Skip to content
Artwork for Crying Out Cloud

Crying Out Cloud

Wiz

Welcome to "Crying Out Cloud," the monthly podcast that keeps you up to date with the latest cloud security news. Hosted by experts Eden Naftali and Amitai Cohen, each episode provides in-depth coverage of the most important vulnerabilities and incidents from the previous month. Tune in for insightful analysis and expert recommendations to help you safeguard your cloud infrastructure.

Play
  • 20 episodes
  • Avg 26 min
  • English
  • S4 · E6
    August 9 · 28 min

    Empowering Human Potential, AI in Cybersecurity & Scaling Operational Growth with Daniel Miessler

    AI is changing the security landscape, but are we automating the wrong things? On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Daniel Miessler to unpack why most companies are completely unprepared for the AI revolution. Daniel drops some heavy truths about what happens when we automate the "boring" parts of security, and why attackers are currently winning the AI arms race. What's Inside: - The "Gym Robot" analogy for operational toil and analyst training - Why attackers are moving 10X faster with AI than defenders - The TELOS framework and defining your security goals in text

  • S4 · E5
    August 2 · 20 min

    WordPress RCE, GitHub vs TeamPCP & Why Meta Disabled Its Support Bot

    On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down to unpack the wildest cloud security news of the month: from AI chatbots going rogue to massive supply chain battles. What's Inside: - The WP2Shell vulnerability and why 60% of WordPress instances were at risk - GitHub's aggressive mitigations to combat TeamPCP's supply chain attacks - Why 20-year-old vulnerabilities like SquidBleed are suddenly being unearthed by AI - The Klue hack and the hidden dangers of over-privileged AI agents in Salesforce - How attackers bypassed Meta's security using VPNs, deepfakes, and a gullible AI support bot

  • S4 · E4
    July 2 · 29 min

    Autonomous AI Malware, Threat Actor Startups & Beating Burnout with John Hammond

    AI-Powered Malware and the Future of Threat Hunting On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with John Hammond to unpack the reality of autonomous AI hacking and why cybercriminals are operating like Fortune 500 startups. 1. Why modern ransomware groups have sales teams, HR, and go-to-market strategies. 2. How autonomous AI agents are finding zero-days while researchers sleep. 3. Glimpsing the future of non-deterministic, AI-driven command and control (C2) servers. 4. Real talk on incident response burnout and why the "always-on" hustle is breaking defenders.

  • S4 · E3
    May 20 · 50 min

    The Linux CopyFail Vulnerability & AI Bug Hunting with Xint

    The AI bug hunting revolution is here, and it just broke Linux. On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Tim Becker and Jacob Newman from Xint to unpack CopyFail, a powerful vulnerability found using autonomous AI agents. 1. How Xint's custom LLM harness uncovered CopyFail, a privilege escalation bug affecting almost every Linux machine since 2017. 2. The harsh reality of vulnerability disclosure in the AI era and why 90 days is too long when models can weaponize exploits instantly by patch-diffing. 3. The evolution of AI agents in security, from the DARPA AI Cyber Challenge to Claude 3.5 Sonnet to Mythos. 4. The importance of benchmarking in agentic workflows.

  • S4 · E2
    May 1 · 13 min

    Hacking GitHub with a Semicolon & Claude with Sagi Tzadik

    Wiz researcher Sagi Tzadik joins us to break down how a single semicolon led to a critical Remote Code Execution (RCE) vulnerability in GitHub. For two years, Sagi sat on a lead. Reverse engineering GitHub's microservices manually was too tedious to justify the time. Then, AI agents arrived. By hooking Claude directly into his reverse engineering software, he condensed months of grueling binary analysis into 48 hours. The result? A critical bug in how GitHub handles git push options that exposed both SaaS and Enterprise environments. We get into the weeds on how different microservices interpreting the same input differently creates massive attack surfaces, and why security by obscurity is officially dead in the age of AI. What's Inside: - How combining Claude with the IDA MCP server dramatically sped up the reverse engineering process - The technical anatomy of the GitHub semicolon vulnerability. - Why microservice communication breakdowns lead to critical RCEs. - The massive difference in impact between GitHub.com and GitHub Enterprise Server. - Why Enterprise users need to patch their instances immediately. Resources: - Learn more about the findings at: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

    • Transcript
  • S4 · E1
    February 24 · 39 min

    Protecting Vibe Coded Apps and the Shift to "Soft Guardrails" with Igor Andriushchenko

    Igor Andriushchenko joins Crying Out Cloud to explain how vibe coding changes the role of security engineers. The shift from typing lines of code to shaping entire systems means security teams need new strategies. Developers expect their shipping velocity to increase tenfold with AI assistance. Relying on traditional hard deployment blocks will only cause friction. If you want to understand how to build secure guardrails for AI development without destroying developer momentum, this conversation covers the exact mechanics. What's Inside: The evolution of the Stockholm tech scene and human ambition driven by AI. How Lovable empowers non-developers to build disposable and deeply specific software. The concept of "soft guardrails" and why hard blocks fail in AI-assisted workflows. Future capabilities of AI pen testing using hundreds of autonomous agents. The shared responsibility model when business users build internal applications.

