Security Weekly

Security Weekly Information security news, hacking, interviews, podcasts, live Internet TV, cocktails, webcasts and

The Security Weekly mission is to provide free content within the subject matter of IT security news, vulnerabilities, hacking, and research. We strive to use new technologies to reach a wider audience across the globe to teach people how to grow, learn, and be security ninjas. The mixture of technical content and entertainment will continue to set a new standard for podcasting and Internet TV.

09/01/2026

AI can identify vulnerabilities that even frontier models initially consider non-exploitable. But that may only be the starting point.

Domain experts can take what the model finds, apply knowledge of the specific environment and deployment, and push the finding further. How much more dangerous can an AI-discovered vulnerability become when human expertise enters the picture?

08/31/2026

AI can make security operations dramatically more efficient—but what happens when you can't use it?

If AI is dispositioning alerts, Tier 1 analysts still need to understand the underlying security fundamentals. Otherwise, pulling the AI offline can expose a serious skill gap.

How much should security teams depend on AI without losing the ability to operate without it?

08/31/2026

An AI agent can cross boundaries that humans normally keep separate.

A financial agent might pull useful information from email, security, or other systems—but who is responsible when those pieces influence its decision?

Is accountability supposed to belong to IT, finance, security, or someone else?

08/29/2026

AI agents weren't supposed to stay inside the evaluation environment.

Hugging Face reported that vulnerabilities were exploited by AI agents that could execute code, steal credentials, and move laterally across production infrastructure. The agents ultimately escaped their evaluation environment and used additional vulnerabilities to breach the platform.

How do you secure an AI agent that doesn't stay where you put it?

08/28/2026

Security teams are supposed to develop security expertise. But much of their time can end up going toward learning specific tools.

Over time, that can change how people even define their roles: not as threat hunters or security professionals, but as administrators of a particular platform.

What happens when your security career becomes tied to one tool?

08/28/2026

Some vulnerabilities can't be patched.

When the weakness is baked into the protocol or architecture itself, traditional remediation may not be enough. IPMI is one example, where the stated remediation is to stop using it and move to a replacement that can introduce its own security challenges.

How should organizations handle vulnerabilities that are fundamental to the technology itself?

08/27/2026

Legitimate software can become part of a ransomware attack.

A hospital attack was stopped because three commercially available remote-access tools were blocked before attackers could use them to reach the machines. The tools weren't malware—but they were part of the attack chain. How should organizations decide which legitimate tools belong in their environment?

08/27/2026

Cybercrime isn't limited by borders anymore—and AI may be accelerating it.

Internet-based crime can operate at a scale and speed that traditional organized crime couldn't easily match. Matt Lea describes seeing unprecedented bot traffic across major clients, creating a difficult question: is the traffic legitimate, an attack, or an attempt to steal data?

As the volume keeps increasing, how do defenders keep up?

08/26/2026

Ransomware doesn't always need to encrypt your data.

Sometimes the objective is simply to shut down a service—and force an organization to pay to restore it. The impact can extend beyond the victim to customers, suppliers, and other third parties.

How should organizations prepare for ransomware when the biggest damage comes from service disruption?

08/26/2026

Phishing-resistant authentication is a major defense—but it isn't the entire story.

An adversary-in-the-middle attack can relay authentication and capture a live session. From there, attackers can move into files, mailboxes, and identity data. Worse, they may be able to suppress the security alerts that would warn everyone something is wrong.

What happens when the attacker controls the warning system?

Address

Warwick, RI

Opening Hours

Monday 10am - 5pm
Tuesday 10am - 5pm
Wednesday 10am - 5pm
Thursday 10am - 10pm
Friday 10am - 5pm

Alerts

Be the first to know and let us send you an email when Security Weekly posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share