
20.8K
Downloads
87
Episodes
Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more!
Join us monthly for an interactive Cyberside Chats: Live!
Youtube channel: https://www.youtube.com/LMGsecurity
Register Here: https://lmgsecurity.zoom.us/webinar/register/WN_4FpdxB0VQo6aURK1p7_k_g
Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more!
Join us monthly for an interactive Cyberside Chats: Live!
Youtube channel: https://www.youtube.com/LMGsecurity
Register Here: https://lmgsecurity.zoom.us/webinar/register/WN_4FpdxB0VQo6aURK1p7_k_g
Episodes

8 hours ago
Outpaced: What AI Did to the Attack Clock
8 hours ago
8 hours ago
16 min
Palo Alto Networks’ Unit 42 investigated an intrusion where the attacker used AI agents to carry out the attack — and compressed work a human team would have needed more than two weeks to do into just under ten hours, using more than 50 MITRE ATT&CK techniques.
Sherri Davidoff and Matt Durrin unpack what actually happened, starting with a correction: despite the headlines, this was not an autonomous AI. A human directed it. They walk the chain from a breached public website through sub-agents harvesting hard-coded tokens out of code repositories, into the secrets manager, and finally to the attacker turning the victim’s own AI endpoints into attack infrastructure — using the company’s compute power against it.
Along the way: why an attempted backdoor in Terraform configurations was the most alarming move in the intrusion, why branch protection stopped an attacker who already held master admin credentials, and why the tactic adversaries use to slip past AI guardrails looks a lot like a Russian ransomware gang’s fake IT recruitment scheme.
The thesis isn’t that AI went rogue. It’s that the clock changed, and incident response plans built for a two-week dwell time are now built for the wrong attack.
Key Takeaways:
- Make every key and token in your environment expire. They will not get rotated by default. Set expirations so they cannot stay invisible forever, and track them.
- Require a second layer of approval for critical infrastructure changes. Branch protection stopped this attacker after they already held master admin credentials. Logging and monitoring are good; prevention is better.
- Give every AI service in your environment a named owner. Somebody has to be managing the keys and controlling it, so you know where it is.
- Apply the same controls to your vendors and MSPs. Work these into your next review cycle: how do they manage keys and tokens, do they scan for secrets, do they require second approvals?
- Run a tabletop against a ten-hour clock. Find out who can actually cut off access to a primary system — who can take it offline, when, and what they need to do it.
Resources:
- Unit 42, “An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation” — https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/
- Anthropic, “Countering misuse of AI: September 2026” — https://www.anthropic.com/threat-intelligence-report-september-2026
- GitGuardian, “The State of Secrets Sprawl 2026” — https://blog.gitguardian.com/the-state-of-secrets-sprawl-2026/
- Tom Pohl (LMG Security), “Private Keys in Public Places,” DEF CON 31 — https://www.lmgsecurity.com/resources/private-keys-in-public-places-defcon-2023-presentation/
- Video of the talk — https://www.youtube.com/watch?v=7t_ntuSXniw
8 hours ago
16 min

No comments yet. Be the first to say something!