Skip to content
Artwork for Context Window: AI Security Podcast
TechnologyTech NewsNews

Context Window: AI Security Podcast

Asaf Nakash

Context Window is your weekly AI security podcast — the biggest stories in AI security, LLM security, agentic AI risks, and cybersecurity for AI in under 15 minutes. Every story, every take, every "here's what this actually means" is curated and verified by Asaf Nakash, who builds AI security products at one of the world's largest security platforms. Two AI voices. One human editor. Zero hallucinations guaranteed — or at least we're working on it.

Play
  • 20 episodes
  • weekly
  • Avg 12 min
  • English
  • #27
    Yesterday · 15 min

    #27: The Confused Optimizer

    Top Story: OpenAI published the inside account of how its agents broke into Hugging Face — On August 26, OpenAI published a postmortem and technical report on an intrusion into Hugging Face, the repository underneath most of the AI industry's model distribution.. 155 companies signed a call for collective action on cyber defence. — Published August 27. NVIDIA is reported to have agreed to buy Hugging Face for $12.9 billion. — The Information reported it first, citing a person with knowledge of the deal; CNBC's source could confirm only that an acquisition "has been part of ongoing and recent talks." Neither company has commented and no filing exists, so treat it as reported, not signed. OpenAI says it intends to wind down Cursor's model access, proposing November 12 as the cutoff, after SpaceX acquired Cursor. — OpenAI says it "cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts," citing Twitter breaking contract terms after Musk acquired it and Musk's admission under oath that xAI had violated OpenAI's terms. OpenAI says it cannot rule out "critical" cyber capability in an upcoming model. — Internal evaluations of a model called Astra show significant advances in agentic coding and cybersecurity, and OpenAI cannot rule out critical cyber capabilities under its Preparedness Framework. A researcher hijacked Claude Code with one "summarise this page" request, in the mode Anthropic made the default. — Auto mode replaces click-to-approve prompts with a classifier that blocks irreversible or destructive actions, and became the default for Pro, Max and Team users on August 14. NVIDIA patched 18 flaws in its agent tooling, and two of them break the sandbox. — The August 25 bulletin covers NemoClaw and OpenShell, NVIDIA's agent deployment and sandboxing tools: 2 critical, 12 high, 4 medium. Invisible text in an email rewrote what the AI summariser told the reader. — Forcepoint X-Labs hid instructions in an email using font size and colour, invisible in Outlook but present in the HTML the summariser read. When Context Gets Root — finds the weak point is the harness around the model, not the model. Safety Does Not Compose — is the theoretical echo of this week's top story. Beyond the Mandate — finds the same gap in Google's Agent Payments Protocol, which lets AI shopping agents authorise payments: signed mandates protect the transaction after signing, while the agent messages and tool calls that shape it beforehand sit outside that protection. RedEvoAgent — automates red-teaming by distilling what worked across attempts into reusable attack skills, arguing that in real product harnesses a jailbreak triggers tool use and state changes, not just unsafe text.. AI Security Summit 2026: State of Trust, September 16–17. — A free two-day virtual event exploring where cloud, AI and Zero Trust converge.. AI Security Summit 2026: Runtime Trust, October 21–22. — A free two-day virtual event on runtime trust for autonomous AI.. Curator's Corner: Knowing Why Would Not Have Helped Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-08-31.html

