A Conversation with Bar-El Tayouri from Mend.io

A Conversation with Bar-El Tayouri from Mend.io

➡ Get full visibility, risk insights, red teaming, and governance for your AI models, AI agents, RAGs, and more—so you can securely deploy AI powered applications with ul.live/mend

In this episode, I speak with Bar-El Tayouri, Head of AI Security at Mend.io, about the rapidly evolving landscape of application and AI security—especially as multi-agent systems and fuzzy interfaces redefine the attack surface.

We talk about:

• Modern AppSec Meets AI Agents
How traditional AppSec falls short when it comes to AI-era components like agents, MCP servers, system prompts, and model artifacts—and why security now depends on mapping, monitoring, and understanding this entire stack.

• Threat Discovery, Simulation, and Mitigation
How Mend’s AI security suite identifies unknown AI usage across an org, simulates dynamic attacks (like prompt injection via PDFs), and provides developers with precise, in-code guidance to reduce risk without slowing innovation.

• Why We’re Rethinking Identity, Risk, and Governance
Why securing AI systems isn’t just about new threats—it’s about re-implementing old lessons: identity access, separation of duties, and system modeling. And why every CISO needs to integrate security into the dev workflow instead of relying on blunt-force blocking.

Subscribe to the newsletter at:
https://danielmiessler.com/subscribe

Join the UL community at:
https://danielmiessler.com/upgrade

Follow on X:
https://x.com/danielmiessler

Follow on LinkedIn:
https://www.linkedin.com/in/danielmiessler

Chapters:

00:00 - From Game Hacking to AI Security: Barel’s Tech Journey
03:51 - Why Application Security Is Still the Most Exciting Challenge
04:39 - The Real AppSec Bottleneck: Prioritization, Not Detection
06:25 - Explosive Growth of AI Components Inside Applications
12:48 - Why MCP Servers Are a Massive Blind Spot in AI Security
15:02 - Guardrails Aren’t Keeping Up With Agent Power
16:15 - Why AI Security Is Maturing Faster Than Previous Tech Waves
20:59 - Traditional AppSec Tools Can’t Handle AI Risk Detection
26:01 - How Mend Maps, Discovers, and Simulates AI Threats
34:02 - What Ideal Customers Ask For When Securing AI
38:01 - Beyond Guardrails: Mend’s Guide Rails for In-Code Mitigation
41:49 - Multi-Agent Systems Are the Next Security Nightmare
45:47 - Final Advice for CISOs: Enable, Don’t Disable Developers

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Jaksot(532)

NO. 387 — Modern Parenting and Narcissism?, New Russian Hacking Unit, McKinsey AI Predictions, and more…

NO. 387 — Modern Parenting and Narcissism?, New Russian Hacking Unit, McKinsey AI Predictions, and more…

In this episode: 🧠 Is modern parenting creating narcissists?🔒 Top cybersecurity official warns of Chinese hackers🇷🇺 New Russian hacking unit identified🚀 NVIDIA's AI red team philosophy📈 McKinsey says AI will massively boost productivity💊 MDMA helps white supremacist move away from hate🔎 Google further soils the bedBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

20 Kesä 202324min

NO. 386 — DBIR 2023, Vision, Smol-Developer, and more…

NO. 386 — DBIR 2023, Vision, Smol-Developer, and more…

In this episode: 🔥 Human Immortality Using LLMs🤖 Generative AI Reshaping Enterprises🔒 Verizon DBIR 2023 Analysis🪳 Chrome Zero-Day Patched💰 Lazarus Atomic Wallet Link🚀 Tame Your Compliance Beast🪳 MOVEit Vulnerability Exploitation📰 North Korean Hackers Impersonate Journalists📱 Apple ID-sharing🌐 Apple Vision Announced🔑 Password Crackdown Success📈 AI-Driven Stock Surge📱 iOS17 Features Summary🔐 Apple Passkey SharingBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

