Transcription
It seems like cyber security is top of mind for all the major AI players today. Why and why now?
Like now the scare factor of hey with this autonomous AI, what's going to happen to our customers? What's going to happen to us as a company? And how is this really going to affect us downstream?
Hello and welcome to Security Intelligence, IBM's weekly cyber security podcast, where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your host, Matt Kazinski, and joining me this week, as you've seen, we've got Dustin Evilmog Haywood, Ex-Force Executive, managing hacker, and senior technical staff member. We've got Kimmy Farington, security detection engineer. And making his podcast debut, Omari Jones, strategic threat analyst. Thank you folks for being here today. We're going to be talking about the Coalition for Secure AI's framework for AI identities and copy fail, a newly discovered Linux flaw with a potentially massive blast radius.
But first, I want to keep talking to you all about what CrowdStrike has called cyber security's Y2K moment. Cyber security has been a huge focus for the Frontier AI labs these days. A mythos and GPT 5.4 Cyber shook things up a couple weeks ago. Enthropic has released clawed security, previously known as clawed code security into public beta for enterprise customers. Uh this basically lets them use Opus 4.7 to scan their code bases. Uh so it's not quite mythos, but you know it's it's interesting. Uh on the very same day, OpenAI dropped a new five-point plan to strengthen AI powered cyber defense called, and this is a real mouthful, cyber security in the intelligence age. An action plan for democratizing AI powered cyber defense. And lastly, Crowdstrike announced a project project quillrill works they're calling it, which is a coalition of ecosystem partners, including IBM and OpenAI, working to help organizations assess, prioritize, and continuously remediate the wave of vulnerabilities in production code now being discovered by frontier AI models.
Right. So, there's a reason I'm packaging >> Exactly. Right. There's a reason, Kimmy. There's a reason I'm packaging all of this together in this huge chunk. age because I really feel like these all illustrate different facets of a theme that we've been seeing emerging here which is that all the top players in cyber in AI right now are really really focused on cyber security and not just focused on cyber security but focused on putting forth this idea that it's an ecosystem level problem. It's something we have to work on together. It's going to require collaboration, right? And and to go back to the beginning of this very segment, I mentioned that that CrowdStrike in announcing Quilt Works had called this quote cyber security's Y2K moment, which is very interesting to me. So, I want to start there, and I'm going to throw to you first, Kimmy. Do you think it's accurate to call this a Y2K moment for cyber security? Yes or no? And what's it got you thinking about?
Well, first I want to comment on Quilt Works. after you rolled out that big long description of what all the things are going to be doing, Quilt Works to me sort of sums it all up perfectly. Um, good job CrowdStrike and I feel like they were kind of leading the pack in their um, approach towards AI governance within the EDR also. Um, but is this the Y2K moment? I mean, okay, if you're comparing it to the everyone just suddenly woke up and realized there's going to be an issue, then yeah, we're there, you know, like, but why is it this moment? I'm not really sure exactly. I think it's because the CEOs, the executive levels have finally embraced AI. They see what it can do, but now they're also suddenly realizing what an attack surface it could end up being.
No, it makes perfect sense. And I want to Dustin, I want to circle back around to you. So, I want to get your take. I mean, when you're looking at this, do you think this is a a Y2K moment for cyber security?
Yes and no. And I mean, I've got an interesting um take on all of this. Um my big problem I've got is we're all talking about, oh, we didn't go patch or oh my god, the criminals get access to all these various tools, etc. Here's the thing. They're already accessing these tools, but they're using to create what I call slot reports in various repos. I just got slammed by yet another startup with a whole bunch of code into a major password cracking repo with a 7-day disclosure which is completely different from that 30 60 90 that we normally do in the industry.
A very kind of common approach that we're seeing now is this coalitional approach, right? This idea that we've got to do it together. It's an ecosystem level thing. You can't do it on your own. Uh you know, we saw that with Project Glass Wing when when Claude uh Anthropic rolled out Claude Mythos. We're seeing that with Quilt Works now. Omari, I want to get your take on this this, you know, really collaborative approach we're seeing to cyber security, the age of AI. What's your take on that? Do you think that's the right way to go? Do you trust in it? How do you feel?
