📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

First findings from Project Glasswing

IBM Technology33:10

Transcription

People are starting to share what they've learned working with Mythos. Mythos is a very special beast. Most AI vulnerability discovery still requires a skilled operator. The layered approach is still king, and we're still seeing that even with advanced frontier models, a customized harness is the most important part of Mythos.

Welcome to Security Intelligence, IBM's weekly cyber security podcast, where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your host, Matt Kazinski, and joining me this week, as you've seen, we've got Kimmy Farington, security detection engineer; Dustin Evilmog, Haywood, Ex-Force executive, managing hacker; and making his debut on the episode, we've got Curtis Pittz, lead CISO Trust. Thank you, folks, for for for being here today. We're going to be talking about the major leak of some sensitive CISA creds, maybe a little more Team PCP activity, and the 28th anniversary of Loft today.

But first, we've got to dive a little bit deeper into these lessons from Glass Wing. Now, when Anthropic first announced Glass Wing, they said the project was going to produce lessons for the whole community. So, even though not everyone was getting Mythos, we were still going to share some of what we found out. And those lessons are finally starting to come to the public. Cloudflare is one of the first organizations to publish a comprehensive write-up of its adventures with Mythos thus far. After letting Mythos take a look at more than 50 repos, some of the key takeaways include, uh, Mythos's proof generation and exploit chain construction capabilities really set it apart from other LLMs. Basically, it's really good at chaining together small things into big attack patterns, and it's really good at writing proofs of concept to prove that those are actually exploitable. The other thing they learned is that pointing an agent at a repo and just asking it to find vulnerabilities doesn't really work, which is where that harness came up, right, Kimmy? They found that the most, the best thing to do really was to set up a harness that breaks the process down into these discrete steps and orchestrates the actions of many different agents along specialized activity.

And there's also reason to think that more lessons are going to be coming soon because, look, Glass Wing is expanding, right? IBM just joined, and Anthropic re- uh, recently relaxed the confidentiality agreements that it had asked Glass-Wing participants to sign at first. So now they're allowed to share a little more freely about the cyber threats and the other things they find out. So Dustin, I will start with you. Initial reactions to Cloudflare's takeaways. Did anything in their write-up really stick out to you?

I mean, nothing really surprised me. Their write-up was all the things we've been saying before. Or, you know, the harness is the most important thing, which honestly, in it, the harness is always the most important thing, even during manual vulnerability discovery. So a lot of this is still not really news to me.

And speaking of the harness, Kimmy, you were the first one to mention that by name, so I want to, I want to bring you in here to talk about what about the harness really stuck out to you. I mean, like Mog said, this has always been one of the most important things, but Cloudflare's take on it seems very sophisticated and, and, and very practical to me. I don't know, what are your thoughts there, Kimmy?

I don't know that it's specifically all that sophisticated, but it is, in fact, um, a tried-and-true method. I mean, if you look at the way the Linux operating system is built in the first place, it's built, it's a bunch of tiny little methods that do a lot of things really good. Only those little things, you know, they're targeted, right? This is the same kind of method that they're using within the harness. They're saying break it down into, um, targeted agents that only do a single task and then pass it to somebody else who does another task within that chain, right? Um, that makes most, the most sense because that's, that's how, you know, researchers would do the processing of, um, the testing in the first place, right?

I like that framing, you know, because, uh, I think that with Mythos, so much of the conversation so far has been about how it's like this brand new game changer, and you point out that like, this is the method we've seen before. We're just applying it to a new thing, you know?

Exactly. That's the thing, right? Is that like, it turns out that the same methods we've used for many other things help us use this new LLM too, and that's really neat, uh, for me, cuz it's like a reminder that, look, the, the entire thing hasn't exploded, like the whole game hasn't completely changed. There's a lot that still works here.

Curtis, I want to bring you in too, you know, thinking about either the harness or just other things in Cloudflare's report, what's sticking out to you? Uh, uh, what, what do you want to talk about here?

