The Department of Know: Astra launches, CISA cuts programs, McKesson breached
Sep 4, 2026 · 34m
Summary
Host Rich Traolino joins CISOs Jonathan Waldrop and Montez Fitzpatrick to discuss the UK’s new tech vendor restrictions, the economic impact of AI on bug bounties, and the cost of porting PLC exploits. The trio also debates the severity of recent breaches at McKesson, a dark web ID service, and Thomson Reuters, ultimately agreeing that patient health data poses the greatest risk.
Topics discussed
Intro: Guests and Cybersecurity Awareness Month
Show intro, sponsor, and 'No or No' segment rules
No or No: Senator Wyden on commercial VPNs vs state actors
No or No: UK Cyber Resilience Bill and vendor bans
No or No: AI slop and the changing economics of bug bounties
No or No: Cost and time of porting PLC exploits with AI
Sponsor break: No Before AI security training
Deep Dive: New AI models, safety rules, and open letters
Deep Dive: CISA scaling back assessments vs Project WATERSHED
Deep Dive: Comparing the worst of three major data breaches
Outro: Thanks to guests, chat, and sponsors
Listen ad-free on Castria