Skip to content
Artwork for Autonomous IT
TechnologyNewsTech News

Autonomous IT

Automox

Go from monotonous to autonomous IT operations with this series. Hosts from Automox, the IT automation platform for modern organizations, will cover the latest IT trends; Patch Tuesday remediations; ways to save time with Worklets (pre-built scripts); reduce risk; slash complexity; and automate OS, third-party, and configuration updates on all your Windows, macOS, and Linux endpoints. Automate confidence everywhere with Automox.

Play
  • 21 episodes
  • Avg 19 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #36
    Tuesday · 42 min

    Autonomous IT, Live! Turn to Face the StrAInge, Patch Speed vs AI Attacks, E08

    In April, Jason Kikta and Dmitri Alperovitch landed on a structural conclusion: AI had collapsed patch-to-exploit time to under an hour, 1-10-60 was no longer fast enough, and the only answer was prevention. Patch by default, limit blast radius, stop playing a detection-and-response game built for human-speed attacks. This episode picks up where that conversation ended. What's changed since April, and can detection-first models survive the pace of change at all? Kat Traxler is here to stress test that question from the inside. Guests: Jason Kikta, Automox CTO, Dmitri Alperovitch, Co-Founder and Chairman, Silverado Policy Accelerator Kat Traxler, Principal Security Researcher, Vectra AI Host: Landon Miles

  • #35
    August 11 · 22 min

    Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

    August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only actively exploited vulnerability of the month, CVE-2026-68820, a use-after-free in the Windows AFD driver that trades a race condition for SYSTEM privileges. Serena breaks down CVE-2026-62832, a User Profile Service privilege escalation that lets an attacker load another user's registry hive with no user interaction required. Then there's the perfect 10.0 in Microsoft Teams that nobody needs to patch. Jason explains how cloud CVEs ended up in Patch Tuesday releases, why a third of this month's critical count requires zero customer action, and why the industry needs a separate disclosure mechanism before monthly CVE volume becomes pure noise. The crew also covers an ugly macOS screen sharing vulnerability that allowed authentication without credentials, the Linux kernel community's shift to issuing CVEs at scale, fresh takes from Black Hat and DEF CON on AI-driven vulnerability discovery, and why frontier models are forcing patching decisions to happen by policy instead of one CVE at a time. Patch your stuff. See you next month.

  • #22
    July 22 · 17 min

    Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22

    Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security. In this episode of Secure IT, host Jason Kikta is joined by Mark Cooper, CEO and founder of PKI Solutions, to unpack why PKI is so critical to identity, authentication, and trust, and what happens when it fails. They explore how certificates enable passwordless authentication, secure TLS connections, IoT devices, endpoints, and enterprise systems, while also examining why misconfigured or poorly monitored PKI environments often become an attacker's fastest path to privilege escalation. From certificate expirations and operational outages to real-world breach scenarios and pen test failures, this conversation maps the full PKI risk spectrum. Jason and Mark also challenge a common assumption in cybersecurity: that recovery equals resilience. Instead, they argue that true resilience means staying secure and operational, even during misconfiguration, failure, or attack. Whether you're new to PKI or responsible for running it, this episode will change how you think about identity infrastructure, resilience, and trust. Topics covered: - What PKI is and why most organizations already depend on it - Certificates, passwordless authentication, and digital identity - How PKI misconfigurations enable high-impact attacks - Why recovery is the weakest form of resilience - The hidden operational and security risks of foundational systems

  • #34
    July 14 · 29 min

    Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

    570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown: An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8 A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the network An RDP bug you can shut down with a single setting, no patch required A SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner access A 9.9 Hyper-V escape that lets one compromised VM take the whole host A BitLocker bypass (6.1) worth knowing if you manage laptops in the field Plus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.

  • #7
    July 1 · 15 min

    Executive IT – What IT hiring actually looks like when AI does the work, E07

    Eighteen months after the Hands-On IT podcast tackled the state of IT careers, Chelsea Rickey, SVP of Human Resources at Automox, comes back to the conversation to assess what held up, what changed, and what nobody quite predicted. AI is no longer a future-state problem. It's already reshaping what roles look like, how productivity gets measured, and how organizations coordinate. Individual learning agility still matters, but Chelsea argues the harder question now is whether organizations can adapt as fast as the people inside them.

  • #26
    June 11 · 27 min

    Product Talk – CISA's BOD 26-04 Directive Explained, E26

    CISA's BOD 26-04 replaces severity-based patching with an exploit-evidence model and remediation clocks as short as three days, fleet-wide, no exceptions. Peter Pflaster and Jason Kikta unpack the four urgency signals, the 16-row decision tree, and the shift from "justify the patch" to "justify why you can't." They also cover what it means for contractors, cyber insurance, and the future of Patch Tuesday. If you own patching or vulnerability management, start here.