The thing that stuck out to me the most when I first read it, because, and I'm not trying to make this a sales pitch, but it really echoes what IBM has been saying the whole time about purpose-built models, right? We don't, we don't throw these massive models at something and assume that it's going to do everything that we want it to do. We need small, focused, purpose-built models or agent or agents in this scenario, right? To do the tasks very well. Expecting it's just like a person, right? We don't hire one person to do everything across the board. You don't employ an agent to do everything across the board. We have to have, well, we try not to, right? We have to,

Sorry, did my face say something out loud?

Yeah. We, we have to have focused models to produce the output that help us versus just give us a bunch of noise.

Absolutely. And it reminds me of on the most recent episode, something that Nikki Robinson had been talking about, which is that we're, we're maybe approaching this point with LLM use now where, like, we're finding a sense of balance, right? In terms of we're not looking at one model to rule them all, basically, but it's like, you said, Curtis, we're learning, like, okay, specialized models really might be the way to go, pointing at things, or, or even just specialized agents, breaking things down into these little tasks, and really just being a little more precise instead of saying, like, okay, Mythos, look at 50 repositories and tell me what you found. Because that was, again, I know I've said this already, but that was a really interesting point part of Cloudflare's report to me was that they were like, yeah, we tried that, and it turns out that's not really the best way to do these things. Like, the context window fills up too fast, it wanders off in different directions. Like, you need to give it a little more direction there. Uh, uh, and, and Dustin, I wanted to throw back to you on terms of direction, because this is something we've seen repeatedly now, where like, there's a question about if we're going to be using LLMs for this kind of research, how do, how do we strike a balance between making them useful enough that they can go find things, but also not so, like, free that they can break things along the way, right? Because like Cloudflare ran into this issue where sometimes Mythos would push back and be like, I'm not going to do that, and they had to rephrase things. Um, any thoughts there on how we deal with, like, that angle?

It's funny, we're relitigating every single one of these issues we've learned over the last 30 years, right? It goes back to the monolith versus the microservices, and then it goes down to the AI safety versus non-AI safety. We've discussed all these topics wearing different skins all these years, and we're coming back to, oh look, small, purpose-built models with a lot less restrictions are doing the job. I mean, it's almost like we need skilled operators again, cuz we got rid of them all originally, and now it turns out you need to have a manager of the AI. So I'm just sitting here laughing a little bit. That's all.

I'm with you, Dustin. I'm with you. Right. Everything old is new again. It just happens all the time, right? Which is why I think it's really awesome that you've included the Loft thing at the end of this, this segment, right? Cuz 1998 called. I didn't even think that there were going to have so much symmetry between those two segments, but it really is shaping up that way. And, and, and I, yeah, I mean, this is again, this is really interesting for me because like, I had not thought about in approaching the story just how much of this is like, oh, we're using things we already know and we're applying them to like a new, uh, uh, instrument, basically.

Curtis, uh, I want to ask you about something that Cloudflare kind of ends on, which is, uh, I'm going to read a quote from, from the, the blog, and then I'll post a question to you. Quote, "The loudest reaction to Mythos preview from other security leaders has been about speed. Scan faster, patch faster, compress the response cycle. Based on their work with Mythos, Cloud, Cloudflare felt like the more important thing to focus on was the architecture around vulnerabilities." Right? Quote, "The principle is to make exploitation harder for an attacker, even when a bug exists, so that the gap between when a vulnerability is disclosed and when it is patched matters less." Any thoughts on that? Almost like sidestepping the patch speed question and focusing on something else instead.

It echoes the underlying principles that we've been talking about anyways in the security world, right? Zero trust architecture is only as good as your internal controls, right? You can never really build a perfect architecture. People are always going to be your insider threat, right? There's always going to be a vulnerability. So the important thing is rather than worrying about how fast someone can get in, how secure is your network once they get in? Not to build your segue into the next topic, but at the end of the day, I think AI management is really just another layer of cyber hygiene.

I agree with you, to be honest. I really do. Um, keeping, yeah. All AI is just really fast human inside the network. So we need to, you know, teach them, or at least control them properly. If you have bad controls, I mean, we're going to get in, right?

Garbage in, garbage out, right?

Yes. Open the attack surface, and we'll step right in.