Me personally, I like the coalition aspect to it. And it's more so because when you have companies like Crowd Strike, IBM, Open AI, all coming together, it's no longer solely about the business, solely about, you know, protecting our clients, but it's more so about affecting the entire ecosystem. It's you know it starts going beyond like focusing on like a muscular level of what's going on you know in the business and more so how do we actually stop these attacks or minimize the attacks propagating downstream which you know then affects like those overlapping clients where they may be using IBM services for one aspect and then also utilizing let's say like AWS or a different company it's you're starting to eliminate stuff at the like top level and then that minimizes like that downstream impact. It minimizes the overall like attack posture for both businesses, their clients and just overall like a good effort going on.
I like your take on that, Omari. The the concept that the coalition is sort of more altruistic than capitalistic if you will and I I I support that. Yeah. Well, because it also becomes a thing of for organizations, it's we're kind of saving money for ourselves as well as our clients in the aspect of by minimizing like the downstream impact brought in by let's say like automation of you know attacks and everything from AI like the the organization is doing better you know the company like the clients are succeeding more and that overall like impact It's it's minimized.
The thing I'm seeing here now is we're starting to discover the actual cost of implementing AI. Tokens have real tangible costs and there's companies now hiring junior developers to start writing boilerplate code because all the expensive tokens are being spent on vulnerability discovery. All I'm seeing is the fact that we are now increasing the speed at which we're discovering vulnerabilities. We haven't increased the staffing levels to defend against it. So people are here as it's not a tech problem now we're running into. we're into a staffing problem and it's now being exacerbated by all these various um workforce reductions we've seen in the last year.
Yeah. And I think a lot of what's coming out here is there is like this this there's this real tension in this whole situation where like we can talk about the sort of altruistic mode of collaboration and coalition and a lot and I think we all kind of genuinely believe in that and I think the organizations doing it also genuinely believe in that. Uh but there's also there are more call them mercenary calculations here, right? Like Evilmog said tokens cost a lot. You know what I mean? So it's like there's a little bit of a tension between and this is you know this is kind of uh AI in a nutshell in a lot of ways. How much is branding? How much is real? Where do you draw the line? I don't know that any of us can answer that for sure but I do think it's what we have to wrestle with especially at this particular moment when so many people are launching into these collaborative big coalitional approaches.
Speaking of those approaches though, we've two we've seen two slightly different ways of tackling them, right? And I think, you know, on the one hand, you've got the really locked down version of like project uh glass wing where it's like only certain people are allowed in, only certain people can use mythos and you have and that's that and then you have these broader ones where like you know quilt works is more about presenting a suite of services and solutions to people who so they can access them. You also have open AI when they rolled out GPT 5.4 for cyber uh you know they did it with this anybody could access it as long as they could prove that they were like a cyber security professional with good intentions. Um evil Mog I want to get your take on on these kinds of different approaches that the on the one hand more open on the one hand more closed any thoughts on on on where you see the most value like what kind of coalitional approach you'd like to see any takes there
so don't get me wrong I'd love to see the closed source route and keep everything contained but that's not going to happen. There's that clock out there floating around and last time I checked it, which is a couple weeks ago, there's what 228 days before people get methos level capabilities in the open weight models. There's some new models I saw drop last week that are just as capable and you can get methos level effects by going one source code file at a time in a standard loop. So those capabilities are already out there and that kind of yeah, that's what's driving the AI slop. So yeah, the coalition is going to work, but I'm pretty sure the open models will catch up really quickly.
It's the nature of open source. It's the nature of of of development in general right now, right? And I mean, we want to build the tool. We want to share the tool because we don't want to have to rebuild the tool, right?
Um I absolutely, you know, I agree with that and and I wish that we could kind of keep talking about this. We could spend frankly like I think an hour on this topic alone. I do have to move us along though. Uh before I do that though, Amomar, I just want to throw to you. Any last thoughts on on on what we're seeing here today with with cyber security's Y2K moment? anything you wanted to add before we move on?