  • #33
    June 9 · 23 min

    Patch [FIX] Tuesday – [Nothing Weaponized, Everything Exposed], E33

    June 2026 has no headliner. Instead of one critical bug, the release spreads thin across the kernel, the network stack, a code editor, an AI assistant, a bootloader, and a nine-year-old Linux root bug. It's a breadth problem, not a severity one, and it changes how you triage. Jason Kikta and Landon Miles break down the whole release, then step off the patch list for the breaches that never got a CVE: GitHub's internal repos reached through a poisoned VS Code extension, a TanStack compromise carrying valid SLSA provenance, and a Red Hat npm namespace compromise that fired the moment anyone ran npm install.

  • #32
    May 12 · 34 min

    Patch [FIX] Tuesday – [AI Hits the Hat Trick], Ep. 32

    The May 2026 Microsoft Patch Tuesday release looks quiet on the surface – no actively exploited zero-days, no public disclosures at release, and a CVE count below the four-month average. Don't let that fool you. In this episode, Jason Kikta and Landon Miles break down everything that happened between April and May patch cycles, including Apple's macOS Tahoe 26.5 release with 79 CVEs, the Dirty Frag Linux kernel privilege escalation chain, and two pre-authenticated network remote code execution vulnerabilities in Windows core services that belong at the top of your patch list. They also dig into one of the month's most significant trends: AI-assisted vulnerability research showing up by name in Microsoft, Apple, and Linux acknowledgments in the same patch cycle – including Anthropic researchers credited on a critical Windows graphics component RCE. Ten AI-attributed vulnerability discoveries shipped fixes across all three major operating systems this month. What's covered: CVE-2026-41089: Windows NetLogon RCE (CVSS 9.8) and CVE-2026-41096: Windows DNS Client RCE (CVSS 9.8) CVE-2026-40402: Hyper-V guest-to-host escalation (CVSS 9.3) macOS Tahoe 26.5: Wi-Fi kernel RCE, nine kernel CVEs, 20 WebKit vulnerabilities Dirty Frag Linux privilege escalation chain and the Copy Fail connection AI-credited discoveries from Anthropic, calif.io, Theori, and NIST's Center for AI Standards and Innovation - Patch Tuesday Blog - DirtyFrag Blog - What "Mythos Ready" Means

  • #31
    May 8 · 10 min

    Patch [FIX] Tuesday – [Emergency Episode: DirtyFrag Exploit Before Patch], Ep. 31

    Breaking from the normal Patch Tuesday cadence for an emergency drop. On May 7, security researcher Hyunwoo Kim published a working proof-of-concept for DirtyFrag - a Linux kernel local privilege escalation chain that gets unprivileged users to root on every major distribution. The embargo was broken by a third party before distribution backports were ready, so the exploit is public and the patch is not. CTO Jason Kikta and Landon Miles walk through what makes DirtyFrag different from the Copy Fail mitigation many teams already deployed (spoiler: the CopyFail mitigation does NOT cover this), why AWS is calling it a class rather than a single CVE, and the five kernel modules you need to block right now: esp4, esp6, ipcomp4, ipcomp6, and rxrpc. In this episode: Why the embargo break matters and what changed on May 7 How DirtyFrag chains CVE-2026-43284 and CVE-2026-43500 to defeat both Ubuntu's namespace policy and the absence of rxrpc.ko on other distros Why this is the third generation of a bug class (DirtyPipe → Copy Fail → DirtyFrag) and what that means for what comes next The Automox Worklet that mitigates both arms across your Linux fleet, and what it deliberately does not do Tested affected platforms: Ubuntu 24.04, RHEL 10.1, AlmaLinux 10, CentOS Stream 10, openSUSE Tumbleweed, Fedora 44 Back to the regular Patch Tuesday schedule next week. Links: Full blog post and mitigation guidance Automox Worklet (in-console for customers): Worklet source on GitHub Hyunwoo Kim's PoC and write-up AWS Security Bulletin 2026-027 CVE-2026-31431 (Copy Fail, parent issue)

  • #7
    April 28 · 33 min

    Autonomous IT, Live! The Math of Modern Attacks, E07

    In this episode of Autonomous IT, Live!, we break down the widening gap between exploitation speed and remediation reality. Disclosed vulnerabilities keep climbing, exploitation windows keep shrinking, and IT and security teams are expected to absorb more risk without more resources. The traditional playbook — manual patching, fragmented workflows, scheduled cycles — was built for a slower world that no longer exists. What you'll learn: Why threat actors consistently outpace defender response times Where manual patching and fragmented processes break down, even for mature teams How rising vulnerability volume and shrinking exploitation timelines are reshaping risk Why working harder isn't the answer — and what actually needs to change Who should listen: IT and security leaders responsible for vulnerability management, infrastructure teams running distributed or SaaS-heavy environments, and anyone focused on shrinking exposure windows and accelerating response. The gap between attacker speed and defender capability isn't closing on its own. This conversation is about what it takes to close it. This live show originally aired April 22, 2026.

