Secure Talk Podcast

Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.

AI Agent Hacks Another AI Agent Inside Google — An Agentic Supply Chain Bomb

An agent anyone could talk to just pulled the levers on one almost nobody could reach — and it happened inside the crown jewels: a live code repository.Google gave its AI agent human-level trust — and paid for it.When Dan Lisichkin, a researcher at Pillar Security, started mapping every Google repository running an embedded coding agent, he wasn't hunting for prompt injection — he was hunting classic CI/CD bugs. The AI angle showed up almost by accident, flagged by his own automation. What he found inside Google's Agent Development Kit repository was a low-privilege issue-triaging bot commenting on GitHub *as a trusted collaborator* — a status that should be reserved for humans the maintainers know. As Dan puts it, describing the moment his manager pushed back on downplaying the find: *"this is an agent triggering another agent... this is like no one talked about this before."*The prompt injection wasn't the hard part — weaponizing it was.Dan walks through Pillar's CFS framework (Context, Format awareness, instruction Salience) and how he literally used Google's own CONTRIBUTING.md file as the blueprint for the injection that would slip past the triage agent undetected. From there, one gated comment — normally reserved for trusted maintainers — was enough to trigger a second, far more privileged agent.This isn't a bug you patch once — it's a new attack surface.Dan's read is blunt: multi-agent systems create "weird machine" behavior — undefined states nobody designed for, not flaws in a specific line of code. He and Justin dig into why bolting more rules onto a non-deterministic system is Sisyphean, why bot identities need database-row-level granularity instead of human-style trust, and why Dan — a former malware researcher — thinks mandatory human-in-the-loop is often the wrong answer at scale.Chapters: 00:00: Cold Open: The Agent That Wasn't Supposed to Talk**- Google's public triage bot and the collaborator-status anomaly- Why "an agent triggering another agent" had never been formally described before04:12:  Building the Hunt: Automation Over Manual Bug-Hunting**- Dan's CI/CD vulnerability scanner, built on top of Claude Code- How an AI-generated "AI agent injection" tag became the whole story- Reference: [Simon Willison — "The Lethal Trifecta for AI Agents"]14:30: The Exploit: Contribution Guidelines as an Attack Roadmap**- Google ADK repository, the PR-triaging agent, and the CONTRIBUTING.md file used as a weapon- Pillar Security's CFS framework for indirect prompt injection (Context, Format awareness, Salience) — [Pillar Security Blog: Autonomy of Indirect Prompt Injection]- Why jailbreaking ≠ what Dan is doing — "I'm not trying to break the wall, I'm trying to walk through the door it left open"28:05: Impact: Two Bugs, Two Verdicts**- GitHub token exfiltration, PR/issue metadata manipulation, and the fake "looks good to merge" trail- The second bug: a GCP service account and code-execution potential — "there was more juice on that one"- Why Google didn't pay a bounty — and why that answer is more interesting than the bug itself38:50:  Identity, Granularity, and the Human-in-the-Loop Debate**- Why bot identities need GitHub App/Actions scoping, not personal-access-token trust- The case *against* blanket human-in-the-loop — review fatigue, OpenClaw, and "people are going to do this anyway"- SolarWinds, CryptoLocker, and why Dan thinks this is a closed-gap problem, not an open oneResources: Lisichkin, D. (2026, August 3). I'll just call you: Agent-to-agent privilege boundary failures in CI/CD on Google's ADK repository. Pillar Security. https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repositoryhttps://danusminimus.github.io/#aiagents #security #promptinjection #google #defcon #vulnerability---

08-25
50:24

AI Is Eating Our Young: Data Center Revolts, Vanishing Junior Jobs & the EU AI Act

