Security Weekly Podcast Network (Audio) Security Weekly Podcast Network (Audio)

RAM, Muse, CloudSyncD, Springsteen, Software, Persistence, and Michael Jenkins - Michael Jenkins - SWN #621

Oct 2, 2026 · 37m

Summary

Host Doug White covers a critical Cisco SD-WAN vulnerability and a new macOS backdoor delivered via a fake Zoom installer. He also discusses the suspension of Oxygen Forensics by UK police due to alleged Russian ownership and details a WordPress exploit using a "self-healing" persistence mechanism. In an interview with ThreatLocker CTO Michael Jenkins, they analyze how AI agents are enabling low-cost, mass-scale attacks on retailers, emphasizing the urgent need for zero-trust architectures and strict ring-fencing to limit the blast radius of compromised systems.

Topics discussed

Intro, episode 621, and show description Sponsor: Financial Services AI Security Forum CISA adds Cisco SD-WAN flaw to KEV; patching challenges Sponsor: InfoSec World 2026 macOS backdoor 'CloudSyncD' via fake Zoom installer Software provenance concerns: Oxygen Forensics and Russia WordPress 'SC' malware: self-healing mesh persistence Meta's Muse AI: trust, safety, and agentic risks Sponsor: ThreatLocker Zero Trust enforcement Interview intro: Michael Jenkins, CTO of ThreatLocker AI-driven attacks: $25 cost, 600k cards stolen Zero Trust principles: default deny and least privilege AI as a catalyst for Zero Trust adoption in SMBs Ring-fencing AI agents and controlling access Anecdotes on poor security hygiene and password exposure Starting Zero Trust: documentation and user education Security for home users and the future of AI threats Zero Trust World conference promotion and discount code RAM price surge and memory shortage outlook Outro and call to action
Listen ad-free on Castria