  • #23
    April 23 · 7 min

    Secure IT – Claude Mythos: AI Vulnerability Hype vs. Evidence, E23

    Claude Mythos dominated the AI security conversation for two weeks straight, from the Cloud Security Alliance's strategy briefing to sharp public skepticism to yesterday's Bloomberg report that unauthorized users on Discord have been accessing Mythos since its limited launch. Host Jason Kikta cuts through the noise to separate the contested vendor claims from the established trend. In this episode: Why the Mythos debate misses the point, and the independently verified AI security milestones that predate it (XBOW topping HackerOne, DARPA's AI Cyber Challenge, Google Big Sleep, Claude Opus 4.6's 500+ high-severity findings) A careful look at the numbers behind Anthropic's system card, including the Firefox exploit rate dropping from 72.4% to 4.4% once pre-discovered bugs are removed The CSA's top CISO recommendations that hold regardless of which Mythos claims you believe: patching, segmentation, egress filtering, MFA, defense in depth Three concrete actions to take this week, including the governance conversation most security leaders are overdue to have with the business Good security starts with good IT. The trend is stable. The claims are contested. Anchor your planning accordingly. Links and sources: CSA briefing Project Glasswing Mythos technical writeup Ottenheimer system card teardown Tom's Hardware on the 198 manual reviews: Bloomberg on the Discord leak

    • Transcript
  • #30
    April 14 · 8 min

    Patch [FIX] Tuesday – April 2026 [Double Feature: SQL Another Day + XSS Never Dies], E30

    This month's Patch Tuesday drops a SQL Server elevation of privilege that hands attackers sysadmin access and an actively exploited SharePoint XSS flaw that requires no authentication. SQL injection in the database engine. Cross-site scripting. In 2026...? Ryan and Mat break down how these attacks work, what to watch for, and why these "classic" vulnerability classes refuse to stay dead. Also covered: 80 Edge and Chromium fixes released this month, and a recurring reminder about Secure Boot certificates you can't afford to ignore this year.

  • #11
    April 9 · 14 min

    Automox Insiders – The Magic of Automox: Emily Pace on Building Smarter IT Tools, E11

    In this episode of IT Insiders, Maddie Regis speaks with Emily Pace, a Senior Product Manager at Automox. Emily shares her career journey, her role in product management, and the collaborative environment at Automox that fosters innovation. They discuss current projects, the importance of customer feedback, and Emily's advice for IT professionals. The conversation concludes with a fun game about real and fake products, showcasing Emily's quick thinking and humor. This episode originally aired November 19, 2024

  • #25
    April 2 · 19 min

    Product Talk – From Click to Fix: Bringing Automox Actions to Zendesk, E25

    What if your IT team could troubleshoot and remediate endpoint issues without ever leaving their service desk? In this episode, Steph Rizzuto and Katherine Chipdey break down the new Automox + Zendesk integration. They cover what it does, why it matters, and how it's designed to cut meantime to remediation for IT teams. The integration surfaces real-time endpoint data directly inside Zendesk tickets. It also gives admins one-click actions like device restarts, patch deployment, and policy execution. Beyond reactive fixes, it flags automation gaps so fewer tickets get created in the first place. Plus, hear how the Splashtop remote desktop integration ties it all together when hands-on troubleshooting is needed. Whether you're running a lean IT team or managing thousands of endpoints, this one's worth a listen.