Right. You guys really did just like pave the way straight to that next topic for us. Uh, and we are going to get there in just a second, but, uh, just to wrap it up, uh, uh, Kimmy, I'm going to do a little quick round table. Kimmy, any final thoughts on what we've learned about Glass Wing so far and where you're looking forward to things going? Any final thoughts there, Kimmy?

I'm glad that we're participating. I think everyone at enterprise level should be participating. If you build software, you should be throwing your stuff at, or you, you should be throwing it at this Glass Wing. You should be definitely using the Mythos model. And, um, I think that the most interesting part of all of that that I took away from Cloudflare's thing, um, it was validating my, my thoughts on using a different model base to do QA on the things that you've discovered, right? Because even after you found a vulnerability and you created a proof of concept and you thought that you, you know, were going to exploit this thing, um, it, it might not be actually a thing, right?

A lot of these things still count for AI. I, I really like how you put it. It's, it's just a super fast human in the system, right? And so much of how we treat humans still applies here. I really like that. Uh, Curtis, any final thoughts on your end about what you, we can expect from Glass Wing?

What we can expect from Glass Wing is we're employing it as another scan tool, right? We have several scan tools. Frontier models are just a new scan tool. I think the important thing to take away is even with the marketing hype and the splash that it made, don't just trust the output. Don't just presume that it's going to do the thing that marketing always says it's going to do for everything in life. And always apply your due diligence, right? Because at the end of the day, it's not responsible for the output, you are. So, make sure that you're doing the due diligence.

And that also like hearkens back to again, the episode we just released. We were talking about, uh, uh, Daniel Stenberg at Curl using Mythos, and it returned, like, five vulnerabilities, and then after they looked at it, they're like, "Oh, only one of these is an actual vulnerability, and it's a very small one at that." That, that, that just illustrates that point like you said, Curtis, don't just assume you pointed at the thing and it does everything. Like, there's, there are more steps, uh, involved, and you're responsible for that output. I like how you put that. Uh, Mog, uh, close us out here. Any final thoughts on Glass Wing?

I'm just excited to see what else we reinvent in this industry that we've invented previously. Um, it seems we're relearning the same lessons on a routine basis. And it, I find it rather comical. Don't get me wrong, this is just my cynical face going on. But reality, the validation harness means more than anything else. And I'm excited to see what X Force Offensive Research can do with this tool. Now,

Stay tuned for C++ coding language.

How many pluses can we get in there? That's right.

Folks watching on YouTube, the comments are open. If you've got thoughts on what Cloudflare's learned about Glass Wing, let us know. Drop it in there. I do read. I do respond. But we got to move on to our next story for today, folks. The CISA repo leaked on GitHub. Now, security researcher Brian Krebs reported that a contractor with CISA, the US Cyber Security and Infrastructure Agency, had for months left exposed a public GitHub repo that contained cloud keys, tokens, plain text passwords, logs, and other sensitive CISA assets. Uh, researchers who tested the credentials in the since-removed repo, so it has been taken down, uh, found that they granted access to cloud servers, secure code, development environments, and a whole lot more. Uh, there's no evidence that the credentials were misused by bad actors that we know of, but it's still a pretty significant leak. Curtis, I want to throw to you first because you were the first, uh, one to kind of gesture towards this story today, but initial reactions to this leak. What's it got you thinking about?

Yes. So, so the organization that I work in, in CISO, is part of the governance organization, right? And so, I, it, it always, when I see these types of things, it makes me think about the amount of steps that had to break for this to happen, right? Governance is built into the process. It's built into everything that we do, presumably. Uh, so having a repo that was left out there, both meant that someone neglected to do the the proper cyber hygiene, as we mentioned earlier, but then the governance failed, right? It's never one person that causes a failure like this. It's multiple people. So, back to the zero, uh, trust architecture, right? You can leave the door unlocked, but if every room in the house is locked, that's a, it's not going to do that much damage. The problem is if you leave all the doors unlocked, right, or you give them a master key to the house, well, now you've got a problem. So, uh, that was the thing that really stuck out to me. It's, it's not that the contractor left a repo with, with, you know, unencrypted secrets. That's bad, don't get me wrong, but there's a whole another process that failed in that, in that sequence that I don't think gets talked about a lot, that would have prevented that type of an accident.

