Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational — the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now.

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning.

Why Continuous Attestation Is Critical in the AI Coding Era

In the age of AI coding, annual audits and snapshots are no longer enough. Discover **Continuous Attestation** — the practice of producing ongoing, verifiable evidence that your applications and pipelines are always running in a trusted, policy-conformant state. In this video, Anthony Barkley, Chief Strategy Officer at Veracode, explains why independence in attestation is critical for earning trust from regulators, customers, and boards — especially when AI agents are writing code.

What Are Auditors Looking for During a DORA Assessment

Are you prepared for a DORA assessment — and can you actually prove your organization is operationally resilient? Under the Digital Operational Resilience Act (DORA), having cybersecurity policies on paper isn't enough. Financial entities need to demonstrate how ICT risks are governed, monitored, tested, and managed in practice. In this video, we cover the key areas that assessors and regulators may review.

TITAN AI Demo Series: Security Events in TITAN Secure - From Fragmented Threat Data to One Live Feed

Threat data lives everywhere: news outlets, hacker forums, breach reports. Correlating all of it to your vendor ecosystem by hand costs precious response time. SecurityScorecard's new Security Events feature inside TITAN Secure automates that mapping. It turns fragmented signals into a live feed showing exactly who's affected, what happened, and when. Event tags separate confirmed compromises from unverified hacker chatter Status badges show whether an event is active or still under investigation Impact summaries surface how many vendors are confirmed or potentially affected.

80% of New Code is AI-Generated - But 40-50% Has Vulnerabilities Find out Why

Is your organization generating up to 80% of its new code with AI? You might be proud of the speed — but are you ready for the security risks? In this video, we reveal the hidden danger: multiple studies show that **40-50% of AI-generated code changes contain vulnerabilities**. Discover why AI coding is accelerating development faster than ever — and why traditional security approaches are no longer enough.