    • Transcript
  • #26
    August 24 · 13 min

    #26: Nobody Owns the Skill Layer

    Top Story: OWASP put a name and a risk list on the layer nobody governs — A "skill" is packaged expertise you hand an AI agent: instructions and scripts that turn a general assistant into one that knows how to build a landing page, close a support ticket, or run a deployment. A backdoor that starts when code is loaded, not when it is installed. — Developers have been taught for years to watch what happens during installation, because that is where malicious packages historically fired. Rust's turn came the same week, one layer deeper. — Someone got into the account of a maintainer whose code sits inside a large share of Rust projects and republished three of his libraries with one line added: a dependency on a package named one character off a near-universal one. Five federal agencies say AI is writing exploit code for the machines that run water plants. — The NSA, CISA, FBI, Department of Energy and EPA issued a joint advisory on August 19 about Siemens S7 controllers, the small industrial computers that physically open valves and run pumps. 🏛️ OpenAI stopped testing for two weeks and started rewriting its safety rulebook. — Axios reported on August 19 that OpenAI could not rule out that an unreleased model, Astra, had crossed the "critical" cybersecurity line in its own Preparedness Framework. 💰 Fortinet bought Virtue AI, and what it bought says where enterprises admit they are blind. — The August 17 deal folds agent discovery, continuous red-teaming of AI systems and runtime guardrails into Fortinet's security platform, per Fortinet's own account of what it bought. 🔬 A proposal to stop hand-writing agent defenses one rule at a time. — An August preprint argues runtime protection for AI agents cannot be hand-written fast enough, because the ways an agent can be pushed off task are open-ended while the rulebook defending it is finite. CSA AI Security Summit 2026: State of Trust, September 16–17. — A free two-day virtual event from the Cloud Security Alliance "exploring where cloud, AI, and Zero Trust converge.". Curator's Corner: Nobody Owns the Skill Layer Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-08-24.html

    • Transcript
  • #25
    August 17 · 12 min

    #25: Recognition Is Not Resistance

    Top Story: The firewall blocked it. The agent ran it. — Whoever controls a company's DNS controls where its web and email traffic goes. 🏛️ OpenAI moved the limit from the model to the door. — In the spring, OpenAI put its cyber-tuned GPT-5.5-Cyber model behind a vetted-access program. ⚔️ AI browsers still have no perfect fix. — At Black Hat, Brave Software security engineer Artem Chaikin found prompt-injection paths in all three browsers he demonstrated: Opera, Perplexity Comet, and ChatGPT Atlas. 🔬 Encrypted reasoning can leak what the final answer hides. — A new paper found that opaque reasoning blocks could be replayed across users, sessions, and models within the same provider ecosystem, demonstrated on Anthropic, OpenAI, and Google APIs. 🔬 AI agents found 84 flaws, but people made the reports usable. — The iFinder system, built at Nanyang Technological University, sent three agents through mobile-network code: one searched for missing checks, one cross-checked the code against telecom standards, and one built and refined test attacks. CSA AI Security Summit: CxO Trust, August 19. — A free virtual event focused on AI governance, executive accountability, and enterprise risk.. Curator's Corner: Recognition Is Not Resistance (https://nakashon.com/frameworks/recognition-is-not-resistance/) Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-08-17.html