I have a slightly different take on this. And here's the thing. Controls to most businesses, if they're not seamless, will be treated as damage, and people will work around them. So if you, knowing the US gov, or you know, whoever, you know, involved in this things, could have been a little on the crusty side, and I guarantee you somebody got a little annoyed. And, you know, that's the thing, friction is the enemy this day and age. So, and I also believe in offense and depth, you know, as an attacker. So you should be practicing defense and depth. Any one control could fail, and you need to protect against all of my controls, or all of my attacks that are going to go out there. Right.

I think in a lot of ways, there's, there's less daylight between those two positions than we might think at first, because I do think that, like you're saying, Mog, uh, uh, there was probably friction involved, and someone was trying to get away around that friction. And, and that isn't that kind of a governance failure in itself? Like, if, if our controls are introducing so much friction that people are like, I'm not going to follow them, that's not a good control. Like, that's not good governance, you know what I mean? And so I almost feel like it, you know, it's, we're still dealing with, at the end of the day, it's like, these were, there could have been better compensating controls, either to prevent, either to prevent somebody, you know, people who get in from doing any real damage. Because that's the other thing, and I don't, I don't want to harp on anybody, but like, they found that some of the passwords were just like, name of platform and year. Like, it's not, that's not good. It reminds me of like months ago, when, when there we found out that the password to the Louvre's camera system was just "Lou." Like, I, it's, you know, it's 2026, and we're still kind of seeing this stuff.

Do you want to know the kind of passwords I see for a living? I mean, the most common is going to be "season" and then "year" then exclamation mark, or "month year" exclamation mark, or the company name, year, exclamation mark. Without fail, 50% of the time.

If the human had to create it, it's probably that simple. This is why, folks, I have become, since starting this podcast, I've become such a convert to passkeys. Like, I just, I try to get rid of as many passwords as I can, because look, I, not like I was coming up with great passwords, dude. I was completely, I was doing the same stuff, you know.

Get a password manager. To be fair, passkeys don't work with Active Directory. And because AD passwords are or hashes are password equivalent, you got to rotate them all the time anyways. So the 90-day policy is garbage, but you still have to use it, which means get a password manager.

Which is crazy considering the guidance right now says the 90-day password is the wrong way to go anyways.

To be fair, that only applies if you have multifactor, if they're heavily properly salted, you have compensating controls, you can detect things like teleportation and all this other stuff, which AD can't do.

You did say teleportation. I heard that.

Yes.

It's a really cool way to say impossible travel. I prefer teleportation. I'm going to steal that and we're just going to do teleportation from now on.

Yeah.

Yeah. I'm going to tell my team that that's the new term for impossible travel. Teleportation. I like it.

You heard it here first, folks. Kimmy, I want to bring you in here, uh, uh, specifically because you had before this episode, you had reached out to me about another kind of ongoing GitHub, uh, incident, which is Team PCP had breached GitHub's, uh, uh, uh, source code allegedly through a compromised employee device. Slightly different. This was like an active hack and not a leak. But we're still talking about like two big supply chain attacks or, or these supply chain breaches involving GitHub. I don't know. Anything you want to say about either one of these situations, Kimmy, what are you thinking about?

I mean, you hit on it, Matt. It's a supply chain problem, right? Um, and, and all of this has to do with third parties having access to your supply chain in that, in that respect, right? Um, when you talk about grabbing the source code at GitHub, um, now you know how everyone's repositories work, and you can figure out ways to slide inside things so that you don't be detected when they check in their code, and they get their updates, and they do their things, and now you've rep, I mean, the, the, the possibilities for compromise are endless at this point. Um, I, I, I'm glad that the CISA, um, repo that was was up there from the contractor who was obviously not practicing good hygiene. Um, you know, checking in repos from his house with his own password and his own repo. Um, bad idea, bad comp. Anyway, I was thinking about what, what about these enterprises who are using GitHub for their version code right now? Um, now that, now that the threat actors have access to the source code for this repository system, the framework, um, and they have potentially access to some of the customers and the, um, source codes of those enterprises. What should enterprises be concerned about? How should they, should they be switching to a new version? Should they be looking at the blockchain? What are we gonna do here? Like, is there something to be done?

