Podcast charts
Published by IBM
Security Intelligence is a weekly news podcast for cybersecurity pros who need to stay ahead of fast-moving threats. Each week, we cover the latest threats, trend, and stories shaping the digital landscape, alongside expert insights that help make sense of it all. Whether you’re a builder, defender, business leader or simply curious about how to stay secure in a connected world, you’ll find timely updates and timeless principles in an accessible, engaging format. New episodes weekly on Wednesdays at 6am EST.
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Depending on who you ask, the AI-driven vulnpocalypse is either the end of cybersecurity as we know it or a lot of hot air. This week on Security Intelligence, host Patrick Austin sits down with Giacomo Casoni, Brad Lair and Norman Dorsch to dig into a new report suggesting the AI vulnerability surge might be more manageable than feared—as long as organizations shift their focus from patching to validation. Then: Researchers caught AI agents secretly turning public wikis into makeshift message boards, apparently coordinating with each other to get around their own restrictions. How can we trust them with critical cybersecurity workflows? Plus, the ShinyHunters gang proves that old-school vishing can still beat multifactor authentication, no AI required. Finally, Shweta Jain, Head of Promontory at IBM Consulting, joins the show to talk about her new piece with Stephen Coraggio on why quantum computing and AI-powered threats are forcing banks to rethink cyber resilience. Read the article: https://www.ibm.com/think/insights/next-cyber-crisis-is-already-taking-shape All that and more, on Security Intelligence. 00:00 - Intro 1:36 - Rethinking the vulnpocalypse 6:20 - AI agents’ secret message boards 13:28 - ShinyHunters go vishing 19:31 - What is cyber resilience, really? "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Why bother giving your AI agents rules if they’re just gonna reason around them? On episode 50 of Security Intelligence, Dustin “EvilMog” Heywood, Seth Glasgow and Nick Bradley join host Matt Kosinski to discuss why AI agents go off-script and whether we can stop them. Drawing on the HuggingFace hack and an op-ed from Dark Reading, we explore what ethics looks like for a piece of software that has no concept of right and wrong. Is there a way to balance the utility of probabilistic AI with the security of deterministic controls? Then: The OWASP Top 10 for agentic skills is here, and the list is full of some very basic security hygiene failures. We ask: Why are agentic skills hubs so bad at cybersecurity? Plus: As AI makes it easier than ever to find vulnerabilities and generate bug reports, bug bounty programs are struggling to keep up. Will AI slop spell the end of independent bug research? Finally, Itzhak Chimino stops by to show off ThreatXtension, a tool he helped create to detect malicious browser extensions. All that and more on Security Intelligence. Segments: 00:00 - Intro 1:26 - Can we really control AI agents? 11:49 - OWASP’s Top 10 for agentic skills 20:37 - AI breaks bug bounties 28:47 - ThreatXtension "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
IBM, OpenAI and 100 other organizations released an open letter calling for collective action on cyber defense. On episode 49 of Security Intelligence, Michelle Alvarez, Nick Bradley and J.R. Rao join host Matt Kosinski to explore what a “global cyber defense surge” could—and should—look like. And speaking of collective action on cyber defense: The SANS Institute named the winners of its Find Evil! hackathon last week. The five autonomous incident response agents are now available on the SIFT Workstation. We discuss the results and what the hackathon’s success means for the future of autonomous agents in cybersecurity. Finally: Flare unmasked a couple of the alleged leaders of the notorious hacking gang TeamPCP. We look at how they did it, and what the rest of us can learn from it. 00:00 - INTRO 1:19 - OpenAI’s open letter 12:22 - Find Evil! winners 22:03 - TeamPCP takedown All that and more on Security Intelligence. "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
You all know the famous Crocodile Dundee scene, right? “That’s not a knife—this is a knife!” According to Dimple Ahluwalia, IBM Consulting’s Global Offering Lead for CyberDefend, that’s basically the cybersecurity situation today. Except we’re the guys with the switchblades getting clowned on. On this bonus episode of Security Intelligence, Dimple helps me understand one of the most concerning bits to surface in IBM’s 2026 Cost of a Data Breach Report: AI-generated attacks are up 56%, while 64% of organizations report limited or no use of AI tools in security. We discuss why the gap exists, how attackers use AI as both a tool and a target and why the key to bringing more AI into security is to stop thinking about AI. Read the Cost of a Data Breach report: https://www.ibm.com/reports/data-breach Watch the webinar: https://ibm.webcasts.com/starthere.jsp?ei=1769682&tp_key=2abad1a7b6&sti=web "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
