Uploaded August 2026 | Updated September 2026, 2 weeks ago
This week:
- When you are not at summer camp you can't read about it
- The Fettle continues
- Using the CFAA against AI
- Social contracts are not security models
- VSCode extentions, again
- Bugtraq is back!
- NVIDA, LVFS, and unraveling AI infrastructure
- More routers that come with backdoors
- Do we care about LPE?
- Even more AI that finds vulnerabilities
- When AI breaks its own guardrails
Visit securityweekly.com/psw for all the latest episodes!
Show Notes: securityweekly.com/psw-938
00:00:00 Welcome to PSW, Guest Intro, and Event Announcements
00:03:02 Why AI Dominates Cybersecurity News and Black Hat
00:09:30 Optimistic Outlook: AI's Role in Vulnerability Management and Fettle
00:21:46 The Challenge of AI Guardrails and Open Source Models
00:31:12 The Complexities of AI Hardware, Firmware, and Supply Chain
00:41:14 The Nostalgic Return of the Bugtraq Mailing List
00:50:44 Incentives: Bug Bounties, AI Slop, and Responsible Disclosure
01:04:36 Malicious VS Code Extensions and the Supply Chain Problem
01:23:41 Prioritizing Local Privilege Escalation in Today's Threat Landscape
01:35:10 How Big Players Use Context for Smarter Security Decisions
01:38:59 Analyzing Accenture's Integration of RunZero, Dragos, and Netrise
01:51:49 Palo Alto's Acquisition Strategy and Episode Wrap-up
This week:
- When you are not at summer camp you can't read about it
- The Fettle continues
- Using the CFAA against AI
- Social contracts are not security models
- VSCode extentions, again
- Bugtraq is back!
- NVIDA, LVFS, and unraveling AI infrastructure
- More routers that come with backdoors
- Do we care about LPE?
- Even more AI that finds vulnerabilities
- When AI breaks its own guardrails
Visit securityweekly.com/psw for all the latest episodes!
Show Notes: securityweekly.com/psw-938
00:00:00 Welcome to PSW, Guest Intro, and Event Announcements
00:03:02 Why AI Dominates Cybersecurity News and Black Hat
00:09:30 Optimistic Outlook: AI's Role in Vulnerability Management and Fettle
00:21:46 The Challenge of AI Guardrails and Open Source Models
00:31:12 The Complexities of AI Hardware, Firmware, and Supply Chain
00:41:14 The Nostalgic Return of the Bugtraq Mailing List
00:50:44 Incentives: Bug Bounties, AI Slop, and Responsible Disclosure
01:04:36 Malicious VS Code Extensions and the Supply Chain Problem
01:23:41 Prioritizing Local Privilege Escalation in Today's Threat Landscape
01:35:10 How Big Players Use Context for Smarter Security Decisions
01:38:59 Analyzing Accenture's Integration of RunZero, Dragos, and Netrise
01:51:49 Palo Alto's Acquisition Strategy and Episode Wrap-up










