Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Oops, OpenAI Hacked Australia's Health System - The 443 Podcast - Episode 389

This week on the podcast, we cover yet another rogue AI security incident that Australia's Prime Minister disclosed in front of the United Nations last week. Before that, we discuss an FBI alert on WaterPlum, a North Korean threat actor targeting IT professionals. Then, we cover the FBI themselves becoming a victim of cyberattack, this time by ShinyHunters.

Your Clients Already Deployed AI. Nobody Sold Them the Security for It.

Every vendor this year says the same thing: AI is transforming cybersecurity. True, and not useful. Here is the useful version. AI is doing two things at once. It is compressing the time between a vulnerability being found and being exploited, which is the part everyone talks about. And it is quietly installing a brand new attack surface inside your clients' businesses, which is the part nobody is selling against yet.

The AI Act Duty That Applies Regardless of Risk Tier

Almost every obligation in the AI Act is keyed to a risk classification. Work out which tier a system falls into and the duties follow. ‍ Article 4 is not. It applies to providers and deployers of any AI system whatever it does, its subject is people rather than systems, and national authorities began supervising and enforcing it from 2 August 2026 while the high-risk regime moved to December 2027. It is the live one, and it sits outside the structure most governance programs are built on. ‍

AI Review of Privileged Material and the Waiver Question

Sending privileged material through an external AI service is a disclosure to a third party, and voluntary disclosure to a third party waives privilege. The reasoning is straightforward and a federal court has now applied it. ‍ A second federal court reached the opposite conclusion on the same question within days, on a distinction the first did not draw. The position is genuinely unsettled, and the parts that are settled point at configuration choices rather than at a prohibition. ‍

What Google Gemini's Sandbox Escape Reveals About Securing APIs Against AI Agents

Recently, Gemini was running a capture-the-flag exercise in a sandbox operated by the AI testing firm Irregular. Its task was to steal data from a fictional company. On three occasions, the fictional target shared a name with a real business. Gemini slipped past the test’s containment, reached the open internet, and broke into the real company’s systems. In one case it guessed the password. In the other two, it pulled working credentials from a public database of leaked passwords.

One Identity: Governing Every Identity - Human, Machine, and AI

Every enterprise runs on identity — and machines and AI agents now outnumber people in many environments. This 2-minute overview covers why identity has become a board-level priority, and how One Identity governs every identity — human, machine, and AI agent — on one unified platform. Validated by Omdia: 150% ROI, go-live in as little as one day, zero-touch onboarding.

Phone Numbers as an Attack Surface: What SIM Swap and Data Leaks Actually Expose

The majority of security teams' work time is devoted to passive mitigation, password rotation, enabling multifactor authentication, or making authentication more complex and giving much more attention to the phone number in recovery than to other factors. Not a communication channel, but rather an identifier, as said, it's used in many aspects of tools, banking, and also e-mail, and when all thieves discover the methods of using it, that's when trouble arrives.

What Is Agentic AI Security? The 3 Layers and Their Owners

Two of the three layers of agentic AI security already have an owner in your organization, and the third has none. Identity falls to IAM and interaction falls to AppSec, because the controls at both layers extend products those teams already run. The behaviour layer covers what the agent does on the infrastructure once it is running, and it sits between a platform team with no security mandate and a SOC with no sense of what normal looks like for an agent. That gap is where a coerced agent works.

AI Agent Identity Security: Where an Agent's Baseline Lives

Identity governance cannot tell you which AI agent did something. It records which identity is allowed what. In a cluster, one service account often serves several workloads, and every pod is replaced at the next rollout. As a result, the permission record and the behavior record point at different objects. Detection and investigation need a unit of attribution. The Deployment is the right one. It stays stable across restarts and replicas and changes only when someone ships a rollout.