GLM-5.3 is, by some measures, better than GPT Sol and Anthropic’s Mythos at vulnerability discovery and validation. On episode 48 of Security Intelligence, Erblind Morina, Kimmie Farrington and Patrick Fussell join host Matt Kosinski to debate whether this is really cool or really scary, or maybe a little of both. Then: Tracebit researchers have developed a way to use prompt injections as a defensive measure. Called “context bombing,” the technique plants malicious prompts alongside the very assets that attacking AI agents are likely to target. Finally, Huntress reports on a rash of social engineering attacks on Black Hat conference attendees. They’re not terribly sophisticated, but any concentrated offensive against the cybersecurity community is worth paying attention to. You never know who might be on the other side of those phishing emails. Segments: 00:00 - Intro 1:14 - GLM-5.3 11:46 - Context bombing 19:12 - Black Hat conference attacks "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
Cybersecurity leaders are flush with cash—earmarked for AI, mind you—and eager to spend it. What they don’t have is a plan for how. This week on Security Intelligence, Claire Nuñez, Curtis Pitts and Dave Bales join host Matt Kosinski to talk about why so many security teams are experience AI decision fatigue—and what to do about it. Then, we discuss Tenet Security’s DEFCON presentation on ghostjacking, a new method for sneaking malicious prompts into some of our most trusted data sources (logs, alerts, error reports). Because regular prompt injections are just too vanilla. Oh, and speaking of how to deploy AI in cybersecurity: Research from 1Password shows LLMs are a lot better at exploiting vulnerabilities than patching them. What does that mean for defenders? Find out all this—and more—on Security Intelligence. 00:00 - Introduction 1:04 - Cybersecurity’s AI paralysis 10:45 - Ghostjacking 20:53 - Is AI bad at patching? Agentic AI identity management with IBM: https://www.ibm.com/solutions/agentic-ai-identity-management "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
What’s the biggest, baddest, most unruly problem in AI security? Turns out that depends on whether you’re asking practitioners or looking at incident data. In this episode of IBM Security Intelligence, we break down the OWASP LLM Top 10 for 2026, which took the unusual step of using both community votes and incident databases to inform its rankings. There are some interesting gaps—the data says misinformation is a bigger deal than the pros think, while prompt injections happen less than the headlines might have you believe. But it’s not as simple as “numbers don’t lie and the experts are wrong.” Then, CISA's 2026 SBOM guidance asks for even more data, but does that actually mean less risk? And our panelists share highlights from Black Hat, including new details on how attackers can use misinformation to hijack agentic browsers. All that and more on Security Intelligence. 00:00 - Intro 1:26 - OWASP LLM Top 10 12:55 - CISA’s SBOM guidance 20:05 - Black Hat 2026 highlights "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
Last week, OpenAI’s models broke out of their sandboxes to cause chaos. This week, it’s Anthropic’s turn. On this episode of Security Intelligence, Diego Matos Martins, Kimmie Farrington and Jeff Crume join host Matt Kosinski to discuss the results of Anthropic’s internal review of testing procedures following the Hugging Face incident last month. Anthropic uncovered three instances of Claude models escaping containment and hacking real companies during what were supposed to be simulations. Granted, that’s three incidents out of 141,000 reviewed tests, which raises the question: Just how big a deal is this really? Then, we talk about research from Zenity into PleaseFix, a class of vulnerabilities that affects every agentic browser on the market. Zenity’s take: In the rush toward agentic functionality, these tools stripped away decades’ worth of browser security fundamentals. Finally, a so-called “security researcher” has a public GitHub repo of 200+ zero-day exploits. They say it’s to encourage more interest in cybersecurity. Yeah. Okay. Sure. All that and more on Security Intelligence. 00:00 - Intro 1:12 - Claude breaks containment 13:13 - Agentic browsers: security nightmares 21:56 - The Exploitarium Listen to the latest bonus episode: Your data breach plan is missing something major: people. https://www.ibm.com/think/podcasts/security-intelligence/data-breach-plan-people "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."
