S4E25 – AI agent accountability, learned helplessness, TeamPCP arrests, and Chinese router backdoors
The Adversarial Podcast
0:00 / 0:00
S4E25 – AI agent accountability, learned helplessness, TeamPCP arrests, and Chinese router backdoors
134 просмотра · 2 недели назад
The Adversarial Podcast
253 подписчика
134 просмотра · 2 недели назад
Jerry, Mario, and Sounil debate who is accountable when autonomous AI agents cross the line—and whether enterprise AI policies provide real governance or merely more paperwork. They examine a revealing CISA red-team report in which culture, alert fatigue, and learned helplessness separated two similarly equipped organizations; consider whether the alleged TeamPCP arrests will deter the next generation of hackers; and ask whether backdoors found in Chinese-made routers are espionage, careless engineering, or something in between.
00:00 AI Agents, Cyberattacks, and Escaping Containment
08:46 Who Is Accountable for Autonomous AI?
15:09 Do Companies Really Need an AI Policy?
31:58 What CISA’s Red-Team Report Reveals About Security Culture
44:50 TeamPCP Arrests and the Deterrence Question
52:32 Chinese Router Backdoors: Espionage or Careless Engineering?
Stories and resources
The Hugging Face Incident and the Road Ahead (https://openai.com/index/hugging-face...)
OpenAI explains how models undergoing cybersecurity evaluations escaped their isolation controls and compromised parts of OpenAI’s and Hugging Face’s infrastructure.
AI Agent Shared Responsibility Model (https://learn.microsoft.com/en-us/azu...)
Microsoft outlines how responsibility shifts among providers, organizations, and users as AI agents gain greater autonomy and access.
AI Management Systems: What Businesses Need to Know (https://www.iso.org/artificial-intell...)
ISO explains why effective AI governance requires continuously maintained policies, processes, controls, and clearly assigned accountability.
A Tale of Two SOCs: Insights From Two Red Team Assessments (https://www.cisa.gov/news-events/cybe...)
CISA compares two organizations that faced similar red-team attacks but produced dramatically different outcomes because of alert tuning, coordination, authority, and security culture.
Two Alleged “TeamPCP” Hackers Arrested in Australia (https://krebsonsecurity.com/2026/08/t...)
Australian authorities arrested two men allegedly connected to TeamPCP, a cybercrime group linked to malicious open-source software and cascading supply-chain attacks.
Chinese Implants in the Supply Chain (https://www.vulncheck.com/blog/zbt-da...)
VulnCheck found multiple factory-installed implants in ZBT router firmware that could provide unauthenticated remote access with root privileges.
Hosts: Jerry Perullo (Founder, https://adversarial.com/)
Sounil Yu (Founder, https://www.knostic.ai/)
Mario Duarte (CISO, https://www.whirlai.com/)
Producer: Tillson Galloway (Founder, http://githoundexplore.com/)