Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 64 - The Mythos Hype Index: What AI Really Did to the Zero-Day Curve

Every CISO is asking it: now that frontier models like Claude Mythos and ChatGPT 5.5 have real offensive cyber capability, are zero days surging? Host Tova Dvorin and SafeBreach offensive engineer Adrian Culley dig into the mid-2026 data — GTIG, Mandiant M-Trends, Rapid7, AISI — and find the curve moved in shape, not volume. Inside: the two AI "firsts" (Big Sleep and a 2FA-bypass exploit), why commercial spyware explains the rebound, the negative-seven-day time-to-exploit, and why defender deployment is the real bottleneck.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS—an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments.

Backup Azure DevOps Test Plans w GitProtect.io | Ochrona QA i Test Suites

Zabezpiecz pełny cykl zapewnienia jakości w swoich projektach programistycznych! W wersji 2.4 GitProtect wprowadza wyczekiwaną funkcję: pełną kopię zapasową oraz odzyskiwanie planów testowych Azure DevOps Test Plans (w tym powiązanych zestawów testów — Test Suites). W tym wideo pokazujemy, jak łatwo dodać i skonfigurować plan ochrony dla Azure DevOps, zachowując przy tym pełną strukturę powiązań między przypadkami testowymi, konfiguracjami i historią ich wykonania.

GitProtect.io & Active Directory Integration (LDAP) | User Management Automation

User management in GitProtect.io is becoming even simpler! In version 2.4, we introduced direct integration with Active Directory via the LDAP/LDAPS protocol. Streamline your administration and replicate your company's hierarchy in minutes. In this tutorial, you'll learn how to establish a secure AD connection, handle verification certificates, and map AD groups to corresponding roles inside the GitProtect.io console.

What Is Dark AI? How Scammers Are Using Artificial Intelligence Against You

AI isn't just being used for good. Dark AI — artificial intelligence weaponized for malicious purposes — is behind a new wave of scams, phishing attacks, deepfakes, and cybercrimes that are harder than ever to detect. Scammers are now using AI to clone voices, fake video calls, impersonate people you trust, and generate convincing phishing messages at massive scale — all powered by dark GPTs built without safety restrictions.

The $50K per hour network downtime dilemma

Networking and network security stakes are high. Like really high. Infrastructure downtime costs teams at minimum $50,000 per hour, according to Business Wire. So what’s standing in the way of a faster, more coordinated response? Join Netskope and Tines for a live conversation on how you can move from reactive networking and network security operations to proactive response. Learn how to bridge the gap between detection and resolution across modern hybrid environments, improving reliability, accelerating response times, and reducing the manual work that slows teams down.

NVIDIA OpenShell Secures the Agent. Who Governs the Fleet?

Most attempts to control AI agents work at the model layer (alignment, system prompts) or the application layer (guardrail libraries, output filters). Both share a flaw: the thing being secured is also the thing doing the securing. A sufficiently confused or sufficiently compromised agent can talk its way past its own instructions. OpenShell takes a different position, and it is the right one. Put the controls in the environment, where the agent cannot negotiate with them.

The Room Where V2 Happens

I ran the same internal AI workshop twice in one week. Same content, same agenda, same Zoom link, just offered at multiple times to cover different schedules. By the second session, half of my material was wrong. Between the two scheduled sessions, something had changed. In the first session we couldn't use the skills feature in Claude. By the second, we could. Nothing dramatic happened.

SonicWall SMA1000 vulnerabilities in active exploitation

On July 14, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. CVE-2026-15409 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw that allows an attacker to force the appliance to make requests to unintended destinations.