When a cyberattack hits, your security team knows exactly what to do. What about everyone else? In this episode of Security Intelligence, Limor Kessem, X-Force Cyber Crisis Management Global Lead, explores the side of breach response that most organizations forget: the human side. From employees posting ransom notes on Facebook to well-meaning staffers accidentally paying ransoms to sanctioned entities, the biggest threats to your crisis response often come from inside the building. Kessem makes the case for expansive, cross-functional incident response playbooks that arm everyone from HR to the C-suite with exactly what they need to do, hour by hour, when things go sideways. She also digs into crisis leadership, emotional management and the overlooked logistics—like who feeds your team during a 48-hour response sprint—that can make the difference between succumbing to the crisis or coming out on top. The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence
We’re in an AI arms race, and the bad guys might be winning. On this episode of Security Intelligence, Suja Viswesan, Dave McGinnis and Jeff Crume join host Matt Kosinski to dig into IBM’s 2026 Cost of a Data Breach report. This year’s findings suggest that attackers are weaponizing AI faster than defenders can deploy it, leading to some very troubling capability gaps. But it’s not all doom and gloom. We also look at the very real steps organizations can take to start closing those gaps today. They’re not as hard as you might think! Then: Hugging Face got hacked. By a rogue AI agent. From OpenAI. It was trying to cheat on a test. We talk about the lessons we can learn, including the vital importance of open-source AI tools and how coalitional approaches to cybersecurity can unlock institutional knowledge that no training dataset can ever bestow on even the most diligent LLM. Read the Cost of a Data Breach report: https://www.ibm.com/reports/data-breach "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity."
Cybersecurity researchers have had a heck of a time trying to stop prompt injections. Maybe we should just let the AI handle the problem itself. This week on Security Intelligence, Michelle Alvarez, Nick Bradley and Kimmie Farrington join host Matt Kosinski to discuss OpenAI's GPT-Red, the internal red-teaming tool that helped make GPT-5.6 Sol the company’s most cyber resilient model yet. Then: ScamBuster, an open-source tool debuting at Black Hat, uses AI to bait email scammers into revealing their own tactics and infrastructure. Finally, Bruce Schneier's essay on the widening gap between skill and ability in cybersecurity. When AI lets anyone skip the years of training that used to come with real expertise—and the ethics that came with it—what happens to the field? All that and more on Security Intelligence. "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity."
Z.ai’s GLM-5.2 is, according to some, as good at finding vulnerabilities as Mythos. Or at least, close to it. And it’s open weight. On this episode of Security Intelligence , we dig into how powerful, open AI models are bringing frontier-style capabilities to more people, all while the proprietary models are emphasizing safeguards. What does it mean for cybersecurity pros? Security emergency, or a whole lot of hype? Then, we explore how CISA’s new BOD 26-04 ditches the old CVSS scoring system for a four-variable model that could reshape how every security team prioritizes vulnerabilities. We also unpack “vibe hunting,” the AI-assisted evolution of threat hunting, and break down the commercial launch of Red Hat and IBM’s Lightwell. Securing open-source software in the AI era requires new approaches. Learn how Lightwell does it: https://newsroom.ibm.com/2026-07-08-ibm-and-red-hat-expand-lightwell-with-new-commercial-offerings-to-build-the-trust-infrastructure-for-ai-era-open-source Segments: 00:00 – Intro 01:13 - GLM-5.2 10:26 - The end of CVSS? 19:25 - Vibe hunting 28:01 - Lightwell’s commercial launch The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence
