Zero days, zero order: The chaos reshaping vulnerability disclosure

Zero days, zero order: The chaos reshaping vulnerability disclosure

The rules of responsible disclosure were written for a different era — one where humans found bugs, humans reported them, and 90 days felt like plenty of time to patch. That era is over. In this episode, Greg sits down with Gal Elbaz, co-founder and CTO of Oligo Security, to unpack how AI-assisted vulnerability research is breaking the frameworks the security industry has relied on for decades. From MITRE admitting it can no longer keep up with the volume of CVE reports, to Linus Torvalds saying the same about the Linux kernel, the cracks in the system are impossible to ignore. Gal draws on his years as a hands-on researcher at Check Point — and his current work leading Oligo's research team — to offer perspective from both sides of the disclosure table. He and Greg dig into the Microsoft controversy, the tension between researcher leverage and community responsibility, and why the Spider-Man rule applies more than ever to the security research community right now. They also tackle the big questions: Should disclosure timelines be based on exploitability rather than a fixed number of days? Who owns the decision to accelerate a disclosure? And is it time to throw out CVSS scores and build something new? Gal's bottom line: the noise needs to be cut, the critical bugs need better definition, and both vendors and researchers need to get back to the table — as humans. For our reporter chat, Greg talked with Derek Johnson about the reaction to the Trump administration's fight with Anthropic.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(138)

Why the autonomous SOC Is the wrong goal

Why the autonomous SOC Is the wrong goal

On this week's episode, we're joined by Mike Nichols, General Manager of Security at Elastic, fresh off the Gartner Security and Risk Summit in the D.C. area, where AI dominated every conversation on ...

11 Kesä 33min

The last layer standing

The last layer standing

What happens when an "assume breach" scenario turns into a total corporate wipeout? In this episode of Safe Mode, host Greg welcomes Brandon Willitts, Director of Cyber Resilience at Everpure, to pull...

4 Kesä 35min

From Two Weeks to Three Days: The KEV Deadline Debate

From Two Weeks to Three Days: The KEV Deadline Debate

Drawing on his experience from his time in government working directly on CISA’s Known Exploited Vulnerabilities (KEV) catalog, Todd Beardsley, VP of Security Research at runZero, explains what it act...

29 Touko 37min

Can specialized security survive Daybreak and Mythos?

Can specialized security survive Daybreak and Mythos?

In this episode, we sit down with Lior Div, CEO of 7AI, at a moment when the ground is shifting under the entire security industry. With AI lowering the barrier to entry for attackers, supply chain co...

21 Touko 38min

Why access brokers have stubbornly remained successful

Why access brokers have stubbornly remained successful

Anna Pham of Huntress joins Safe Mode to discuss the current landscape of initial access brokers and how their tactics continue to support ransomware operations. She explains that attackers are still ...

14 Touko 31min

Can you prove which agent did what?

Can you prove which agent did what?

In this week's episode, Greg Otto talks with Howard Ting, CEO of Opal Security, about the growing security challenges created by AI agents inside the enterprise, especially around identity governance,...

7 Touko 28min

How government and Industry can raise the cost of cybercrime

How government and Industry can raise the cost of cybercrime

Sophos CEO Joe Levy and Director of Government Partnerships Alex Rose join Safe Mode from Washington, D.C. to discuss what meaningful public-private cybersecurity partnership looks like right now—movi...

30 Huhti 43min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
rss-podme-livebox
rss-ootsa-kuullut-tasta
rss-vaalirankkurit-podcast
ootsa-kuullut-tasta-2
otetaan-yhdet
et-sa-noin-voi-sanoo-esittaa
rss-raha-talous-ja-politiikka
tervo-halme
the-ulkopolitist
rss-kaikki-uusiksi
linda-maria
rikosmyytit
rss-mina-ukkola
rss-polikulaari-pitka-kiekko-ja-muut-ts-podcastit
rss-asiastudio
rss-ulkopoditiikkaa
rss-pinnalla