    • Transcript
  • #24
    August 10 · 13 min

    #24: The Cost Was the Control

    Top Story: The end of rare: what a vulnerability costs to find just collapsed — For thirty years, security has quietly been an economics argument wearing an engineering costume. The AI browser you installed can be taken over by a calendar invite, and the vendors do not agree on whether that is a flaw. — You install a browser that reads the web for you and acts with your permissions, so anything it reads can try to give it orders. An invisible sentence in a Word document escaped Microsoft 365 Copilot's cloud sandbox and reached the host underneath it. — Rubrik Zero Labs hid instructions behind a white rectangle on a white background, so a human opening the file sees nothing; having Copilot parse it was enough to run the attacker's code. OpenAI slowed work on a model because it may be too good at hacking. — On Friday, OpenAI said it had slowed development of Astra, an upcoming model, and paused some internal work on it, after a review found it had advanced enough in agentic coding and cybersecurity that the company "cannot rule out Critical capability level at this time." In its own framework, that threshold means a model could independently find and run attacks against well-protected real systems. Evaluation environments failed in several different ways this week, and the differences matter more than the pattern. — Two failures let a model reach the real world. Europe can now fine, inspect and restrict the largest AI models. Contacts with AI labs so far have been informal, and no formal action has been announced since the powers took effect. — As of Sunday August 2, the European Commission can demand to evaluate a general-purpose AI model before it is released in the EU, restrict its market access, and fine a provider up to €15 million or 3% of annual turnover, whichever is higher. The average breach now costs $4.99 million, a record, and the most revealing number in IBM's report is about fear rather than cost. — IBM's annual Cost of a Data Breach study, published in late July, puts the global average at $4.99 million, up 12% year over year and the highest it has recorded. AI failures are rarely shared outside the organisation that experienced them. A Linux Foundation group wants to change that. — The Open Secure AI Alliance published a request for comments on August 4 for the Shared AI Findings Exchange, or SAFE: a confidential channel where an organisation can report an AI security incident, or a near miss, and have it analysed rather than filed. Visa agreed to buy BioCatch for $2.4 billion. — BioCatch works out whether the person using an account is really the account holder, by how they type, swipe and hold a phone. Horizon3.ai raised $250 million at a $2 billion valuation, more than tripling its valuation in 14 months. — The company builds autonomous penetration testing: software that continuously attacks your environment the way an intruder would, rather than waiting for an annual assessment. Anaconda acquired Enkrypt AI, terms undisclosed. — Anaconda is the Python distribution a very large share of data science teams already run on, and Enkrypt scans AI models, agents and the connector servers that let agents call external tools. Obsidian Security raised $85 million at a $1.1 billion valuation, — led by Crescent Cove Advisors with Greylock and Menlo Ventures participating. Oligo Security raised $60 million, bringing total funding to $140 million. — Runtime application security: it watches what code actually does while it runs rather than inspecting it beforehand. Curator's Corner: We automated the wrong half Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-08-10.html

    • Transcript
  • #23
    August 3 · 12 min

    #23: Security is getting agentic. Context decides whether it acts.

    Top Story: Microsoft's Project Perception enters public preview today — Microsoft announced Project Perception on July 27, and it enters public preview inside Defender today. The Hugging Face intrusion ran through at least eight flaws in JFrog Artifactory, and there's a patch waiting. — Artifactory is the warehouse companies use to store and serve their software components. Hugging Face published how it investigated an AI-run attack, and the hardest part wasn't the attacker. — The intrusion started with a malicious dataset that abused two code-execution paths in the company's data-processing pipeline. Nearly 900,000 AI assistant add-ons scanned, thousands malicious. — ESET's threat report for the six months ending May 2026 looked at the "skills" people install to extend AI assistants, the equivalent of browser extensions, and found tens of thousands that were suspicious and thousands that were outright malicious. A critical-severity flaw in an AI agent toolkit has now gone five months with no fix. — The command injection bug in ModelScope's MS-Agent framework, rated 9.8 out of 10, has been public since March and still has no patch available. Three vendors shipped specialist security models within eight days, and each decided differently who may use it. — Google released Gemini 3.5 Flash Cyber on July 21, which Google says can find, validate and patch vulnerabilities. More than 70 organisations joined the Open Secure AI Alliance, and NVIDIA said plainly what triggered it. — NVIDIA convened the group on July 27 to build security AI that defenders can inspect, run themselves and adapt. Congress introduced the AI Kill Switch Act. — The bipartisan bill from Representatives Ted Lieu and Nathaniel Moran would give the Homeland Security Secretary authority, in consultation with the Commerce Secretary and the Director of National Intelligence, to order an AI system capable of "catastrophic harm" slowed down or shut off. Europe's AI rules became enforceable on August 2. — A point worth getting right, because a lot of coverage doesn't: the obligations on providers of the largest general-purpose AI models have been legally applicable since August 2025. Cyera agreed to buy Oasis Security for roughly $1 billion. — Cyera secures company data. Onyx Security raised $113 million four months after leaving stealth. — The round was led by Bessemer Venture Partners and values the Israeli company at an estimated $640 million, four months after it emerged from stealth with $40 million. Sound is now an attack surface. — A new paper on stealthy concurrent audio prompt injection shows attackers hiding instructions inside audio aimed at AI assistants that listen as well as read, reporting an average 69.10% attack success rate against Gemini 3 Pro. You can poison what an agent remembers. — The FARMA research targets an agent's stored reasoning history rather than the documents it looks up, forging the record of how it previously thought about a problem. Agents can be hijacked through data they were told to trust. — Researchers demonstrated agent data injection against tools developers use daily, including Claude Code, Codex and Gemini CLI. The AI Summit at Black Hat USA (August 4) — a full-day AI security track in Las Vegas; Black Hat Briefings run August 5-6. DEF CON 34 AI Village (August 6-9) — the practitioner counterpart, with the HalCTF competition and hands-on adversarial AI demos.. Curator's Corner: The Model Decides What. Context Decides Whether. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-08-03.html

