RAM, Muse, CloudSyncD, Springsteen, Software, Persistence, and Michael Jenkins - Michael Jenkins - SWN #621
Oct 2, 2026 · 37m
Summary
Host Doug White covers a critical Cisco SD-WAN vulnerability and a new macOS backdoor delivered via a fake Zoom installer. He also discusses the suspension of Oxygen Forensics by UK police due to alleged Russian ownership and details a WordPress exploit using a "self-healing" persistence mechanism. In an interview with ThreatLocker CTO Michael Jenkins, they analyze how AI agents are enabling low-cost, mass-scale attacks on retailers, emphasizing the urgent need for zero-trust architectures and strict ring-fencing to limit the blast radius of compromised systems.
Topics discussed
Intro, episode 621, and show description
Sponsor: Financial Services AI Security Forum
CISA adds Cisco SD-WAN flaw to KEV; patching challenges
Sponsor: InfoSec World 2026
macOS backdoor 'CloudSyncD' via fake Zoom installer
Software provenance concerns: Oxygen Forensics and Russia
WordPress 'SC' malware: self-healing mesh persistence
Meta's Muse AI: trust, safety, and agentic risks
Sponsor: ThreatLocker Zero Trust enforcement
Interview intro: Michael Jenkins, CTO of ThreatLocker
AI-driven attacks: $25 cost, 600k cards stolen
Zero Trust principles: default deny and least privilege
AI as a catalyst for Zero Trust adoption in SMBs
Ring-fencing AI agents and controlling access
Anecdotes on poor security hygiene and password exposure
Starting Zero Trust: documentation and user education
Security for home users and the future of AI threats
Zero Trust World conference promotion and discount code
RAM price surge and memory shortage outlook
Outro and call to action
Listen ad-free on Castria