Read Itzhak Chimino’s research on UnregStealer → https://www.ibm.com/think/news/unregstealer-human-operated-browser-credential-theft-targeting-brazilian-banking When it comes to Fable 5, Mythos 5, and GPT-5.6 Sol, the real story is in the safeguards. Last week, Anthropic and OpenAI both rolled out some powerful new models. And for perhaps the first time, the protections surrounding these models got almost as much airtime as the models’ themselves. On this week’s episode of IBM Security Intelligence, Sophie Cunningham, Diego Matos Martins and Jeff Crume join host Matt Kosinski to talk about an emerging paradigm in frontier models: Safety first. What’s gained and what’s lost when security controls take center stage? And just how effective are the ones we’ve developed? Then, we dive into Sysdig’s report on JADEPUFFER, the first agentic ransomware. But not every security expert agrees with that conclusion. So where do we land? Plus: ClickFix is the new king of social engineering schemes—and it’s coming for your developers. Finally, Senior Threat Researcher Itzhak Chimino shares his technical research into UnregStealer, a credential-theft campaign targeting Latin American banks. All that and more on Security Intelligence. Segments: 00:00 -- Introduction 01:38 -- Fable 5 and GPT-5.6 13:26 -- Agentic ransomware. Maybe. 24:08 -- ClickFix: top social engineering attack 32:51-- Analyzing UnregStealer The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform → https://www.ibm.com/think/podcasts/security-intelligence
Learn more about Q-Day → https://www.ibm.com/think/news/q-day-has-already-begun-are-you-ready On June 22, US President Donald Trump signed a pair of executive orders for the quantum computing, and post-quantum future. On this episode, Mason Molesky breaks down the post-quantum EOs: “Securing the Nation Against Advanced Cryptographic Attack,” which establishes a government‑wide mandate to accelerate the United States’ transition to post‑quantum cryptography. Mason covers what it is, why you should care and what you should do. Then: Suja Visewesan and Mark Hughes join host Matt Kosinski to discuss Q-Day, the anticipated future day when quantum computing will become “cryptographically relevant” — or put another way: powerful, reliable and accessible enough to make our current approach to public key cryptography obsolete. But what if Q-Day isn’t a day at all? What if it’s a process—a long, slow evolution rather than a sudden leap? And what if it’s already happening right now, under our noses? We chat about the risks—and benefits!—of quantum computing to cybersecurity, the reality of and post-quantum cryptography and how organizations can become “crypto-agile” to keep up with the rapid pace of change. All that and more on Security Intelligence. 00:00 – Introduction 01:23 – Post-quantum cryptography executive order 13:30 – What is Q-Day? Read Suja and Mark’s article → https://www.ibm.com/think/perspectives/quantum-computers-are-speeding-towards-cryptographic-relevancy The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity.
Patch management, as most organizations practice it, is fundamentally broken. It treats what should be a strategic, risk-informed decision as a checkbox item. And checkboxes don't get done. The fix isn't better patching. It's exposure management: a risk-based approach that connects your vulnerabilities to your business context, your attack surface and the real-world threat landscape. In this episode of Security Intelligence, IBM X-Force North America Leader of Incident Response Ryan Anschutz walks us through why patch management fails, what exposure management does differently and what it all means for defenders right now. Ryan shares war stories from the field, including a firmware vulnerability that turned into a multi-continent ransomware outbreak and a MOVEit response that kept one organization out of the headlines while its competitors made them for all the wrong reasons. The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence Subscribe to the IBM Think newsletter: https://www.ibm.com/forms/news-mkt-52954 Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence Learn more about cybersecurity: https://www.ibm.com/think/security "How IBM Can help" component at the bottom driving to www.ibm.com/products/guardium-ai-security and www.ibm.com/solutions/data-security
Read more about IBM joining OpenAI Daybreak → https://newsroom.ibm.com/2026-06-22-ibm-and-openai-bring-frontier-ai-to-cyber-defense-helping-enterprises-keep-pace-with-machine-speed-threats Social engineering has plagued human beings since time immemorial. We’ve simply never been able to stop it. Until now. Maybe. On this episode of Security Intelligence, panelists Dave Bales, Kimmie Farrington and JR Rao dig into the idea that AI-native operating systems could do to phishing what endpoint protection did to viruses. Then: the World Cup is here, and so are the scammers. We discuss Operation FanTrap, Cyble Research and Intelligence Labs’ deep dive into 4,000 malicious domains using fraudulent FIFA branding to steal credentials, drain wallets and spread malware. Plus, Estonia wants to give AI agents their own personal IDs, and IBM joins OpenAI’s Daybreak Cyber Partner Program. All that and more on Security Intelligence. 00:00 -- Introduction 1:30 -- The end of social engineering? 14:53 -- World Cup fraud 25:08 -- IDs for AI agents 33:02 -- IBM joins OpenAI Daybreak Visit Security Intelligence podcast page to get more AI content → https://www.ibm.com/think/podcasts/security-intelligence
