
Hosted by Jerry Perullo, Sounil Yu, Mario Duarte · EN
Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the latest cybersecurity news. Each week, we discuss the most pressing headlines, offer candid commentary, and share unique insights from our extensive experience in the field.

00:00 Intro03:10 NPM supply chain attack leaves attackers empty handed24:44 Why is Atlassian buying a browser company?37:20 Apple's new Memory Integrity Enforcement52:56 Salesloft breach leads to downstream hacksHackers left empty-handed after massive NPM supply-chain attackHackers briefly compromised popular NPM packages like chalk and debug-js, infecting ~10% of cloud environments, but despite the massive supply-chain reach they only netted about $600 in stolen cryptocurrency.https://www.bleepingcomputer.com/news/security/hackers-left-empty-handed-after-massive-npm-supply-chain-attack/Why is Atlassian Buying a Browser Company?Atlassian is buying The Browser Company (makers of Arc and Dia) for $610M to gain control of the browser channel, secure its AI agent (Rovo) distribution, and enter the emerging “enterprise browser” market, even though success is uncertain against Google and Microsoft.https://nextword.substack.com/p/why-is-atlassian-buying-a-browserMemory Integrity Enforcement: A complete vision for memory safety in Apple devicesApple’s new Memory Integrity Enforcement (MIE) brings always-on hardware-software memory safety to iPhone 17, making advanced spyware exploits far harder.https://security.apple.com/blog/memory-integrity-enforcement/Salesloft breached to steal OAuth tokens for Salesforce data-theft attacksHackers exploited Salesloft’s Drift–Salesforce integration to steal OAuth tokens and exfiltrate sensitive Salesforce data, tracked as UNC6395.https://www.bleepingcomputer.com/news/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacks/Hosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway (Founder, https://githoundexplore.com)

00:00 Introduction & BlackHat02:06 Cybersecurity in Schools18:53 Black Hat Conference Highlights34:02 New York sues Zelle44:48 Trends in Cybersecurity Mergers and Acquisitions1:02:44 95% of generative AI pilots at companies are failing1:08:53 Prompt injection with poisoned calendar invitesDARPA announces $4 million winner of AI code review competition at DEF CONDARPA announced Team Atlanta as the winner of its two-year competition among researchers to create the best artificial intelligence systems that can find and fix vulnerabilities.Attorney General James Sues Company Behind Zelle for Enabling Widespread FraudNew York today sued Early Warning Services, a company owned and controlled by a group of the largest banks in the United States that was tasked with developing and operating the electronic payment platform Zelle, for failing to protect its users from massive amounts of fraud.Cyber AcquisitionsPalo Alto / CyberArkCrowdStrike / OnumOkta / AxiomArmis raises millions at $5B valuationMIT report: 95% of generative AI pilots at companies are failingA recent MIT‑commissioned study—highlighted in Fortune on August 18, 2025—reveals that approximately 95% of generative AI pilot programs at companies failed to deliver any measurable return on investment or financial uplift. The core issue appears to be not the AI itself, but poor integration into existing workflows and misaligned use cases, with only about 5% of pilots achieving rapid revenue growth by focusing sharply on specific pain points.Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart HomeSecurity researchers demonstrated that a poisoned Google Calendar invite could indirectly prompt-inject Google’s Gemini, causing it to control smart-home devices.Hosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway (https://tillsongalloway.com)

00:00 Introduction & BlackHat 03:14 AI Action Plan Overview 13:30 Chip Security Act 20:48 Government led AI-ISAC? 23:16 UK government considering banning public sector ransomware payments 28:14 Microsoft probing if Chinese hackers learned SharePoint flaws through alert 42:07 Ethics in Vendor Relationships – Gifts for meetingsAmerica's AI Action Plan“America’s AI Action Plan,” released by the Trump administration, outlines a roadmap with over 90 federal actions across three pillars—accelerating AI innovation, building U.S. AI infrastructure, and asserting international AI leadership through exports and technology alliances.The Chip Security Act: A Bipartisan Solution to Chip SmugglingThe Chip Security Act, introduced by U.S. lawmakers, mandates that export‑controlled AI chip makers (like NVIDIA) embed on‑chip location‑verification mechanisms to ensure devices go only where they’re authorized—aiming to deter smuggling (especially to China) without deploying intrusive GPS or kill switches.Why a Government-Led AI-ISAC is a Missed OpportunityErrol Weiss argues that an AI‑ISAC led by the U.S. government, as proposed in the July 2025 White House AI Action Plan, represents a missed opportunity, because government-led initiatives tend to be bureaucratic, slow, less innovative, struggle to win private-sector trust and buy‑in, risk duplicating existing ISAC efforts, and may be perceived as politically biased—undermining effective, rapid, cross-industry intelligence sharingUK plans to ban public sector bodies from paying ransom to cyber criminalsThe UK government is set to ban public sector bodies and operators of critical national infrastructure from paying ransom demands to cyber criminals, as part of a wider package also mandating mandatory reporting for other organisations planning to pay, aimed at dismantling the ransomware business model and protecting essential services from dangerous disruptions.Microsoft probing if Chinese hackers learned SharePoint flaws through alert, Bloomberg News reportsMicrosoft is investigating whether a leak from its Microsoft Active Protections Program (MAPP)—which provides early vulnerability alerts to security partners—may have enabled Chinese-aligned hackers (Linen Typhoon, Violet Typhoon, and Storm-2603) to exploit critical zero‑day flaws in on-premises SharePoint servers before Microsoft fully patched the software, fueling a global espionage and ransomware campaign.Hosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway (https://tillsongalloway.com)