I'm not that concerned. The reason for this is simple. Underlying GitHub is still Git. Git is fully open source anyways. There's GitLab. There's all the other various. They're just fancy wrappers around Git. And so, if you know Git, I mean, that's the part that's still reasonably secure. It's just, you know, little fancy SSH wrappers about, you know, API keys. It's nothing earth-shattering. So yeah, if your system is so brittle that the source code gets released, all of a sudden you lose all your security. It's not a good system. Anyways.

Thank you for telling me the sky is not falling.

Your point is is true and it's very real. You would be surprised. I evaluate suppliers for IBM CIS, so daily, and the amount of times I have to have this conversation with third-party suppliers that don't understand the potential gravity of unsecure source code repositories, or don't understand why we ask for the commitments that we do, or the controls that we do. Uh, it, it would stagger most people, right? It's while it seems common place and common sense for us to think about it that way, there are so many suppliers out there that that don't look at it the same way or don't give it the same gravity that we do. And so at the end of the day, those vulnerabilities still very much exist. And it's, it's becoming increasingly difficult, but increasingly more important to evaluate against those types of things because they're so prevalent in the industry now as, as problems, right? And it's, it's taking up a significant amount of cycles.

So let me ask you this. Um, is SBOM making your life easier doing the review?

Well, so not all SBOMs are created equal, right? It's a great question. Um, it depends on what you're using, right? Some SBOMs are capable of, um, exhibiting the provenance of code. Some companies, I've found, don't even know where their developers are located, and they don't know where the code comes from. Some of them don't know where the code, the software is built, right? Where it's compiled, which is mind-blowing to me, but it, it does happen. It was SBOMs.

Yeah, SBOMs are are only as good as the information that they can gather. And a lot of companies, I've found, um, don't, don't have the information to feed into an SBOM, even with the current tools that are available to give us relevant data. So we're getting SBOMs and we're evaluating it, and I'm seeing no provenance for the code, and I'm saying, okay, well, where, where did this get developed? And they're like, well, our developers are all over the place. I said, okay, where is your governance model? Where is it built? Who's in charge of supervising the final compilation of that code? And they're like, "Well, I'll have to get back to you." That shouldn't be a, "I have to get back to you" question, right? That should be a, "I know exactly where my code repository is sit. I know exactly where my build locations are, and I can tell you off the cuff." I'm finding very often that that's not the case.

And for those who don't know, SBOM stands for Software Bill of Materials.

Hearing that, it's interesting, right? Because I think I'm going to have to move this along very, very soon. But like, I just think about how one of the, the, sort of approaches to AI security that I keep hearing about is like, "Oh, we're going to do AI BOMs. It's going to be fine. We're going to do a BOMs, it's going to be fine." You know, it, it depends on what's going into there. You know what I mean? Like, it really depends on what's going into there. Um, uh, but no, I, I have to move us along here, folks. This is a fabulous conversation. We went in all kinds of directions I didn't even expect. I feel like the major takeaways, at least for me, were like, vet your third parties. Secrets management, uh, tools exist. Get them. And, uh, make sure governance like actually works and isn't just introducing, uh, uh, needless friction or no friction at all. But let's move along to our final story of the day.

Looking back on Loft Day, May 19th marked the 28th anniversary of Loft Day, when a group of hackers known as Loft Heavy Industries warned Congress about a set of major cyber threats facing the US. Space Rogue was one of those hackers. Uh, uh, he used to be an IBMer. He's been on the show before, and he was the one who, I kind of learned about this from, cuz he was there at, you know, testifying with Congress and reflecting on this 28, uh, years later, he wrote on LinkedIn, "What strikes me now, looking back from 2026, is how much of it landed and how little actually changed. The vulnerabilities we described: weak authentication, unencrypted protocols, fragile infrastructure with no accountability, became the blueprint for the next three decades of breaches. We weren't predicting the future, we were describing the present in a language the policy world wasn't ready to hear yet."