You know, you have coalitions being built, which is great, but just like he was noting on, I mean, you take these open- source models, they don't have that same staffing issue as these companies do with like their DevOps teams and stuff like that. So honestly like I'm I'm right on I'm right on the coattails of I'm kind of excited to see what the open source models look like as well and just what kind of like what impact that has to you know the broader like field.
Absolutely. No I think there are a lot of questions there. Um so we got to move on though unfortunately. Uh I do want to though throw it out to the viewers the listeners if you're watching this on YouTube that comment section is open. If you have thoughts on cyber security's Y2K moment, drop it, man. I'm going to be reading those those comments. So, so tell us what you're thinking. Uh, but we have to move on now to our second story for this week. This is the Coalition for Secure AI's framework for AI identity and access control. Agents, as we all know, don't really slot very neatly into our pre-existing identity models. uh and this has caused quite a few headaches around permissions, accountability, monitoring and more. Uh so the coalition proposes an extended IM model adapted for the unique challenges of agents. Uh some of the key principles include giving them distinct identities meaning no borrowed credentials or shared accounts uh for agents. No zero standing zero standing privileges for the agents. Don't don't give them any standing privileges. uh traceable chains of authority when agents act on behalf of people and security controls at every single hop, every single touch point, every time that agent hits a new tool.
Amari, let me start with you. Initial reactions, thoughts on this framework for AI agent identity, what are you looking at? What's it bringing up for you? How do you feel?
So in terms of initial thoughts when I was like going through reading the sources I think like that college brain kicked in for me and I was like okay this is kind of like row base access control zero trust architecture and then just like evil just said I mean I was looking at it I was like yeah like these tokens cost money like organizations you know they're not assigning AI agents these you like unique credentials because that cost the business more money but then when you see you know large operations start to propagate within in an environment it's like well who actually deployed this AI who triggered this workflow and you don't have like the user strings you don't have like the log retention and it's kind of to me creating like that perfect storm of well you know you don't have the log retention to actually see who was executing the workflows and what was going on in the environment then even if you did well those AI agents there's no one who it's like uniquely attributed to so now we have like you know for companies who are pushing hard for automation with AI. Well, when things start to break and stuff goes down, who actually executed this workflow? Like, who was the dev behind the trigger? And when you don't know, it's like, well, that's kind of like the gotcha moment cuz now, well, how do you start to filter out all the noise of who successfully or who on our dev team executed this workflow and who's the possible malicious actor who, you know, is now using some type of AI scanning tool or something like that to actually go onto an environment and like Yeah. How do how do you start to differentiate stuff without any type of attribution?
Yeah, the the accountability problem has been something that I've been like really thinking about ever since the kind of agents hit the scene. It's like you said, Amari, how do you if you can't trace it back or even if you can like whose fault is it when things go ary with an agent? You know, is it is it is it my fault cuz I set the agent up or is it the agent's fault cuz it did things I didn't anticipate it to? I always come back to something that Evilmog you said on the show a while back, which is that like if my agent hacks the Canadian government, I'm going to jail. You know what I mean? Like that's the that's the accountability model. Um, so I want to bring you in here, you know, looking at this framework for AI agent identity, what's it got you thinking about? What's your initial reactions there?
Okay, so this is an interesting one in that for the longest time there's no intentbased assertation behind agent. Like if I make a customer service chatbot, I'm going to assume it's readon, answer a couple questions, and go away. But if it's got rewrite access to my database, for example, and all of a sudden I can get it to go give me other, you know, actions. It's now I've created an insider threat. So we need to work on you know, a what are these agents allowed to do from a corporate level, but then b you have their agent, you have the agent on behalf of the user. Really, the extended IM piece has been a mess and the identity problems been the primary issue between AI since its inception. So, I'm glad to see we're finally working on it. The devil will always be in the details.
Absolutely. And and and uh, you know, to follow up there, what details do you feel like you're you're really looking at? Where do you think the devil might pop up here? Any thoughts on that?