12 Kesä 202326min

NO. 384 — World AI Coin, Russian Power Attacks, Guidance AI Workflow…

NO. 384 — World AI Coin, Russian Power Attacks, Guidance AI Workflow…

In this episode:👁️ Worldcoin, OpenAI, and eye scanning: A global ID and currency?⚡ Grid Threat: Russia-linked malware targets power grids🧠 Neuralink gets FDA approval for clinical trials🤖 Bing integrated into ChatGPT for enhanced AI chatbot experience🚗 Tesla Model Y becomes world's best-selling car🌈 LGBTQ searches soar 1,300% since 2004Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

3 Kesä 202321min

NO. 382 — AI Attack Surface Map, Digital Assistants, Dragos Nope, Rogue AI Girlfriend…

NO. 382 — AI Attack Surface Map, Digital Assistants, Dragos Nope, Rogue AI Girlfriend…

In this episode:🛡️ Support DEFCON's AI Village event🧠 Dive into AI attack surfaces🤖 Uncover digital assistants' future🔒 Investigate Dragos Incident & Snake takedown🎵 Experience Google's MusicLM magic🚀 Secure the cloud with a free guide👩‍💻 Witness an AI girlfriend gone rogueBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

16 Touko 202317min

The Right Amount of Trauma

The Right Amount of Trauma

In this standalone episode I read my essay titled "The Right Amount of Trauma". https://danielmiessler.com/blog/the-right-amount-of-trauma/   Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

11 Touko 20237min

NO: 381 — Reviving Conference Strategies, Nurturing High-Performers, AI Business Takeover, Cyber Threats, and Diversifying Production 🧠🏢🦈📱🚗

NO: 381 — Reviving Conference Strategies, Nurturing High-Performers, AI Business Takeover, Cyber Threats, and Diversifying Production 🧠🏢🦈📱🚗

🧠 The Right Amount of Trauma: Nurturing high-performers🏢 Universal Business Components: AI's business takeover🦈 North Korean ReconShark: New global cyber threat📱 Apple's Brazil production: Diversifying from China🚗 NYPD's AirTag advice: Protect your car💵 US dollar losing reserve currency status🤖 IBM's hiring pause: AI and automation's impact🌐 World Economic Forum: Job disruption predictions 📺 YouTube views: Half on TV📞 GenZ's dumbphone trend: Reducing distractions🌿 A Post AI Future for Humans: Local community model💡 The Self-checkout Tipping Anti-Pattern: Dark pattern or generosity?Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

9 Touko 202311min

NO. 380 — LLM-Mind-Reading, Automated War, Rusty Sudo, Eliezer Bitterness Theory...

NO. 380 — LLM-Mind-Reading, Automated War, Rusty Sudo, Eliezer Bitterness Theory...

📚 Pre and Post-LLM Software: Adapt or be replaced🎙️ RSnake Show Appearance: AI-focused conversation🔐 RSA Live Podcast: Industry insights and advice🔮 Palantir AI: Automated war and terror🍏 New Apple Update Mechanism: Rapid Security Response🧠 LLM Mind-reading: Extracting text from brain activity🚫 Chatbanning: Samsung's response to data leak🔧 VMware & Zyxel Patches: Addressing vulnerabilities🔒 Google Security AI: Cloud Security AI Workbench🦀 Sudo Rust: Safer sudo and su in Rust🎥 Palo Alto Cameras: License plate tracking🏃‍♂️ Apple Coach: AI-powered health app🏦 First Republic Falls: FDIC intervention💡 Eliezer Bitterness Theory: AI doomsday predictions🤖🔥 Prompting Superpower: Advanced AI prompting techniques🛠️ ShadowClone & FigmaChain: Useful tools🐍 Recommendation: Learn Python and Langchain💬 Aphorism: Carl Jung on creativityBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

2 Touko 202318min

NO. 378 — AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...

NO. 378 — AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...

NO. 378—AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

17 Huhti 202325min