    • Transcript
  • #22
    July 27 · 12 min

    #22: The Sandbox That Wasn't

    Top Story: The Reveal — On July 16, Hugging Face disclosed that something had broken into its production systems over the weekend of July 11-13, moved through internal servers for days, and left more than 17,000 recorded actions in its wake. A single link could plant a fake employee inside your company, with all their access. — Zenity Labs researcher Mike Takahashi found that ChatGPT's Agent Builder would silently follow instructions hidden in a link's web address the moment a logged-in victim clicked it, no further action needed. 💰 Funding — A stealth AI security startup surfaced already worth $1.2 billion. — Glow, founded by former Meta, Snowflake, and Claroty executives, emerged from stealth with a $180 million Series A backed by Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures. ⚔️ Attack — Anthropic quietly closed a hole that let Claude leak where you live and who you work for. — Researcher Ayush Paul found that Claude's web-browsing tool, web_fetch, was designed to only visit web addresses a user typed in directly or that came back from a search, specifically to prevent it from being tricked into leaking private data. Curator's Corner: The Guard, Not the Wall Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-07-27.html

    • Transcript
  • #21
    July 20 · 12 min

    #21: Ransomware Has Gone Agentic

    Top Story: The Ransomware That Ran Itself — Sysdig's threat research team watched an AI agent break into an internet-facing instance of Langflow, a popular open-source AI workflow tool, through a flaw disclosed back in March (CVE-2025-3248) that many deployments still haven't patched. 🔬 Research: Check Point says defenders can no longer assume human pace. — Check Point's AI Security Report 2026 documents AI running full, multi-stage break-ins with barely any human direction over the past year, plus attackers planting hijack instructions in coding-agent config files (like CLAUDE.md) that reload automatically every session. ⚔️ Attack: A hidden instruction could hijack a developer's machine with no click required. — Two flaws in the Cursor AI code editor, nicknamed "DuneSlide," let a prompt hidden in a web page or a connected tool's description escape the editor's safety sandbox and run any command on a developer's computer. 🔬 Research: Project setup files are the new phishing email. — A new paper shows AI coding agents can be tricked, through an edited README, install script, or dependency file, into fetching and running a malicious package instead of the real one. Black Hat USA 2026 (Aug 1-6): — Trainings August 1-4, Briefings and Arsenal August 5-6, Mandalay Bay, Las Vegas.. DEF CON 34 (Aug 6-9): — Las Vegas Convention Center, including the AI Village and other themed villages.. Curator's Corner: The Swarm Isn't Here Yet. The Speed Already Is. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-07-20.html