00:00 Intro3:23 Cybersecurity stocks: why now might be the time to buy?8:55 AI in cyber investment and business29:28 Microsoft is moving antivirus providers out of the Windows kernel34:29 New AI Malware PoC Reliably Evades Microsoft Defender37:08 VSCode Fork; Putting Millions at Risk43:39 Extensions turn Trojan and infect 2.3M Chrome and Edge users54:20 US government takes down major North Korean ‘remote IT workers’ operation1:06:06 Phishing Training Doesn't WorkCybersecurity stocks: why now might be the time to buy?https://moneyweek.com/investments/tech-stocks/buy-cybersecurity-stocksAI Is Driving A Shift Towards Outcome-Based PricingCloudflare will now, by default, block AI bots from crawling its clients’ websites Microsoft is moving antivirus providers out of the Windows kernelhttps://www.theverge.com/news/692637/microsoft-windows-kernel-antivirus-changesNew AI Malware PoC Reliably Evades Microsoft Defenderhttps://www.darkreading.com/endpoint-security/ai-malware-poc-evades-microsoft-defenderMarketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork; Putting Millions at Riskhttps://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44Massive browser hijack: extensions turn Trojan and infect 2.3M Chrome and Edge usershttps://cybernews.com/security/chrome-edge-hijacked-by-eighteen-malicious-extensionsUS government takes down major North Korean ‘remote IT workers’ operation https://techcrunch.com/2025/06/30/us-government-takes-down-major-north-korean-remote-it-workers-operation/We've All Been Wrong: Phishing Training Doesn't Workhttps://www.darkreading.com/endpoint-security/phishing-training-doesnt-workHosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway

00:00 Intro03:17 Banks call out US Treasury's cybersecurity failures28:54 SEC scraps proposed cybersecurity rules38:05 What makes AI Security differentBanks Challenge Treasury on Cybersecurity Failures. A coalition of major U.S. banking associations—including the American Bankers Association, Bank Policy Institute, MFA, and SIFMA—has publicly challenged the U.S. Treasury and OCC to adopt private-sector cybersecurity standards, decentralize sensitive data, enforce rapid breach notifications, and streamline data collection following high-profile email breaches at federal regulators. https://www.theglobaltreasurer.com/2025/06/10/banking-groups-demand-regulator-cybersecurity-standards/SEC scraps proposed cybersecurity rules for investment advisers, market participants. The U.S. Securities and Exchange Commission (SEC) has scrapped proposed cybersecurity regulations targeting investment advisers, funds, and market participants. The withdrawal reflects pushback from the financial industry, which cited concerns over compliance burdens and regulatory overlap. Critics argue the move weakens oversight as cyber threats continue to rise across the financial sector. https://www.cybersecuritydive.com/news/sec-withdraw-cyber-rules-investment-advisers-funds/750786/Exclusive: New Microsoft Copilot flaw signals broader risk of AI agents being hacked—‘I would be terrified’. A newly discovered vulnerability in Microsoft’s Copilot platform—dubbed “Echoleak”—allows malicious actors to extract private user data from AI agent interactions. The flaw underscores the broader risks associated with AI-powered assistants, particularly as they become more deeply embedded in enterprise workflows. Experts warn this class of attacks could signal a new era of AI exploitation. https://fortune.com/2025/06/11/microsoft-copilot-vulnerability-ai-agents-echoleak-hacking/Hosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway (https://tillsongalloway.com)

