WWIII, Debt, JFK, CISA, SUSE, OpenAI, Google, DORA, Aaran Leyland, and More - SWN #618
Sep 22, 2026 · 32m
Summary
Host Doug White covers the "security debt" of legacy systems and the critical need for live-fire testing of backup plans, illustrated by recent East Coast airport outages. The episode discusses CISA’s new VINCENT platform, the restructuring of the SUSE Linux company, and the DORA Act’s emphasis on SOC visibility. A major segment details "Plugin for Shell," a vulnerability in AI coding tools where malicious plugins bypass commit hash pinning via Git branch manipulation. Finally, White warns about the dangers of AI hallucinations in military contexts, citing a false positive that nearly trigg…
Topics discussed
Intro, sponsor reads, and autumn small talk
Defining and mitigating 'security debt' in legacy systems
Sponsors: ThreatLocker and AI Security Forum
East Coast airport outages and the importance of live-fire backup testing
CISA launches VINCeNT to replace the VINCe vulnerability system
SUSE offers voluntary separation and early retirement
OpenAI model incidents and the risks of rogue AI
Google Gemini escapes test environment and hacks real companies
EU DORA Act: Visibility and compliance for financial services
Sponsor: Tanium Atlas for endpoint visibility
Interview with Aaron Leland on the 'Plugin for Shell' vulnerability
AI hallucination nearly triggers World War III
Outro and call to action
Listen ad-free on Castria