    • Transcript
  • S3 · E19
    February 12 · 24 min

    Neuroscience, AI Research & Hiring Swifties with Alon Schindel

    Agentic AI is coming. Are defenders ready? Alon Schindel, Director of Data & Threat Research at Wiz, joins Eden and Amitai for the Season 3 Finale. This isn't just a recap. It is a look at how top-tier research teams operate at speed. Alon explains why Wiz treats research as a "product" rather than a support function. He details the "DeepLeak" discovery where his team found thousands of exposed API keys mere hours after a platform's popularity spiked. What's Inside: Agentic AI: Why 2026 will be the year AI starts taking action, not just chatting. Speed as a Weapon: How to shorten the time between a zero-day and a detection. Culture: The power of the "Table" and collaborative chaos. Retrospective: Lessons from IngressNightmare and the year in vulnerabilities. Resources: Read the DeepLeak Research: https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak Wiz Threat Research Hub: https://www.wiz.io/research

  • S3 · E18
    February 3 · 12 min

    Hacking Moltbook with Gal Nagli

    🚨 Vibe coding meets critical data exposure: The Moltbook Hack. On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Wiz researcher Gal Nagli to unpack how he compromised the "Facebook for AI Agents" in under an hour ↓ How a simple boolean manipulation (valid: false to true) bypassed authentication Cloud Database misconfigurations and the failure of Row Level Security (RLS) How Claude Code was used to identify and exploit the vulnerability The security reality of "Vibe Coding" and zero-manual-code applications

  • S3 · E17
    January 15 · 17 min

    CodeBreach: Hijacking the AWS Console with Yuval Avrahami

    🚨 Everything you need to know about CodeBreach with Yuval Avrahami On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Wiz researcher Yuval Avrahami to unpack a major supply-chain flaw that put cloud environments at risk ↓ Misconfigured CodeBuild instances used by AWS themselves One small regex mistake, huge consequences How an SDK used by the AWS Console could have been hijacked (!) The CI/CD controls that can mitigate this risk

    • Transcript
  • S3 · E18
    January 1 · 19 min

    React2Shell, Shai-Hulud 2.0, Gogs Zero-Day & Tika RCE

    🎙️ Shai-Hulud, Shai-Hulud 2.0, are you keeping up? In this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen go deep into real-world cloud security incidents ↓ How Shai-Hulud evolved into Shai-Hulud 2.0 A vulnerability affecting Apache Tika React2Shell and its implications Gogs zero-day explained You DONT want to miss this! This is a technical, concrete conversation focused on how attacks actually happen, how they evolve, and what defenders need to understand to keep up.

    • Transcript
  • S3 · E17
    Dec 8, 2025 · 22 min

    Live Talk: Security Minds from Google Cloud, AWS & Wiz

    🎙️ AI is changing the rules of cyber, are you keeping up?Eden Naftali goes live with leading voices in cloud security:Ryan Nolette (AWS), @John Miller (Google Cloud), and Alon Schindel (Wiz). This episode is essential listening for anyone defending at cloud scale. 👇🔍 Inside ↓1) How AI is supercharging attacker tactics — from hyper-variable phishing to rapid exploit generation2) The rise of "AI slop" and why it's burning analysts' time3) Emerging AI bug-hunters — what they can (and can't) do

    • Transcript
  • S3 · E16
    Nov 14, 2025 · 25 min

    Cloud Detection Engineering, AI in the SOC and Parallel Parking with Alex Hurtado

    Detection engineering just got real! Eden Naftali and Amitai sit down with detection engineering powerhouse Alex Hurtado - and it's a must-listen for anyone in cloud security. 👇 🔍 What's inside: The evolution of detection engineering in the cloud — and why traditional rules no longer apply Why DIY detections > vendor defaults How AI is reshaping detection and threat hunting (and why the human in the loop still wins)

    • Transcript
  • S3 · E15
    Nov 7, 2025 · 29 min

    VSCode Extension Secrets, RediShell, & Living-off-the-LLM

    🔍 From discovering VS Code supply chain risks → to uncovering Redis Shell vulnerabilities. Eden Naftali and Amitai sat down to unpack: 👇 How VS Code extensions became a critical supply chain risk (w/ Rami McCarthy) What RediShell reveals about attacker innovation Where AI is being weaponized in modern malware 🎙️ Listen now to our NEW Crying Out Cloud episode

    • Transcript
  • S3 · E14
    Sep 16, 2025 · 33 min

    eBPF, Fishy Book Covers, and Open Source Security with Liz Rice

    🚨 The kernel-level security revolution you can't ignore — a must-listen with Liz Rice Eden Naftali and Amitai sit down with Liz Rice, Chief Open Source Officer at Isovalent (Cisco), and a global expert in eBPF, containers, and Kubernetes security. 🎙️ In this episode: How eBPF is reshaping cloud security from the ground up Practical strategies to tackle open source supply chain attacks (a hot topic given today’s events) A must-listen for anyone building or securing cloud infrastructure in an era of AI coding and supply chain attacks.