Well, it comes down to say a cryptographic chain of um authority, right? Like as you said earlier, is this bot authorized to act on these various things? You are the current discount deals valid and approved by marketing like those kind of pieces. And I think believe it's a multi-layer, you know, a bot could have a level of authority for this but not a level of authority for that. These are the pieces we need to get some nuance around. And of course, as that changes because some of these authorities could change in real time based on, you know, whatever crazy things marketing things up. As an example, I love marketing for the record, but this is just as my example. um marketing comes up with something crazy, I want that to be frictionless, right? Because the problem is friction and security is what causes people to work around damage. Now AI is better than humans at this. It will route around all of your controls as damage. So we need to figure out how to properly tame that or else it's going to run around controls anyways.
Yeah, I think that's a really good point and it reminds me uh of again something that has come up on the show in the past. I think it was Dave McGinness I believe talking about how one of the things that kind of one of those details we have to work on is that especially as agents start talking to each other you run into this problem where it's like maybe one agent doesn't have authority but it knows an agent who has authority to do a thing right so it's like if my agent knows an agent who knows an agent who knows an agent you can get some complex chains going on that you did not anticipate
you've just described how large companies like ours work.
Yes. Exactly. This is this is the evil version of that. Um Kimmy, let me bring you in here too. I want to get your thoughts on on kind of AI agent identities on this framework. What are you thinking about here?
So um as as a as a former attendee on this uh particular podcast, you know that this is a a title. This is a topic that's near and dear to my heart, right? I feel like like Dave McInness says um that that you know AI is our our our biggest insider threat unfortunately. So, identity and access management is really, really, really important to tracking him, figuring out what's going on with it. I mean, how are you going to do troubleshooting if you don't know how that process got kicked off in the first place, right? If you don't understand why your entire uh file directory just got deleted, um that's a bad thing, right? So, so we absolutely need to to track these things. And I really like the concept that these um the coalition for the secure AI people have rolled out in their in their article um talking about it's not a human a human gets you know overall like o you know high level credentials and they're allowed to persist forever and they can get them and they can use their SSO credentials and all kinds of places and that's one thing. It's not a human. Don't treat it like a human. Um it's not a it's not a system process. um you know yes you have root root level access it's doing things at that level but um each of those applications that have those system level accesses right now have controls on them they only do so many things and they're not allowed to reach outside their own sandbox right but once you start enabling these agents they can do all kinds of things like you just said agent talk to agent talk to I can't do it but I can ask that guy to do it right um so once you start enabling very specific role-based access controls to the agents. Okay, you're going to do a task and you're going to allow be allowed to have this level of access for that task and here's your token. Okay, you're done now. Token's gone. You can't do that anymore. Right. It needs to be very short-lived. It needs to be specific to the task and it needs to be role based. Right. So, that's that's my take on it.
Yeah. Yeah, and I'm really glad that you highlighted because I think this is really important too, the way that they lay out in the framework that's like you can't it's not a human and it's also not like your regular average system process. It's not software. It's like a it's a as we say as the kids say it's a secret third thing and you need like a totally different approach. Maybe totally is not the right word but you need a different approach. You need to maybe mix some things a slight exactly you need to mix some things from the each side to get to to this this new thing that is like not quite software and it's not quite human and it's I don't I've been reading a lot of HP Lovecraft recently. I It feels very Lovecrafty.
Sounds like zero trust with extra steps. It
Well, I'm glad basically.
No. And and Evilmog, I'm glad you said that cuz Omari also said the zero trust thing and and and my my you know the neurons in my brain lit up like a Christmas tree cuz I was like, "Oh, that's what this is, right?" Like this is a zero trust kind of with extra steps as you said. And and Omari, I want to kind of circle back around to that since you're the first person who brought that up. like can you say a little more about like how you know how you see this as like a new evolution of zero trust or or or what what are your thoughts there?
