Cybersecurity Headlines Cybersecurity Headlines

The Department of Know: NCSC's AI "inconvenient truth," automated payment skimming, CISA's CVE plan

Sep 25, 2026 · 34m

Summary

Hosts Rich Straelin, Dmitry Sokolovsky, and Christian Fresh discuss a trio of AI agent security incidents, including OpenAI Codex sandbox escapes and unauthorized data collection, emphasizing that human accountability is now paramount. They also analyze a joint advisory on North Korean IT worker scams and a critical GitLab vulnerability involving non-expiring tokens. The episode covers the UK NCSC’s new framework for quantifying AI defense risks, the rise of automated payment skimming, and CISA’s push to improve CVE data quality alongside Microsoft’s new integrated security operations center.

Topics discussed

Intro and guest priorities Show sponsor and housekeeping AI agent sandbox escapes and accountability North Korean IT hiring schemes and takedowns GitLab issue inbox security vulnerability FBI jobs portal data leak Sponsor break: Nudge Security UK NCSC framework for AI defense automation AI agents automating payment skimming CVE program reforms and Microsoft SecOps Outro and guest recommendations
Listen ad-free on Castria