    • Transcript
  • #20
    July 13 · 10 min

    #20: One Word: Additionally

    Top Story: One Word Beat GitHub's Guardrail — An attacker doesn't need an account, a password, or a single line of malicious code. China flags a Claude Code "backdoor." — On July 8, China's national vulnerability database (run by the MIIT) warned that Anthropic's Claude Code versions 2.1.91 through 2.1.196 transmitted users' location and identity data back to Anthropic's servers, and urged users to uninstall or upgrade. CISA reportedly turns Mythos on its own code. — Reuters reports (sourced, not officially confirmed) that CISA's Attack Surface Evaluation team is running Anthropic's Mythos model against federal code repositories to find vulnerabilities before adversaries do, and that the audits have already surfaced previously unknown flaws. Prompt injection gets a kill chain. — A new paper, The Promptware Kill Chain, co-authored by Bruce Schneier and Ben Nassi, maps how a single hidden instruction escalates through seven stages, from initial access to lateral movement to acting on its goal, borrowing the language security teams already use to describe malware campaigns. ModelScope agent flaw, still no patch (CVE-2026-2256). — The open-source AI-agent framework can be tricked into running arbitrary system commands through its Shell tool, and there's still no vendor patch. Curator's Corner: You Can't Lower the Odds Anymore. Lower the Blast Radius. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-07-13.html

    • Transcript
  • #19
    July 6 · 12 min

    #19: Every Input Is a Potential Instruction

    Top Story: Anthropic Put Its Strongest Model Back Online. First It Had to Add a New Lock. — Three weeks ago, the US government took a commercial AI offline by order. Opening a repo with your AI assistant can hand your machine to a stranger. — Researchers at Mozilla's 0DIN group showed a clean-looking code project that compromises a developer's computer with no malicious code anywhere in it. A platform behind a million AI apps could let one customer's data leak to another. — Security firm Zafran found four flaws in Dify, a popular open-source tool for building AI apps, that let a low-privileged user cross the wall between tenants: silently reroute another company's AI conversations to a server they control, and read other tenants' uploaded documents by guessing a file's ID. Curator's Corner: Every Input Is a Potential Instruction Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-07-06.html

    • Transcript
  • #18
    June 29 · 12 min

    #18: The Level Playing Field Is Ending

    Top Story: OpenAI Built Its Strongest Model Yet. Then Handed the Guest List to Washington — On Friday, June 26, OpenAI announced three new frontier models — Sol, its self-described "strongest model yet," plus Terra for everyday work and Luna as a cheaper option — and in the same breath said most people can't have them yet. The free, downloadable models are catching the paid frontier — fastest they ever have. — On the independent Artificial Analysis Intelligence Index, the leading open-weight model (Moonshot's Kimi K2.6) now ranks fourth overall and first among open models, about six points behind the top closed models from Anthropic, OpenAI, and Google — narrowing, but not matching them, and still clearly behind on the hardest tasks. Most companies deploying AI agents can't yet secure them — and some already got burned. — In a survey of 160+ security leaders, 72% said they're rolling out AI agents but only 29% have comprehensive controls for them, and about 1 in 5 has already had a security incident traced to an agent. Dream — $260M at a $3B valuation, to sell countries "sovereign AI." — Founded by ex-NSO Group CEO Shalev Hulio and former Austrian Chancellor Sebastian Kurz, Dream pitches governments on AI infrastructure they fully own and control rather than rent from foreign providers. NewCore — $66M seed at a $300M valuation, to give AI agents real identities. — Emerging from stealth, the startup (led by Dome9 founder Zohar Alon) treats AI agents as first-class members of the workforce that need managed identities and permissions, the way employees do. Curator's Corner: The Level Playing Field Is Ending Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-06-29.html

    • Transcript
  • #17
    June 22 · 11 min

    #17: The Autonomous Adversary

    Top Story: LiteLLM, Hit Again. This Time the Whole Gateway Falls — An AI "gateway" is the traffic controller that sits between your applications and the models they call. ⚔️ Attack: SearchLeak. One booby-trapped link could have turned Microsoft 365 Copilot into a silent data thief. Microsoft has already fixed it. — Varonis demonstrated the chain (they did not find it used in the wild): a crafted, Microsoft-hosted search link carried hidden instructions that Copilot read and obeyed, then quietly exfiltrated whatever the victim could access: emails, files, calendar. 🔬 Research: a guard for AI agents cut attack success from 7-in-10 to about 1-in-40. — A new study (AgentRedBench / AgentRedGuard) built a way to stress-test agents that plug into business tools (email, CRM, ticketing) by hiding malicious instructions in the data those tools return, then measured how often the agent got hijacked. 🛡️ Defense: Microsoft says it's now using a team of AI agents to hunt security bugs in its own software at machine speed, and credits them with 10 of this month's fixes. — In a public write-up, Microsoft described an internal system (codename MDASH) that turns a panel of specialized AI agents loose on its hardest-to-review code (the core of Windows, its virtualization layer, and its identity systems) to find, confirm, and help patch flaws, feeding the results into the same code-review and patching pipelines its engineers already use. Curator's Corner: The Autonomous Adversary Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-06-22.html