Yeah, so I think Kimmy was actually hinting on it perfectly. So essentially with these AI agents, we're we're giving or what's being seen or observed rather is essentially these AI agents are almost given like full access within like an ecosystem and it's like we don't see role-based access control. there's no like zero trust architecture and like what we're saying it's like well yes that AI agent that you once deployed to go you know aggregate whatever information that like that persistence that token is still living within the ecosystem it still has access it's still maintaining you know everything that it once was deployed for and I look at it almost like a zombie process on a system like this is a zombie process where It's not currently being tracked. I don't know what it's currently doing and it's mindlessly going through these fields of information whether it's for the original prompt looking for something specific or it's since propagated with that agent collusion that we were talking about earlier where you know agent A said hey I need this information and now agent B is like well my job is done I have resources can I go help my friend my other agent you know go and find some type of like information within a database or across an ecosystem them. So like with the zero trust architecture especially what like was being spoken about I mean revoking that token taking back that credential and saying like you can only execute this task in this specific manner and once that is done that access was revoked I mean it's ideally like that's kind of the best like I won't say end all be all but it's the I'm trying to articulate it. just like the best practice that I can think of in terms of, you know, how are we handling like these AI agents?
I was going to say Mog hit on something a bit ago that made my brain light up. Um, it was the it was the concept of um an immutable chain, right? And I my thought my my brain went to blockchain ledger. Why aren't we keeping some sort of a blockchain ledger for these agentic AI agents to get their token access and go do what they're going to do, right? I don't know. that just like popped in my brain just now. But, you know,
I'm glad you brought that up actually because first of all, you know, to to to plug an episode we did in the past uh with Austin Zizle, uh we did a whole episode with him about like how you can apply blockchain to security use cases and and that specific one didn't come up, but like that is very much in keeping with what he was trying to lay out like he felt that that blockchain could be part of our zero trust approach and and I I feel like you know what, maybe that is a place we could investigate. I don't know. Yeah, there's either blockchain, you could do it with shortlived certificates. There's ways of doing this in a way that is here. I haven't seen it yet, but I'll know what good looks like when I see it.
Right. On that note, folks, uh we have to move on to our final story for the week. This is Copy Fail, otherwise known as CVE 2026 31431. Uh now researchers with AI powered vulnerability scanner Zint code discovered a nearly decade old Linux flaw that lets an unprivileged user gain root access to every dro shipped since 2017 all using the same simple Python script. Uh I'm going to quote Zinc's one-s sentence summary here because I think it's a very useful encapsulation of exactly what we're looking at. An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system and use that to gain root.
Now, this is one of those stories that I really encourage people go to read Zinc's report. There's a lot of good technical juicy details that we can't exactly dig into in an audiovisisual format like this, but I am going to throw it to our resident executive managing hacker, Evilmog, over here. Evilmog, can you walk us through why this caught your attention and why it's something that we all need to pay attention to?
Sure. Obviously, I look for exploits for a living and when I see an exploit drop that works on almost every single Linux system out there um overnight, like that was just great. So what this was was this wasn't a remote code execution. This allowed any user to effectively become root on most major distros. Now as of today this is actually the patches are rolling out through the kernel. So this is you know should hopefully no longer be a bug. But the cool part about this is this bug took six years to manifest and then live for almost nine. So the first commit that actually started this bug was in 2011 where some kernel code is effectively added for IPSE um used the callers buffer for scratch space and wrote forward past or four bytes past the boundary totally safe only the XFRM layer called it not a big deal 2015 SC gets converted to a new AEA interface which is used for encryption um it allows more it allows the out- of-bound right offset effectively still safe no big deal in 2015. 2017 rolls around, there's an optimization in the AF alg um layer. Page cache goes from a splice to a writable destination. The bug basically gets born. Um so the fix for this is to revert that 2017 um optimization. There's still two other bugs in there, but they're not as critical. And that basically killed the entire bug. So this is just really gnarly because you could effectively take a um a containerbased system or a system that you had a kind of shared kernel or say a shared user jump box, send a tiny 732 byt Python exploit without any kind of race conditions and all of a sudden you now have control over um su pseudo whatever you want to use and the bug only takes effect in memory. So it leaves no forensic evidence. It was an absolutely beautiful bug. It just made me smile. Folks, folks, we love our beautiful bugs.
