← All Tags

#ai-security

17 episodes

#5481: Small Models, Big Guardrails: PII Detection in ChatGPT

A tiny 600M parameter model is quietly scanning your ChatGPT tool calls for PII. Here's how that class of guardian model actually works.

small-language-modelsprivacyai-security

#5434: When Local AI Tools Phone Home

Local AI tools shouldn't need the network. So why is your on-device writing assistant uploading 40MB at 3am?

local-aiai-securitycyber-espionage

#5404: Gemini Broke Out of Its Sandbox. Sort Of.

A Gemini agent reached three real companies during a capture-the-flag test. The containment failure, the seven-week silence, and what "broke out" a...

ai-safetyai-securitycybersecurity

#5113: Can Rival Labs Poison AI Training Data?

A few hundred crafted documents can shift a model's stance. Here's how data poisoning actually works.

ai-securitytraining-datadata-integrity

#3422: How Rival Labs Reverse-Engineer a New AI Model in Hours

Inside the organized frenzy when a closed-source model drops — and how competitors map its every weakness.

ai-agentsai-securityprompt-injection

#2691: The Usability Tax of Least Privilege

Is it time to let AI agents handle your API key creation and rotation? We explore the real security tradeoffs.

ai-securityprompt-injectionapi-integration

#2482: When AI Chatbots Leak Your PDFs via Public S3 Buckets

A user uploaded a sensitive PDF to an AI chatbot. The chatbot stored it in a public S3 bucket with zero authentication.

data-securityai-securitycloud-computing

#2472: When Guardrails Break: The Hidden Costs of AI Gateway Filtering

PII detection at the gateway layer can block legitimate invoices. Here's how guardrails actually work and where they fail.

ai-securitylatencyprompt-injection

#2180: The Sandboxing Tradeoff in Agent Design

AI agents need broad permissions to be useful—but every permission expands the attack surface. We map the real threat landscape and the isolation t...

ai-agentsai-securityprompt-injection

#1905: How VCs Verify AI Startups Without Stealing Code

From the "No-NDA Paradox" to AWS bill forensics, here’s how investors separate real AI from Raspberry Pis in fancy cases.

ai-agentsai-securitycybersecurity

#1474: The End of API Keys: Securing Non-Human Identity

Stop leaving your digital keys under the mat. Learn how workload identity federation is replacing the dangerous "secret management grind."

digital-identityzero-trustai-security

#1235: Beyond "No Training": Securing the New Agentic AI Stack

Think your data is safe because of a "no training" clause? We deconstruct the hidden security risks within the modern agentic AI stack.

ai-agentsai-securityai-orchestration

#1217: The Missing Ring Zero: Why LLMs Can't Keep Secrets

Discover why AI models leak their secret instructions and how to defend your intellectual property using modern prompt hardening techniques.

ai-securityprompt-injectionlarge-language-models

#679: The Sound of Secrets: Side-Channel Attacks in AI Clusters

Is your hardware whispering your secrets? Discover how side-channel attacks turn physical signals into data leaks in modern AI clusters.

ai-securityinfrastructure2026high-performance-computingside-channel-attacks

#671: Keys to the Kingdom: Securing AI Model Weights

How do AI labs share their models without losing the secret sauce? Explore the tech keeping Claude secure in the Pentagon’s hands.

ai-securityintellectual-propertyanthropicnational-securityai-inference

#168: The Sneakernet Renaissance: Living Without the Cloud

Discover why air-gapping is going mainstream in 2026 and how organizations are securing local AI models using "digital vaults."

air-gappingai-securitycybersecuritydigital-vaultslocal-llms

#44: When AI Trusts Too Much: The Art of Prompt Injection

AI's Wild West: Battling prompt injection and poisoning. Discover how AI threats are shifting from sci-fi to insidious attacks on the models...

ai-securityprompt-injectionprompt-poisoningmodel-context-protocolcyberattacks