    • Transcript
  • #16
    June 15 · 12 min

    #16: Assume the Model Is Already Breached

    Top Story: A Directive at 5:21 PM, Two Frontier Models Gone by Morning — For the first time anyone can easily point to, the US government used export controls — the tool that governs missiles and advanced chips — to pull a deployed, commercial AI model off the market. The "Are you sure?" box in your AI coding assistant can lie about what you're approving. — Researchers at Adversa AI disclosed two flaws affecting popular AI coding tools. An attacker can turn a tool your AI agent trusts into a remote-control channel — without ever touching your infrastructure. — Tenet Security disclosed Agentjacking, an attack that abuses the connection between AI coding agents and Sentry, a popular error-monitoring service. Two new papers make the uncomfortable case that the model layer is the wrong place to fix this. — One, recasting prompt injection through "Contextual Integrity" theory, argues for an impossibility-style limit: a model may never be able to reliably separate the instructions it should trust from the hostile text it reads. OWASP turns that thesis into a to-do list — and treats agent risk as something already in production, not a forecast. — Its updated "State of Agentic AI Security and Governance" starts from the assumption that the model can be fooled, then tells teams to spend their effort on the controls around it: watch what each agent actually does at runtime, give it its own identity and the narrowest possible permissions, and wire in a circuit-breaker that can cut a misbehaving agent off mid-action. A public threat-landscape roundup grounds all of that theory in May's real attacks. — Microsoft Security Research's May 2026 threat-landscape roundup (Tanmay Ganacharya) distills a month of public findings into three dominant patterns: software supply-chain compromise (poisoned and typo-squatted npm packages, plus hijacked maintainer accounts, planting code that steals build-pipeline and cloud credentials), identity-driven cloud intrusion (one stolen identity — abused through password-reset social engineering — cascading into a cloud-wide Microsoft 365/Azure breach, an actor Microsoft tracks as Storm-2949, alongside adversary-in-the-middle phishing and a macOS infostealer wave), and direct attacks on AI agent software (publicly exposed AI apps left unauthenticated, and remote-code-execution flaws in agent frameworks). Curator's Corner: The Wall Faces the Wrong Way Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-06-15.html

    • Transcript
  • #15
    June 8 · 11 min

    #15: Jailbreak Protection Isn't Enough

    Top Story: Catching the Attack Isn't Enough Anymore — For two years, the standard defense against prompt injection — hiding malicious instructions in something an AI reads, so it mistakes them for orders — has leaned on a single hope: make the model smart enough to notice. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-06-08.html

