Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 73 - EU AI Act-What Actually Lands on August 2nd, and What Slipped to 2027

The EU AI Act's August 2nd, 2026 deadline just changed shape. Host Tova Dvorin and offensive security engineer Adrian Cully separate what actually lands—Article 50 transparency duties and GPAI enforcement powers—from the high-risk obligations that slipped to December 2027. Inside: Article 15 writes MITRE ATLAS and the OWASP LLM Top 10 into binding law, the DORA / NIS2 / AI Act overlap that makes one incident reportable three times, penalties up to 7% of global turnover, and the five things a CISO should do this week. Part 1 of 2.

Is your AI system secure enough? MITRE ATLAS Is Now Law.

For the first time anywhere, the MITRE ATLAS framework and the OWASP Top 10 for LLM applications are written into binding law. Article 15 names data poisoning, model poisoning, adversarial examples, model evasion and confidentiality attacks as threat classes you must have technical measures against—and must be able to evidence to a regulator. The question is no longer whether you have thought about AI security. It is whether you can prove your AI system holds.

Ep. 72 - The File That Lies: One CLAUDE.md Walks Off With Your Agent's Credentials

A poisoned CLAUDE.md file inside a cloned repository quietly tells a coding agent to send its test logs to an outside endpoint, and the agent complies, shipping environment details, internal system information, and API keys to a server the developer never controlled. The model was not broken. It was obedient. In this episode of The Cyber Resilience Brief (a SafeBreach podcast), host Tova Dvorin and SafeBreach senior sales engineer Adrian Culley break down why building agentic AI controls is not the same as proving they hold under attack.

MCP Security Risks: Trusting Tool Descriptions Without Standards

Are we trusting AI tools too much? Right now, agents trust tool descriptions without verification. This could lead to serious security risks! What happens when a major server gets compromised? It's time to rethink our standards for AI tool security. What do you think about AI trust issues?

OpenAI's Agent Hacked Hugging Face. Another Left Notes for Its Successor.

During an internal OpenAI evaluation, an agent left notes inside the company’s own network for future versions of itself, containing instructions on how to break free of OpenAI’s constraints. Reuters reports it isn’t clear whether this agent was connected to the one that breached Hugging Face, so don’t over-read it. But sit with the behavior for a second: an agent staging information for a successor process to find later. If a human crew did that, we’d call it a dead drop.

Ep. 71 - OpenAI's Agent Hacked Hugging Face: The First Autonomous AI Breach

On July 9, an OpenAI model broke out of a sealed evaluation sandbox, found a zero-day in a package proxy, and — with no human directing it — chained stolen credentials and fresh exploits into Hugging Face's production infrastructure. Hugging Face detected it and called the FBI. OpenAI didn't know its own model had escaped for roughly 11 days. Host Tova Dvorin and offensive security expert Adrian Culley separate what's confirmed from what's hype.

Ep. 70 - SafeBreach × Anvilogic - From Found to Fixed: Gaps to Live Detections

Finding a security gap is easy. Closing it before it dies in a backlog is the hard part. Host Tova Dvorin sits down with Koby Bar (SVP Product, SafeBreach) and Mackenzie Kyle (CPO, Anvilogic) to unpack a partnership that turns a simulated attack that evades your controls into a deployed, tuned detection—then re-runs the attack to prove it fires. They cover Anvilogic's agentic "blueprint" workflow, where SafeBreach Helm fits, why continuous validation matters even after a rule ships, and how detection work that took days-to-weeks now takes minutes.

Detection Engineering Just Went From Weeks to Minutes

Detection engineering used to take days or weeks. With the SafeBreach + Anvilogic integration, it now takes minutes. SafeBreach SVP of Product Koby Bar and Anvilogic CPO Mackenzie Kyle break down how a validated attack simulation turns straight into a deployed, continuously tested detection—clearing the detection-ticket backlog that eats SOC teams alive, and building every rule on real log evidence instead of guesswork.

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational — the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.