at all.
A
Yeah, that to me seems that. And again and again not to like going back to the cyber pledge as well. Those are laudable things. I wish more we could like a voluntary scheme. Like those all seem like very reasonable precautions here, but I wish we could get to a place where, I don't know, like companies would seem the self interest in Doing that as opposed to nat. Turns out. No. Real quick, Chris having some issues with his camera, but he is still here. He is still with us. Don't. Don't worry, Chris, the voice of cyber security coming to us right here. We're gonna close out the show here. Real quick. David, you already kind of started aligning some of the pieces here of our rundown here, but if you had one piece of advice to kind of give our audience as we're heading out here, what would it be? Kind of just based on the conversation we've been having today that I.
B
It's focus on the fundamentals. I hate to say it because it's trite, but it's you. You got to look at the harvest now, decrypt later, and you got to look at the agility of crypto. You have to start moving towards the post quantum, because that is a real risk with real consequences for people. That really matters. And I think the AI stuff is interesting and it's worth discussing, and I certainly get paid a lot of money to talk about it, but it is not. It is not the existential crisis that the vendors want you to believe. And I. Perhaps most important of all, we need better integrity controls to prevent integrity breaches, and that means we need to have independent validation of things. Vendors say we have independent validation in some of the crypto space because of the science behind it. Whether that's the thing, are we going to be at risk or not? There's all kinds of independent research going on, but the AI space seems to have almost no independence. You have hundreds of people signing up to agree to a marketing brochure because they're all going to get paid a lot, but no true independence in assessing whether or not this is something you should be focused on. So get integrity breach in your head, get your post quantum migration going, look at France and focus on the fundamentals.
A
Eat your vegetables and your baguettes just to be nice to France as well. Chris. What? Yeah. Oh, please. I mean, how else are you supposed to enjoy bread? Chris, what piece of advice would you leave our audience with other than bread and butter is a classic couple.
C
All right, If I can't use bread and butter, I'm going to lead with or leave with. The one thing that I'm going to go do, which is go check your GitHub. Org for accounts that haven't logged in since 2023. If an account hasn't logged in this year, it doesn't need access, it needs deleting.
A
Oh, I like this. Just a very like, hey, you get into a better state tomorrow. I like this.
B
I like plugins run for GitHub.
A
I like where our mind's at. This is absolutely lovely here. All right, that just about does it for this episode of the department of Node. Thank you so much to Davi Ottenheimer and Chris Ray for being here. Some of my favorite guests to have on the show. This is absolutely phenomenal. Please check out, we'll have links to their websites, to their LinkedIn and all of their good stuff. Davi sent me that link for the sandbox stuff. I would love to share that as well and have that in our show notes. So look for that@ciso series.com and also a huge thank you you to Vanta for being a sponsor today and helping make the show possible. Remember, you can send us feedback anytime. Feedbacksoseries.com and join us again next Friday at 4pm Eastern for another edition of the Department of no. Thank you so much for joining us for your Friday stand up here. Have a great week. Stay secure out there. And for myself, for the big boss man, David Spark for Dahvie, for Chris and the entire CISO series team, here's wishing you and yours to have a super sparkly day. Cybersecurity headlines are available every weekday. Head to csoseries.com for the full stories. Behind the headlines.
Episode Theme:
This episode (July 10, 2026) explores current and emerging threats in cybersecurity, with a special focus on quantum readiness, the evolving role of AI/LLM-powered agents in both attack and defense, and Europe/UK’s approaches to national cyber resilience. Guests Davi Ottenheimer (Principal, Flying Penguin) and Chris Ray (Field CTO, Giga Home) join host Rich Stroffolino to discuss the week's most pressing infosec stories.
[03:12 - 06:28]
"The longer we end up with these tools, the deeper they try to get embedded, the less we can trust them because they prove themselves untrustworthy."
— Davi Ottenheimer [04:00]
[06:31 - 08:32]
[08:33 - 12:29]
[12:29 - 15:31]
[17:34 - 23:47]
"This is not a study... They said: we're slamming the door and we're going to move on this executive decision made. That positions France as clear leadership in a clear technology space."
— Davi Ottenheimer [20:25]
[23:47 - 29:02]
"If you take your vitamins and eat your vegetables, boom, you're not going to be unhealthy."
— Davi Ottenheimer [27:49]
[29:03 - 35:30]
"France shows us how it should be done and Gitlost shows us how it shouldn't be done. And this is both not France and not Gitlost."
— Davi Ottenheimer [30:54]
"Even if cyber shield underdelivers...institutionalizing the partnerships, the communication channels—that may be the deliverable here that actually matters."
— Chris Ray [33:28]
On agent-based security chaos:
"EDR was built to profile humans, not something that types 10,000 words a minute... Signal-to-noise ratio has just collapsed."
— Chris Ray [04:29]
On advancing cryptographic standards:
"Certification leverage is how you move a market... deadlines are the only thing that moved cryptography."
— Chris Ray [19:17]
On fundamental defense:
"Focus on the fundamentals. I hate to say it because it's trite, but... you have to start moving toward post-quantum, because that is a real risk."
— Davi Ottenheimer [36:27]
Practical advice:
"Go check your GitHub org for accounts that haven't logged in since 2023. If an account hasn't logged in this year, it doesn't need access, it needs deleting."
— Chris Ray [37:51]
Davi and Chris both stress focusing on the basics—patching, egress monitoring, strong cryptography, and independent validation—as technology and policy noise around AI and quantum continues to grow. France emerges as a leader with its bold deadlines for quantum-safe encryption, while skepticism remains about the UK’s current posture. Despite the rapid pace of threat evolution, fundamentals remain the most reliable defense.
Full Episode and related resources at CISOseries.com.