Enterprise Security Weekly (Audio)

Ransomware, Agentic AI, and Supply Chain Risks: Insights from Black Hat 2025 - HD Moore, Jason Passwaters, J.J. Guy, Theresa Lanowitz, Mickey Bresman, Yuval Wollman, Jawahar “Jawa” Sivasankaran - ESW #423

12 snips
Sep 8, 2025
Join Doug White as he chats with a powerhouse lineup: Theresa Lanowitz from LevelBlue sheds light on the critical risks of software supply chains, while Yuval Wollman from CyberProof dives into how AI agents are reshaping cyber threats. Mickey Bresman of Semperis discusses the evolution of ransomware and extortion tactics. J.J. Guy explores asset visibility challenges, and Jason Passwaters emphasizes the need for precise threat intelligence. Together, they highlight the integration of AI and the increasing complexity of cybersecurity in today's digital landscape.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Software Supply Chain Has Exploded

  • The software supply chain now includes internal code, commercial software, open source, and rapidly growing AI-generated code.
  • That expansion multiplies attack surface and forces security to be a primary product consideration in 2025.
INSIGHT

AI Code Floods Repos With Low-Quality Packages

  • AI-generated code often lands in open-source repos as poorly tested or even empty packages.
  • Human review remains essential to catch defects, bloat, and performance regressions from AI outputs.
ADVICE

Demand SBOMs And Supplier Security Evidence

  • Build and maintain SBOMs and verify supplier security practices so you can trace components when vulnerabilities appear.
  • Prioritize visibility into where software comes from and require security evidence from third-party suppliers.
Get the Snipd Podcast app to discover more snips from this episode
Get the app