Перейти к содержимому

S4E25 – AI agent accountability, learned helplessness, TeamPCP arrests, and Chinese router backdoors

The Adversarial Podcast

0:00 / 0:00

S4E25 – AI agent accountability, learned helplessness, TeamPCP arrests, and Chinese router backdoors

134 просмотра · 2 недели назад
The Adversarial Podcast
253 подписчика
134 просмотра · 2 недели назад
Jerry, Mario, and Sounil debate who is accountable when autonomous AI agents cross the line—and whether enterprise AI policies provide real governance or merely more paperwork. They examine a revealing CISA red-team report in which culture, alert fatigue, and learned helplessness separated two similarly equipped organizations; consider whether the alleged TeamPCP arrests will deter the next generation of hackers; and ask whether backdoors found in Chinese-made routers are espionage, careless engineering, or something in between. 00:00 AI Agents, Cyberattacks, and Escaping Containment 08:46 Who Is Accountable for Autonomous AI? 15:09 Do Companies Really Need an AI Policy? 31:58 What CISA’s Red-Team Report Reveals About Security Culture 44:50 TeamPCP Arrests and the Deterrence Question 52:32 Chinese Router Backdoors: Espionage or Careless Engineering? Stories and resources The Hugging Face Incident and the Road Ahead (https://openai.com/index/hugging-face...) OpenAI explains how models undergoing cybersecurity evaluations escaped their isolation controls and compromised parts of OpenAI’s and Hugging Face’s infrastructure. AI Agent Shared Responsibility Model (https://learn.microsoft.com/en-us/azu...) Microsoft outlines how responsibility shifts among providers, organizations, and users as AI agents gain greater autonomy and access. AI Management Systems: What Businesses Need to Know (https://www.iso.org/artificial-intell...) ISO explains why effective AI governance requires continuously maintained policies, processes, controls, and clearly assigned accountability. A Tale of Two SOCs: Insights From Two Red Team Assessments (https://www.cisa.gov/news-events/cybe...) CISA compares two organizations that faced similar red-team attacks but produced dramatically different outcomes because of alert tuning, coordination, authority, and security culture. Two Alleged “TeamPCP” Hackers Arrested in Australia (https://krebsonsecurity.com/2026/08/t...) Australian authorities arrested two men allegedly connected to TeamPCP, a cybercrime group linked to malicious open-source software and cascading supply-chain attacks. Chinese Implants in the Supply Chain (https://www.vulncheck.com/blog/zbt-da...) VulnCheck found multiple factory-installed implants in ZBT router firmware that could provide unauthenticated remote access with root privileges. Hosts: Jerry Perullo (Founder, https://adversarial.com/) Sounil Yu (Founder, https://www.knostic.ai/) Mario Duarte (CISO, https://www.whirlai.com/) Producer: Tillson Galloway (Founder, http://githoundexplore.com/)