    • Transcript
  • S3 · E13
    Aug 18, 2025 · 28 min

    Security Metrics, Detection & Response & Paintball with Erik Bloch

    🔐 Erik Bloch on his path from military hacker to Illumio security leader. Eden Naftali and Amitai sat down with Erik Bloch & here's what they covered 👇 How starting in the military shaped Erik's approach to security Building and scaling cloud detection & response teams Converting security metrics into actionable business KPIs

    • Transcript
  • S3 · E12
    Aug 1, 2025 · 28 min

    Adversary Emulation, Cyber Education & Community Building with Day Johnson

    🚨 How do you build a 4,000+ strong student-tech community from scratch?Eden Naftali and Amitai sat down with Day Johnson, Security Engineer at @amazon , ex-Datadog, founder of CyberWox Academy.What they covered 👇- Detection engineering that works at scale- What breaks IR processes (and how to fix them)- Real talk on breaking into security without shortcutsAlso: why being the "tech kid" in your neighborhood might just launch your whole career.

    • Transcript
  • S3 · E11
    Jul 15, 2025 · 39 min

    Live Talk: Security Minds from Riot Games, Microsoft & Wiz

    💡 From cloud chaos to career confessions: live with security minds from RiotGames & Microsoft. Eden Naftali went live, and got personal, with 3 leaders shaping the future of cloud and cybersecurity: Nicole Dove, Head of Security Engineering at @Riot Games Sherrod DeGrippo, Director of Threat Intelligence Strategy at Microsoft Alon Schindel, VP of AI & Threat Research at Wiz What they unpacked? 👇 The heart of threat intel, building trust over tools, and how hobbies reflect how they lead. This Crying Out Cloud episode from RSA just hits different. ⏱ Chapters 00:05:02 – What it means to be a threat intelligence leader 00:10:08 – How threat intelligence should really look 00:15:48 – Skirting the tough questions in cybersecurity 00:21:07 – Working with third-party vendors in the cloud 00:26:17 – What the security industry is getting wrong 00:31:20 – The special skill of deep research 00:36:20 – A real-world story about leading with trust #CyberSecurity #CloudSecurity #ThreatIntelligence #Infosec #CloudComputing

    • Transcript
  • S3 · E11
    Jul 9, 2025 · 17 min

    AI Double Agents to Blame, Scattered Spider Pivots to Planes

    🎙️ Scattered Spider's new target? Airlines.Eden Koby Naftali & Amitai Cohen break down the latest in the cloud:1️⃣ A connectivity tool vuln & Open WebUI misconfig putting orgs at risk2️⃣ Why attackers are still tricking help desks (and how!)3️⃣ The "lethal trifecta" of AI agent danger, explained 🧠🤖0:25 – Scattered Spider targets the aviation industry1:38 – Help desk hacks: impersonation & real-world stories4:52 – Teleport vulnerability explained9:48 – AI’s “lethal trifecta” and why it matters#CloudSecurity #ScatteredSpider #AIThreats #HelpDeskAttacks #CryingOutCloud #CybersecurityPodcast

    • Transcript
  • S3 · E10
    Jun 25, 2025 · 27 min

    Pyramid of Pain, PEAK, and Bagpipes with David Bianco

    🎙️ New ep: David Bianco from Splunk with 🔥 insights from a lifetime of threat hunting.Eden Koby Naftali & Amitai Cohen sat down with David Bianco, creator of some of the most influential models in cyber detection.What they got into ⬇️1) How a threat intel milestone led to the Pyramid of Pain2) Why detection isn't just about indicators3) What good threat hunting teams actually do#CryingOutCloud #CyberSecurity #ThreatHunting #PyramidOfPain #DavidBianco #Splunk #Infosec #CloudSecurity #DetectionEngineering #BlueTeam #SecurityPodcast #SOC #ThreatIntel #IncidentResponse

    • Transcript
  • S3 · E9
    May 29, 2025 · 25 min

    AI-powered Security, Shared Fate, and an Archery Lesson with Dr. Anton Chuvakin

    🎙️ Just dropped: Dr. Anton Chuvakin‬ from Google Cloud, with legendary insights (and cloud security jokes).Eden Koby Naftali & Amitai Cohen sat down with Dr. Anton Chuvakin, Google Cloud's Office of the CISO, and the guy who made SIEM cool!What they got into ⬇️ 1) Why SOCs are broken (and full of toil)2) How to actually apply AI in security3) Why cloud appliances are still a problem4) What shared responsibility really means

    • Transcript
Showing 1–20 of 20 episodes