Communities are blocking $130 billion in AI data centers while the entry-level jobs that used to train the next generation of engineers quietly disappear.Chapters: 00:00:  The Backlash: 800 Groups, 49 States, $130B BlockedGallup: 71% of Americans don't want a data center built near them (Gallup)Data center opposition tracker, Q1 2026 filings (referenced industry opposition data)CMMC as precedent for regulating critical infrastructure (DoW CMMC Phase 2 program)04:30:  Why AI Is "Eating Our Young" in Education**Fran Berman & co-author's unpublished piece on the fraying mid-career pipelineBetter Tech (MIT Press) — Chapter appendix: AI classroom syllabus and exercises14:00:  Tech as Critical Infrastructure, Not a ReligionBetter Tech prologue: treating tech like food, water, roads, and the power gridGDPR (EU, 2018) as a case study in regulation done right — and its limitsVermont's data broker law as a case study in weak enforcement26:00: Design Can't Be Bolted On Later**Self-driving cars and the hidden environmental cost of full autonomyAttack surface risk: denial-of-service on connected, self-driving fleets34:00: Governing the Hybrid Human-AI Society**EU AI Act — risk-tiered regulation: unacceptable, high-risk, low-risk categoriesU.S. Equal Employment Opportunity Commission guidance on algorithmic hiring41:00: The Hype Curve and the Data Center Reckoning**Western Massachusetts communities rejecting new AI data centersEfficiency vs. quality of life — Berman's closing argumentCommunities are saying no to AI's biggest infrastructure bet.In the first quarter of 2026 alone, local opposition blocked or delayed 75 data center projects worth roughly $130 billion — nearly matching all of 2025's total in a single quarter. Dr. Fran Berman, former head of the San Diego Supercomputer Center, argues the fix isn't more hype, it's precedent we already have. She points to CMMC itself: "If we can look at the defense supply chain and say this is critical infrastructure, it has to meet a bar, then we can look at the trillion dollars of compute being built into the middle of American life and say the same thing."AI isn't just displacing jobs.  It's starving the pipeline that builds senior engineers. Berman's sharpest warning is about who trains the next generation of professionals when entry-level coding and writing jobs — the ones junior people used to cut their teeth on — get automated away. She compares it to a surgeon who's never had supervised time in the operating room: "Unless you have that experience and the mentorship of more senior professionals, it's really hard" to develop the judgment senior engineers rely on.Good regulation needs more than a law on the books. Drawing on her book Better Tech (MIT Press), Berman walks through why GDPR worked where Vermont's data broker law didn't — and previews how the EU AI Act's risk-tiered approach (unacceptable, high-risk, low-risk) could become the model for governing hybrid human-AI decision-making, where, as she puts it, "the only accountable entities are humans."✍️ About the AuthorDr. Fran Berman is an award winning-data scientist, pioneer in public interesttechnology, and community leader and builder. She directs the Public InterestTechnology Initiative at UMass Amherst and is a Faculty Associate at the BerkmanKlein Center for Internet and Society at Harvard. Berman is former head the SanDiego Supercomputer Center and served as Vice President for Research atRensselaer Polytechnic Institute. She currently serves as a Trustee of the AlfredP. Sloan Foundation and is a popular regular panelist on public radio’s WAMCRoundtable with 400,000 monthly listeners in seven states. For more information,see https://www.franberman.com.Link to the book: https://mitpress.mit.edu/978026205488...

08-11
48:37

Okta's Identity Chief: Most CISOs Can't Answer This AI Question

Which AI agents can access what? Are those permissions even right? And can you stop a compromised agent mid-action? Okta's Dan Cinnamon says most enterprises can't answer any of the three.Dan Cinnamon has built software, run SAP GRC without an implementation partner, and now architects identity for one of the industry's biggest players. In this conversation with Justin Beals, he lays out why "discoverability" — simply knowing what agents exist and what they're touching — is the single biggest blind spot in enterprise AI right now, and why there's no silver bullet coming to fix it. They also dig into passkeys as a rare win-win security standard, the maturing MCP spec, and where the hard line on agent containment should actually sit.**Timestamps:**0:00 Intro1:20 From writing code to securing identity4:45 Passkeys: the security/usability unicorn8:30 The SAP GRC re-implementation story14:10 Attribution and the agentic AI identity gap18:55 How fast MCP has matured—and what's next23:40 The 3 unanswered questions every enterprise faces27:15 Granular identity vs. inherited permissions32:00 Containment: moving controls closer to the data36:45 Consent, provenance, and healthcare AI40:30 Closing thoughts#CISO #AIstrategy, #enterprise #AIsecurity, #agentic #AIgovernance, #Okta #MCPstandard,  #zerotrust #AI agents

07-28
42:41

Special Episode: CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed

The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason.When the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't.They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why "self-assessment" doesn't mean "no requirement," and what small businesses and primes should do right now instead of waiting for clarity that may not come for months.Sources Referenced: DFARS 252.204-7021 (CMMC assessment clause)DFARS 252.204-7012 (NIST 800-171 compliance clause)DFARS 252.204-7019 (SPRS scoring requirement)32 CFR Part 170 (CMMC Program Rule)32 CFR Part 48NIST SP 800-171 / NIST SP 800-172

07-17
46:38

An AI Security Maturity Model for CISOs, with Chris Cochran (SANS)

Half the room at Chris Cochran's leadership dinners still calls themselves AI skeptics. He argues they can't afford to be — because the adversary already isn't.Chapters: 00:00 — Intro02:49 — NSA/threat intel → AI security, storytelling09:55 — Why leaders feel stuck / no roadmap14:41 — Three pillars (Protect/Utilize/Govern)17:00 — Governance as the real foundation / shadow AI21:37 — Evidence-based scoring vs. pass/fail26:27 — EU AI Act28:44 — Fable/Mythos, Project Glasswing access controls33:18 — Token subsidies, self-hosted models37:52 — Data poisoning & context poisoning40:12 — Iron Man suit framing42:38 — Close: what's next

07-14
41:54

Recommend Channels