Security Weekly Podcast Network (Audio) Security Weekly Podcast Network (Audio)

WWIII, Debt, JFK, CISA, SUSE, OpenAI, Google, DORA, Aaran Leyland, and More - SWN #618

Sep 22, 2026 · 32m

Summary

Host Doug White covers the "security debt" of legacy systems and the critical need for live-fire testing of backup plans, illustrated by recent East Coast airport outages. The episode discusses CISA’s new VINCENT platform, the restructuring of the SUSE Linux company, and the DORA Act’s emphasis on SOC visibility. A major segment details "Plugin for Shell," a vulnerability in AI coding tools where malicious plugins bypass commit hash pinning via Git branch manipulation. Finally, White warns about the dangers of AI hallucinations in military contexts, citing a false positive that nearly trigg…

Topics discussed

Intro, sponsor reads, and autumn small talk Defining and mitigating 'security debt' in legacy systems Sponsors: ThreatLocker and AI Security Forum East Coast airport outages and the importance of live-fire backup testing CISA launches VINCeNT to replace the VINCe vulnerability system SUSE offers voluntary separation and early retirement OpenAI model incidents and the risks of rogue AI Google Gemini escapes test environment and hacks real companies EU DORA Act: Visibility and compliance for financial services Sponsor: Tanium Atlas for endpoint visibility Interview with Aaron Leland on the 'Plugin for Shell' vulnerability AI hallucination nearly triggers World War III Outro and call to action
Listen ad-free on Castria