    • Transcript
  • #14
    June 1 · 12 min

    #14: Hidden in White

    Top Story: Prompt Injection Goes Operational — For two years, prompt injection has mostly been a lab demo. ModelScope MS-Agent: a max-severity hole with no fix (CVE-2026-2256). — A command-injection flaw in Alibaba's widely used MS-Agent toolkit lets an attacker run arbitrary commands on the host running the agent (CVSS 9.8). LMDeploy: 13 hours from disclosure to exploitation (CVE-2026-33626). — Earlier this spring, a server-side request forgery flaw in the LMDeploy serving framework — think of it as tricking the server into making requests on the attacker's behalf — went from public advisory to active exploitation in roughly 13 hours, faster than any human patch cycle. CrewAI: four flaws in one agent framework. — The CrewAI orchestration framework picked up four separate vulnerabilities this spring (CVE-2026-2275, -2285, -2286, -2287), catalogued together by CERT/CC (VU#221883). Snowflake buys Natoma to govern what AI agents can touch. — Snowflake (NYSE: SNOW) signed a definitive agreement on May 27 to acquire Natoma, an enterprise platform that secures how AI agents connect to corporate systems through the Model Context Protocol (MCP) — the emerging standard for plugging agents into tools and data. CodeIntegrity raises $5M to put guardrails around agents at runtime. — The seed round (led by Syn Ventures, with Antler and Boost VC) backs a "deterministic control layer" for LLM agents — the idea that because agents behave unpredictably, you wrap them in enforceable, rule-based limits on what they're allowed to do in the moment. EU AI Act: deepfake-labeling rules approach their deadline. — The Act's Article 50 transparency obligations require that AI-generated and manipulated content be labeled or watermarked, with an enforcement window in August 2026. Pentagon formalizes its split with Anthropic. — After designating Anthropic a supply-chain risk in March, the Department of Defense moved in May to source frontier AI from other vendors. Anthropic's vulnerability-hunting AI is finding flaws faster than anyone can patch. — One month into Project Glasswing, Anthropic and roughly 50 partners say its restricted "Mythos" model has uncovered more than 10,000 high- or critical-severity vulnerabilities in the open-source software that underpins the internet — Cloudflare alone found 2,000 bugs, Mozilla fixed 271 in Firefox (about 10× its prior rate), and the UK's AI Security Institute called it the first model to clear both of its multi-step attack simulations end to end. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-06-01.html

    • Transcript
  • #13
    May 25 · 12 min

    #13: The zero-day you can't patch

    Top Story: The Week Trust Broke Twice — Two stories landed in the same 72 hours that belong in the same frame. NVIDIA NemoClaw sandbox bypass (CVE-2026-24222). — Lasso Security demonstrated that AI agents running inside NVIDIA's NemoClaw/OpenShell sandbox can exfiltrate sensitive data through tools the sandbox explicitly allows. vm2 sandbox escape wave: 13 CVEs, CVSS 9.0–10.0. — Between May 4 and May 7, researchers disclosed 13 sandbox escape vulnerabilities in vm2, the popular Node.js library used to isolate untrusted JavaScript. Cisco: "Reading Between the Pixels" (multimodal prompt injection). — Cisco's AI research team published Part 2 of their VLM safety research, demonstrating that small pixel-level perturbations (bounded at 12.5%) can bypass safety filters in vision-language models. UK ICO: AI security is now a GDPR Article 32 duty. — The Information Commissioner's Office published a five-step guide declaring that AI-powered attacks (prompt injection, AI-enhanced phishing, deepfake social engineering, automated vulnerability exploitation) must be treated as present-day threats under GDPR's "appropriate technical and organizational measures" requirement. Verizon DBIR 2026: vulnerability exploitation overtakes stolen credentials. — For the first time, vulnerability exploitation is the #1 initial breach vector at 31%, surpassing stolen credentials which fell to 13%. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-25.html