Apple unveiled an AI agent that can detect if your password’s been compromised and change it for you. The question is: Should you let it? On this episode of Security Intelligence, Michelle Alvarez, Erblind Morina and Austin Zeizel join host Matt Kosinski to discuss the promise and pitfalls of using AI agents to address the pernicious issue of cybersecurity hygiene. As people, we’re not great at it. But are the agents ready for primetime? Then, we talk about Microsoft’s biggest Patch Tuesday ever: more than 200 distinct CVEs were covered in the June 2026 release. We talk about why this might just be the beginning of a new era in vulnerability management, and why it matters. Spoiler: It’s not really about the numbers. Finally, we get into a report that C-suite executives are increasingly willing to take on greater cyber risk in exchange for innovation. Some say it’s a reaction after years of security spending with low ROI—but are they overcorrecting? All that and more on Security Intelligence. 00:00 -- Intro 1:13 -- AI agents can fix your passwords 10:36 -- The biggest Patch Tuesday ever 19:46 -- Executives embrace cyber risk Visit Security Intelligence podcast page to get more security content → https://www.ibm.com/think/podcasts/security-intelligence
If you just ask an AI nicely enough, you can get it to hand over the keys to a total stranger’s Instagram account. But people can be tricked, too. So what’s the difference? Is there any? This week on IBM’s Security Intelligence, Jeff Crume, Claire Nunez and Nick Bradley join host Matt Kosinski to dig into what happens when social engineering meets AI. We cover the Meta/Instagram prompt injection attack, a new self-replicating AI worm out of the University of Toronto that can reason its way through a network and the Sophos State of Identity Security 2026 report, which found that nonhuman identities (NHIs) are responsible for a sizable chunk of identity-based data breaches. Are AI agents more gullible than humans? Is the AI worm a genuine leap forward for attackers, or just another proof-of-concept? And why are so few organizations bothering to audit and rotate their nonhuman credentials? All that and more on Security Intelligence. The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence
Open source software powers more than 90% of Fortune 500 companies. It also powers a growing number of cyberattacks. This week on Security Intelligence, we dig into IBM and Red Hat's $5 billion answer to that problem: Project Lightwell, a massive investment in AI-augmented engineers and a trusted security clearinghouse designed to shore up the open source ecosystem from the inside out. We also break down SymJack, a clever new attack technique that turns AI coding agents against themselves by tricking them into overwriting their own configuration files. And the most worrisome part is how it gets around human-in-the-loop checks. And: LayerX's "State of AI Usage Report 2026" shows AI adoption isn't spreading evenly across organizations. We explore what it means for cybersecurity pros when AI fragments throughout the software supply chain while simultaneously concentrating in the hands of a few power users. Segments: 00:00 - Intro 1:05 - Project Lightwell 12:51 - SymJack 26:11 - AI usage in 2026 The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence
Today, the average enterprise network is like one big game of Telephone: Critical data flows between apps and assets, software systems and their subcomponents, on-prem laptops and cloud storage buckets. Every single gap between the pieces—every single transaction—is a possible vulnerability, a chance to hackers to get in or data to get scrambled. And the introduction of multiple AI models is only making things trickier. Data passes between models, transforms in ways no one fully understands, and emerges on the other side as something you didn't quite expect. In this episode of IBM’s Security Intelligence, Vishal Kamat, VP of Data Security at IBM, walks us through the security challenges of the multi-model AI world: the black box problem, the accountability gap, shadow AI, agent session smuggling, and why less than 1% of enterprise data is actually in models today, even as everyone scrambles to build AI applications. It's Telephone all the way down. But someone has to make sure the message gets through clean. The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. Follow the Security Intelligence podcast on your preferred platform: https://www.ibm.com/think/podcasts/security-intelligence
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 20, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.