00:00 Intro04:15 Our journeys from CISOs to Entreprenuers23:48 Trump changes Biden's Cyber EOs28:40 States rebuff proposed federal ban on AI laws36:43 Vanta bug exposes customers' data to other customers49:12 SentinelOne outage52:53 Banking groups ask SEC to drop incident disclosure requirements1:00:37 Cybersecurity teams generate average $36M in business growth1:03:50 Cybersecurity Companies Want to Go Public. The Market Isn’t Letting ThemTrump Cybersecurity Fact Sheet President Trump announced a reprioritization of U.S. cybersecurity efforts, shifting away from prior frameworks and emphasizing national defense and economic resilience. https://www.whitehouse.gov/fact-sheets/2025/06/fact-sheet-president-donald-j-trump-reprioritizes-cybersecurity-efforts-to-protect-america/Vanta Bug Exposed Customer Data A software flaw in Vanta's platform briefly exposed sensitive compliance data between customers. https://techcrunch.com/2025/06/02/vanta-bug-exposed-customers-data-to-other-customers/SentinelOne Outage A major backend outage at SentinelOne disrupted security operations for numerous customers. https://apple.news/AuaqeFPP8QUyoOwuAwvRBkAStates Push Back on Federal AI Law Ban U.S. states are resisting a federal proposal to ban state-level AI regulation, citing sovereignty and innovation concerns. https://www.wsj.com/articles/states-rebuff-proposed-federal-ban-on-ai-laws-6dde3ce6?mod=procyber_lead_pos1&tpl=csBanking Groups Oppose SEC Cyber Rule Banking associations urged the SEC to drop mandatory cyber incident disclosure rules, citing risk to financial stability. https://ecency.com/hive-167922/@justmythoughts/banking-groups-ask-sec-toCybersecurity Teams “Drive $36M in Growth” A report claims cybersecurity teams deliver $36M in business value annually—an assertion met with industry skepticism. https://www.infosecurity-magazine.com/news/cybersecurity-teams-business-growth/Cybersecurity IPO Market Frozen Despite strong interest, cybersecurity companies are unable to go public due to investor hesitation and market volatility. https://www.wsj.com/articles/cybersecurity-companies-want-to-go-public-the-market-isnt-letting-them-60bfe663Hosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway (https://tillsongalloway.com)

00:00 Intro02:49 Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals14:29 Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom26:24 Fake OpenAI MCP Integration32:25 Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials36:03 Destructive malware available in NPM repo went unnoticed for 2 years48:10 Sam & Jony introduce io58:23 Discussion: how risky are local admin rights?Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by CybercriminalsIn May 2025, an international coalition led by Microsoft, the U.S. Department of Justice, Europol, and Japan's Cybercrime Control Center dismantled the Lumma Stealer malware operation.https://www.wired.com/story/lumma-stealer-takedown-disrupted/Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransomHackers bribed overseas Coinbase customer support agents to steal sensitive user data, leading to a breach prompting a $20M ransom, which Coinbase refused, instead offering a $20M bounty for information leading to the attackers' arrest.https://www.cnbc.com/2025/05/15/coinbase-says-hackers-bribed-staff-to-steal-customer-data-and-are-demanding-20-million-ransom.htmlFake OpenAI MCP IntegrationA fake OpenAI MCP integration was found by a security researcher, showing the importance of security in emerging technologies.https://www.linkedin.com/feed/update/urn:li:activity:7331118878384615424/Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal CredentialsThree malicious npm packages targeting macOS users of the AI-powered code editor Cursor have infected over 3,200 developers by harvesting credentials.https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.htmlDestructive malware available in NPM repo went unnoticed for 2 yearsA destructive malware campaign infiltrated the npm ecosystem for over two years, with malicious packages disguised as legitimate tools targeting popular JavaScript frameworks.https://arstechnica.com/information-technology/2025/05/destructive-malware-available-in-npm-repo-went-unnoticed-for-2-years/Sam & Jony introduce ioOpenAI has announced the acquisition of Jony Ive's AI hardware startup, io.https://openai.com/sam-and-jony/Hosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway (https://tillsongalloway.com)

00:00 Intro00:44 Sounil's RSA Innovation Sandbox experience5:00 5% staffing cuts at Crowdstrike, AI cited as a factor16:00 Trump picks private sector veteran as Pentagon CIO32:41 Messaging app used by Trump official suspends operations after reported hack49:52 An open letter to third-party suppliers59:32 Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support1:04:42 Discussion: delivering secret keys stored in PDFs for password managersHosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (CISO, https://www.aembit.io/)Stories5% staffing cuts at Crowdstrike, AI cited as a factorCrowdStrike is laying off 5% of its workforce, citing AI-driven changes in industry operations as a driving factor.https://www.cnbc.com/2025/05/07/crowdstrike-announces-5percent-job-cuts-says-ai-reshaping-every-industry.htmlTrump picks private sector veteran as Pentagon CIOFormer President Trump has nominated a private-sector executive to serve as the new Chief Information Officer for the Department of Defense.https://therecord.media/trump-picks-private-sector-veteran-for-dod-cio-positionMessaging app used by Trump official suspends operations after reported hackA secure messaging app used by a Trump official has suspended service following a reported cyberattack.https://www.cnbc.com/2025/05/05/signal-telemessage-hack-trump-waltz.htmlAn open letter to third-party suppliersJPMorgan has issued an open letter urging its third-party suppliers to prioritize stronger cybersecurity and operational resilience.https://www.jpmorgan.com/technology/technology-blog/open-letter-to-our-suppliersMicrosoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless SupportMicrosoft is now enabling passkeys by default for new accounts, expanding passwordless access to over 15 billion users.https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html