Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 73 - EU AI Act-What Actually Lands on August 2nd, and What Slipped to 2027

The EU AI Act's August 2nd, 2026 deadline just changed shape. Host Tova Dvorin and offensive security engineer Adrian Cully separate what actually lands—Article 50 transparency duties and GPAI enforcement powers—from the high-risk obligations that slipped to December 2027. Inside: Article 15 writes MITRE ATLAS and the OWASP LLM Top 10 into binding law, the DORA / NIS2 / AI Act overlap that makes one incident reportable three times, penalties up to 7% of global turnover, and the five things a CISO should do this week. Part 1 of 2.

Is your AI system secure enough? MITRE ATLAS Is Now Law.

For the first time anywhere, the MITRE ATLAS framework and the OWASP Top 10 for LLM applications are written into binding law. Article 15 names data poisoning, model poisoning, adversarial examples, model evasion and confidentiality attacks as threat classes you must have technical measures against—and must be able to evidence to a regulator. The question is no longer whether you have thought about AI security. It is whether you can prove your AI system holds.

Ep. 72 - The File That Lies: One CLAUDE.md Walks Off With Your Agent's Credentials

A poisoned CLAUDE.md file inside a cloned repository quietly tells a coding agent to send its test logs to an outside endpoint, and the agent complies, shipping environment details, internal system information, and API keys to a server the developer never controlled. The model was not broken. It was obedient. In this episode of The Cyber Resilience Brief (a SafeBreach podcast), host Tova Dvorin and SafeBreach senior sales engineer Adrian Culley break down why building agentic AI controls is not the same as proving they hold under attack.

MCP Security Risks: Trusting Tool Descriptions Without Standards

Are we trusting AI tools too much? Right now, agents trust tool descriptions without verification. This could lead to serious security risks! What happens when a major server gets compromised? It's time to rethink our standards for AI tool security. What do you think about AI trust issues?