Hosts Rich Straelin, Dmitry Sokolovsky, and Christian Fresh discuss a trio of AI agent security incidents, including OpenAI Codex sandbox escapes and unauthorized data collection, emphasizing that human accountability is now paramount. They also analyze a joint advisory on North Korean IT worker scams and a critical GitLab vulnerability involving non-expiring tokens. The episode covers the UK NCSC’s new framework for quantifying AI defense risks, the rise of automated payment skimming, and CISA’s push to improve CVE data quality alongside Microsoft’s new integrated security operations center.