Um, now, given that on, in a lot of ways, and I didn't expect this when I set it up, but in a lot of ways, this whole episode has kind of been about like, same old story over and over again. Uh, uh, Kimmy, I want to ask you, what do you think? Have we really not advanced much at all in the last 28 years when it comes to security? What are you thinking?

I mean, I only jumped in about 14 years ago myself. Uh, but looking back and, and learning the history, and now knowing the future, or seeing the future, and living in the future, we haven't really changed a whole lot. Our problems are always going to be the same, whether we move them to the cloud, or we have them in the mainframe, or they are, you know, living next door, or it's, you know, the, uh, robot version of me. Um, their problems are always going to be the same, but we're figuring out new ways to exploit them and try to defend ourselves against them, right? I mean, it's that whack-a-mole problem.

It is. And it's, it's almost like an eternal cycle, it feels like, some in some ways. Uh, Mog, any thought? Like, do you think we, we, we will make progress, or is it really just that like new technology comes, the same problems pop up, we fix them, and, and repeat ad nauseam? What do you think?

You all know my opinion on this one, and it's going to be this internal cycle. I will say this though, we have improved meaningfully since the Loft testimony because they were complaining about BGP being the central issue that takes down the internet. We've since added RPKI to things, so we can actually start validating routes, and a good chunk of the routes now are protected, especially because of cloud. So anything that's going into like your Amazon, your, uh, Azures, anything via BYOP requires RPKI and route authorization objects. So, we've at least kind of hopefully killed IP4 and IP6, um, hijacking. No more routing through China. Um, in fact, I'm even quoting a couple of those. But other than that, nothing else has really changed. We just keep reinventing the same cycle.

Curtis, I want, I want to ask you about, uh, uh, something that Space Rogue closes on in his post, which he says, quote, "The gap between what security knows and what decision makers act on is still the fundamental problem." Kind of two-part question for you. One, do you agree that there is a gap and it's a problem? And two, any thoughts on how we close that gap?

Yeah, I think there'll always be a gap, right? Because the people who focus on this day-to-day, the experts know all of the things that we should do. Uh, the people that enact those policies are rarely the experts, right? They have entirely different skill sets. I think we've gotten better at detection. I think we've gotten better at creating technologies that protect the existing architecture and infrastructure. But much like the beginning topic around AI and Mythos and Glass Wing, we've also gotten better at creating technologies that break those things. So it's, it's this eternal struggle of we get better, but that makes us have to get better because we've created our own problems that we now have to solve. We created the problem of the internet. We tried to solve a lot of those problems, and we've created different problems. Uh, we'll never get to end state, right? We will always be creating more problems that we have to solve, probably as humanity as a whole. That probably goes to every topic that you can think about, not just cybersecurity. Um, but I, I do think we've gotten better. Um, I do think there will always be a gap, uh, between the, the security focals and the decision makers. I think our job is to find a way to put it into words that they care about and understand. Um, think about it like the old Mr. Rogers testifying before Congress why PBS should exist, right? They saw it as a line item in a budget. He saw it as a path to kids' hearts. And we need to do the same thing with data and security, right? Find a way to express that sentiment that the, the data is the gold of today's world, and we need to protect it as such. We need to build our Fort Knox. And with that comes requirements of budget, requirements of of capability and architecture changes, and all of the things that go into that.

So here's the thing. No business is in the function of being secure. They're in the business of making widgets, performing a function, doing a thing. And as soon as we get in the way of that, we are going to be treated like damage. So we need to be business accelerators. Look at COVID pandemic. We all decided to go VPN working remote. We became business accelerators. But the second you get in the way, or governance becomes crusty, or whatever else, it's going to be the same old thing in that gap.