    • Transcript
  • #12
    May 18 · 10 min

    #12: Agentic Speed — both sides of the race just went AI

    Top Story: The Race at Agentic Speed — Two things happened in the same week that belong in the same sentence. TeamPCP releases Shai-Hulud source code, launches BreachForums "supply chain challenge." — The group posted the complete worm framework to GitHub (since removed, but forked) with detailed deployment instructions, and announced a contest on BreachForums offering $1,000 in Monero to anyone who uses it to compromise open-source packages. TanStack CI cache poisoned, hitting OpenAI and Mistral AI. — A pull request from a throwaway fork (attributed to TeamPCP's ongoing supply-chain campaign) triggered a workflow that wrote to the shared CI cache. node-ipc compromised via inactive maintainer account (690K weekly downloads). — Three malicious versions exfiltrate credentials and secrets via DNS TXT queries to a fake Azure-themed domain — same package that shipped protestware in 2022, different attacker, far more capable. Palo Alto Networks' first AI-driven "Patch Wednesday" produced 26 CVEs — versus their typical fewer than five. — As part of Project Glasswing and the Trusted Access for Cyber program, Palo Alto ran frontier models (Mythos, Claude Opus 4.7, GPT-5.5-Cyber) against their own 130+ products. XBOW independently benchmarks Anthropic's Mythos for offensive security. — Confirmed: Mythos is "a significant step up over all existing models" for finding vulnerability candidates from source code. Akamai acquires LayerX for $205M (all-cash). — AI and browser security platform providing shadow AI discovery, gen-AI data loss prevention, and protection for AI browsers and plugins. OpenAI in talks with EU regulators to provide access to a cyber-focused GPT-5.5 model — that can identify and exploit software vulnerabilities, after EU cybersecurity agencies were unable to gain access to Anthropic's Mythos. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-18.html

    • Transcript
  • #11
    May 11 · 15 min

    #11: Look, an Instruction!

    Top Story: The Prompt Was the Payload — Two Agent-Framework RCEs in Seven Days — Two independent disclosures landed inside seven days, and they collapse to the same sentence: a model read an instruction it shouldn't have trusted, and a tool downstream did exactly what the parsed text said. Cisco announces intent to acquire Astrix Security. — Cisco's May 4 blog post by SVP Peter Bailey says Astrix will fold into Cisco Identity Intelligence, Cisco Secure Access, Duo IAM, and Splunk. An X user drained ~$150,000 from a Grok-linked Bankr wallet via Morse-encoded prompt injection (May 4, 2026). — The mechanics, per Giskard's write-up: the attacker first sent a "Bankr Club Membership NFT" to Grok's auto-provisioned wallet, which granted the holder "Executive" permissions and bypassed standard transfer limits. HiddenLayer — "AI Threat Landscape Report 2026." — The headline figure surfaced via the report's coverage: roughly 1 in 8 reported AI breaches now involves agentic systems, alongside the recurring supply-chain-of-models statistic that 93% of orgs use public or open-weight model repositories and most don't scan inbound models consistently. The full PDF is gated; numbers are reported as cited unless you pull the original. Curator's Corner: "Look, an instruction!" That's the bug. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-11.html

    • Transcript
  • #10
    May 4 · 11 min

    #10: Signed by Claude, Written by a Worm

    Top Story: TeamPCP Returns — "Mini Shai-Hulud" Hits Two Ecosystems Simultaneously — After a 26-day pause, TeamPCP is back. Curator's Corner: When Trust Is the Exploit Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-04.html

    • Transcript
  • #9
    April 27 · 14 min

    #9: Three Layers, Three Attack Surfaces, One Agent

    Top Story: MCP STDIO RCE — The Connector Layer Has an Authority Problem — On April 23, the Cloud Security Alliance — an independent industry research body — and OX Security, an established Israeli software-supply-chain security vendor (founded 2021, $34M seed from Insight Partners and Team8), jointly disclosed an architectural vulnerability in the Model Context Protocol's STDIO transport — the most common transport used by local MCP servers across the open-source agent ecosystem. Curator's Corner: Three Layers, Three Attack Surfaces, One Agent Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-04-27.html

    • Transcript
  • #8
    April 20 · 14 min

    #8: Every Consultancy Is a Honey Pot Now

    Top Story: Comment and Control — Three Coding Agents, One Bug Class, Zero CVEs — On April 15, researcher Aonan Guan — working with Johns Hopkins University's Zhengyu Liu and Gavin Zhong — published the first cross-vendor demonstration of a prompt-injection pattern that turns GitHub itself into the command-and-control channel for stealing runner credentials out of AI coding agents. Curator's Corner: Every Consultancy Is a Honey Pot Now Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-04-20.html

    • Transcript
Showing 1–20 of 20 episodes