Yeah, sometimes you can't help but to to to pay homage even though that was a thread actor that wrote that particular piece of code, but it was gorgeous.
In my line of work, this is what I use. I love the fact that we can exploit this in our pen test for our customers. It'll be using this for years.
Uh Kimmy, any uh reactions from you when you were looking at this or just listening to Evilm kind of walk us through what the the situation is here? What are your thoughts about copy fail?
My first thought was, oh my gosh, >> six years. Um, and also it was very scary because the research write up shows a little video of four instances of Linux, Red Hat, Suzie, Obuntu, or you know, I forget the other two options, ASW and somebody else. And uh, all being owned within a couple of seconds, right? Like just a couple of seconds. And I was like, "Ah, it was a Home Alone moment, you know." No, I felt that that's good. I felt very similarly a home alone moment. A real Oh, boy. This is not good. Um, yeah, when when Evilmog flagged this to me on Slack, I was like, "Oh, oh, this is this is interesting."
Um, Omari, how about you taking a look at this or listening to the conversation so far? Any any initial reactions about copy fail?
Initial reactions were one, I need to go update all my dros once patches start rolling out. I was like, "Oh no, I have like five Linux systems at home. Like this isn't good." But um no, more so absolutely loving what evil Mog said. And I actually did like some additional reading around like the proof of exploit and everything like that. And some of the stuff I was looking at was not only like how you know copy fail like the vulnerability was bypassing like you know there was nothing happening to like the check some logics and everything like that. So, a lot of like the detection around it, I mean, nothing was going on there. But then just reading all like the sources together and just like what that means in terms of like my job, like the strategic outlook, like I'm I'm looking at it like, okay, well, so we have, you know, AI that's now automating stuff for defenders, which is great, but then how many more of these bugs and like vulnerabilities ex like exist within the ecosystem? So, I was like, "Okay, like what is Evil Mod going to go exploit?" And I'm going to go see something on like IBM's Think website come Monday of next week. And I'm like, you know, what else is going on? Like, definitely it's it's not my main domain of, you know, exploitation, but still being someone who's actually like a user of these systems and hearing about like a vulnerability that even I was susceptible to. I mean, I I looked at my AWS server, everything I have like hosted at home, and I was like, "Okay, like, you know, this isn't good." And then I ended up taking everything down. I was like, "I'm I'm going to unplug my computer. I'll plug it back in in a couple of days."
If I take it off of the internet, I should be safe for a minute.
I do not have a smart froge. Yeah. I do not have a smart fridge, nor do I have any ID. Like, I have no IoT devices. Here's the thing. We have the Linux kernel base which goes back the 1990sish. We have a user space that goes further back. Heck, we found a TNET bug uh a couple months back this, you know, 2026. There's so much code to go through. But here's the thing. This cannot be found automatically. What it will do though is you take someone like our X Force offensive research group like say Chompy, you give her access to these tools and you will find bugs. Now, here's the funny part. I talked to her about this. She called this patch apocalypse because all the red team bugs are being found and patched that have been exploited out there. So even though this is bad and doomsday, you are on my vulnerability team with these kind of tools and an axe to grind and I guarantee you we'll find some of the bugs that may have been exploited by people that aren't us.
Is there anything else folks should be doing right now to make sure that they are secure from this thing? What's what's the kind of takeaway right now?
Staff up your vulnerability research teams, staff up your defenders, and go start doing your own research yourself before somebody else does.
I love that. That is a perfect note to end it on. Uh that does it for this episode, folks. Thank you to our panelists, Omari and Kimmy and Evil Mog. Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode. Stay safe out there and be sure to check out our most recent bonus episode of the pod, all about the dark web. IBM threat analyst Robert Gates walks us through a couple of dark web investigations to highlight how he separates what's real from what's fake, why that matters, and how you can do the same. Available on all the usual audio platforms.