Thank you, Mog. All I was thinking was rush to market, rush to market, rush to market. That's why things have failures. That's why things are are holy and they don't, uh, they don't have security built in because that's friction. That's harder. That's, I didn't think about that ahead of time. I just really wanted my tool. It reminds me of of something that, that, uh, Jeff Kroom often says on the show, which is like, security, you can't, it's not, you shouldn't say no, you should say how. Right? So, it's like, you can't say no, we can't do it. We should say, here's how we do that thing you want to do securely. Right? And I'm not going to, I'm not going to say that that completely solves all the problems, right? Because as you've all pointed out, Mog, I know I really like how that you put it, but like, no business is in the business of being secure, right? So like, that's, that's not, uh, you know, they're never, not never, but it's going to be very hard to get security to be the number one thing on the C-suite's mind. You know what I mean? Um, so we just, you figure out how to close that gap and get better and better. And, and Curtis, I like how you put it in terms of like, we just have to put it in, in, in terms that the folks will understand. And maybe it won't erase the entire problem, but like, if you can put it in terms that are not just like pure cybersecurity jargon, but like, here's why you, as a business leader or or decision maker, whoever you are, should care about this. Like, here's how it lines up with whatever your particular priorities are. Then maybe we, we start to close that gap a little bit, and maybe we, we, we accelerate a little more. But at the end of the day, we might just be trapped in that eternal cycle forever.

Um, to close us out though, today, folks, I just want to do one quick final little round table based on, you know, uh, Loft Heavy Industries, uh, uh, testimony 28 years ago, and how far or not far we've come. Is there anything you'd like to see us start doing, uh, as, as a discipline? And Kimmy, I'll start with you because you made that face. Anything you'd like to see us start doing that we're not doing right now?

Everything old is new again. How do we, how do we not chase our tails? How do we not resolve the same problems? How, how do we move forward from what we have now? Um, the problem, of course, is that as soon as we move forward, we're, you know, we're, we're, we're finding the answer to that problem while we're creating a new problem. We already discussed all that, right? Like, is there an answer? I don't know. Um, I think it's going to keep us in, in business for a minute.

I, that's one good way to look at it. Uh, Mog, how about you? Anything you'd like to see us do that we're not doing right now?

Yeah, start training juniors. That's our biggest problem. We have a staffing problem more than anything else, and we got rid of junior roles for so long, and they stopped becoming seniors. We laid all them off. All that institutional knowledge is just gone, and we're recreating the same problems. We're calling it different things. We need to staff up and keep people, train them, and have them solve these problems because I don't want to do this in 10 years.

Absolutely. Curtis, uh, close us out for the day. Anything you'd like to see us do that we're not doing right now?

No, I think Mog hit it dead on the head. I, I actually was going to say that, but generationally, right, versus versus the roles. I think we need to train the user base generationally across the globe in what basic cyber hygiene is, what it is that they actually create as far as vulnerabilities and risks in their day-to-day lives. Uh, you know, I have two children. I try to teach them all the time the internet is not a safe place. It is not a place that you can do what you want to do and expect that there will be no consequences. And so, um, I've tried very hard in my house to to train my children on how to be smart on the internet, how to research if a link is trustworthy, if it's not. Basic cyber hygiene that we think about daily, but the greater population doesn't, right? And so, those people open doors all the time and don't realize it. So, we have to train as best we can to decrease the insider threat because everyone's on the internet. That threat exists in every single endpoint. We also need to train our AI agents in the same manner, right? We need to have built up knowledge bases so that if the AI agent gets a question, it gets a realistic answer from a real database full of information as opposed to garbage that other AI generated.

The problem is we can't really train the AIs with skills and stuff because that technology is changing all the time. I'd rather train the people who can then train the agents because this tech moves so fast. I want stuff that's evergreen so I can actually retire one day. Yes. At the same time, I want knowledge bases that exist, right? I'm, I'm, I'm a librarian at heart. I'm an archivist. Um, you know, by nature, I want to maintain the knowledge as it existed in the day that it was written, right? So that we can look back and go, "Oh, we learned from that. That happened already. Let's do something different."

Right? We don't want it all overwritten by AI generated stuff that then just starts training itself on its own generated documentation. Right? Um, my children already think that history is different because they saw it on the internet, right? Um, and we don't have to get into what specific things about history are different today. But,

Folks, I, I, I'm glad we opened this can of worms to end the show, but that does bring us to the end of this episode. Thank you so much to our panelists, Curtis and Evilmog, and Kimmy. Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode. Stay safe out there, and remember that data is the way to the C-suite's heart.