  • #17
    March 31 · 13 min

    Automox Insiders – Tidy Endpoints, Tidy Mind: Spring Cleaning with Adam Whitman, E17

    In this episode of Automox Insiders, host Maddie Regis chats with Adam Whitman, Manager of Solutions Engineering at Automox, about all things IT spring cleaning. From patch management and software audits to business continuity planning and endpoint hygiene, Adam shares practical, real-world tips for tidying up your tech stack and staying ahead of IT clutter. Along the way, he reflects on his career journey from marketing to IT leadership and reveals some personal spring cleaning confessions. Tune in for expert advice and a fresh perspective to help you refresh your IT environment this season. This podcast originally aired April 24, 2025

  • #1
    March 18 · 7 min

    Behind the Ticket – What to Do When Both Tools Are Right, E01

    A routine support ticket reveals a deeper truth about patch management. Your patching tool says "done," but your vulnerability scanner disagrees – so who's right? In this episode, Automox SVP of Customer Experience Charles Coaxum walks through a real customer case. Dozens of machines showed as patched in the dashboard but were flagged as vulnerable by the scanner. The culprit wasn't a bug or misconfiguration. It was the often-overlooked gap between patch execution and patch completion. Learn why pending reboots create silent compliance gaps. Discover how to identify endpoints stuck in limbo. And see how automation turns hours of manual investigation into a minutes-long fix.

  • #29
    March 10 · 21 min

    Patch [FIX] Tuesday – March 2026 [SMB Is Back and ASLR Gets Shuffled], E29

    March 2026's Patch Tuesday brings no active exploitations, but don't let that fool you. This month, Ryan Braunstein and Henry Smith break down why medium-severity vulnerabilities deserve your full attention. First up: a Push Message Routing Service memory leak (CVE-2026-24282, CVSS 5.5) that lets attackers scrape session tokens and private keys from heap memory. Then, a pair of GDI bugs (CVE-2026-25181 and CVE-2026-25190) that chain together to defeat ASLR and deliver remote code execution with near-perfect reliability. Henry covers a Windows Accessibility Infrastructure flaw (CVE-2026-24291) hiding in a service most teams never think to harden, plus an SMB authentication bypass (CVE-2026-24294) that echoes EternalBlue and WannaCry. What you'll learn: - How attackers chain medium-severity bugs into full compromise paths - Why the Push Message Routing Service is a target-rich environment for credential theft - How a two-stage GDI exploit defeats ASLR with near-100% reliability - Why accessibility services are blind spots on your hardening checklists - What SMB's history with EternalBlue and WannaCry means for this month's auth bypass Patch your systems. Audit your service accounts. Don't skip the mediums.

  • #14
    March 3 · 12 min

    Automate IT – The Server Tango: Step In... and Now MySQL's Down, E14

    In this episode, Jeremy Maldonado shares his experiences and insights on server management, highlighting the importance of learning from mistakes, the power of automation, and finding balance between Linux and Windows environments. He discusses the challenges and rewards of managing servers, the pivotal role of Ansible in streamlining operations, and the confidence required to maintain a reliable infrastructure. Jeremy encourages listeners to view setbacks as opportunities for growth while reminding us to be kind to ourselves throughout our professional journeys. This episode originally aired March 6, 2025

  • #22
    February 26 · 11 min

    Automate IT – The Myth of the All-Knowing IT Pro, E22

    The all-knowing IT pro is a myth. In this episode, Automox Senior Solutions Consultant Jeremy Maldonado breaks down why curiosity and asking for help are the real foundations of a successful IT career. He shares how he went from feeling nervous about asking questions to becoming a trusted resource for IT teams across industries, including hospitals, local governments, and school districts. Jeremy also pulls back the curtain on what he does day to day on the Automox Professional Services team: reviewing IT admins' environments, evaluating patching schedules, and working collaboratively to fine-tune configurations. Rather than coming in as the all-knowing expert, he explains why the best results come from treating every engagement as a shared experience, where both sides learn from each other. Whether you're early in your IT career or a seasoned admin, this episode is a reminder that growth starts with a question. Topics covered: - Why the all-knowing IT pro doesn't exist - How curiosity drives career growth in IT - What an Automox environment review looks like - Tailoring patching best practices to different industries - Finding room for improvement even when things work

  • #29
    February 24 · 17 min

    Product Talk – Bridging the CVE Gap with VulnCheck, E24

    NIST is falling behind on vulnerability scoring — and the gap is growing. In this episode, Peter and Steph break down what that means for IT and security teams relying on CVE data to prioritize patching, and how Automox is solving it. We cover: Why NIST's National Vulnerability Database has a growing backlog and what's causing it How incomplete vulnerability data creates blind spots in your patch management program Automox's new partnership with VulnCheck to deliver real-time vulnerability intelligence What KEV (Known Exploitable Vulnerabilities) data is and why your leadership team cares about it Expanding from fewer than 10 third-party apps to 70% coverage across 500+ supported applications The rollout plan from third-party apps to macOS, Windows, and Linux Whether you're running a mature vulnerability management program or just getting started, this episode lays out how the vulnerability data landscape is shifting and what you can do to stay ahead of real-world threats.

Showing 1–20 of 21 episodes