Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger

Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger

A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this special episode, Jeffrey Wheatman is joined by Bob Maley, Ferhat Dikbiyik, and Black Kite co-founder and CTO Candan Bolukbas to break down what Mythos and Project Glasswing actually change, and what they don't.

The numbers are already alarming. Forty-eight thousand CVEs published in 2025. A 43-day mean time to patch. An exploitation window that has gone negative, meaning threat actors are exploiting vulnerabilities an average of seven days before defenders even know they exist. Mythos accelerates vulnerability discovery, but as the team makes clear, discovering more vulnerabilities faster only matters if you have a program built to handle it.

In this episode, you will learn:

  • What Mythos and Project Glasswing actually are and why the hype may be outpacing the reality

  • Why the vulnerability deluge is already unmanageable with traditional CVSS-based prioritization

  • How the 135-day embargo window affects your third-party exposure

  • Why fourth-party risk, meaning what your vendors run rather than just who they are, is becoming the real blind spot

  • What SBOMs have to do with the future of supply chain vulnerability management

  • The three things security leaders should do right now to prepare their programs

This is not a theoretical conversation. It's the one your program needs before the window closes.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(23)

You Can't Say No to Your Vendors

You Can't Say No to Your Vendors

You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if levera...

29 Juli 41min

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why t...

15 Juli 33min

The #1 Mistake Boards Make on Cyber Risk

The #1 Mistake Boards Make on Cyber Risk

Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well...

1 Juli 32min

The Hidden Signals Predicting Vendor Collapse

The Hidden Signals Predicting Vendor Collapse

Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether for...

17 Juni 37min

Are You Measuring the Right Risks…Or Just the Easiest Ones?

Are You Measuring the Right Risks…Or Just the Easiest Ones?

Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and w...

20 Maj 31min

Why Automation Is Creating More Cyber Risk

Why Automation Is Creating More Cyber Risk

Automation vs Accuracy in TPCRM is one of the biggest challenges in modern third-party risk management. In this episode, we break down how the push for faster automation is impacting accuracy, and wha...

6 Maj 34min

How to Calculate the Real Cost of a Third-Party Breach

How to Calculate the Real Cost of a Third-Party Breach

Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how org...

22 Apr 40min

Populärt inom Teknik

uppgang-och-fall
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
market-makers
bli-saker-podden
 och-bilen-gar-bra
elbilsveckan
rss-uppgang-och-fall
rss-en-ai-till-kaffet
developers-mer-an-bara-kod
rss-veckans-ai
natets-morka-sida
hej-bruksbil
rss-milpodden
rss-technokratin
solcellskollens-podcast
rss-upplyst-entreprenordirektor
rss-it-sakerhetspodden
ai-sweden-podcast
rss-fabriken-2