Everything Yinon Costica said on any show that made the record, most notable first. Each card names its show and opens the statement there.
Costica: Most AI security incidents stem from insecure cloud infrastructure
“Actually, when we look at AI related incidents, the majority of them is within this layer of Using the infrastructure in an insecure manner that allows threat actors to just do what they are used to do in cloud in the past.”
Costica: Vibe coding does not absolve developers of understanding their code
“The way I'm looking at it is that vibing code is a great way to accelerate, but it doesn't remove you from the responsibility of actually knowing your code, being able to address issues within the code, and guide AI farther into the, you know, maintenance proc…”
Costica: AI automation disproportionately benefits cyber attackers over cybersecurity defenders
“And now with AI, the interesting thing that the threat actors can automate a lot more, but from a defense perspective, it doesn't give me the same order of magnitude of, let's say, improvement that the threat actor can gain. So, in essence, there is an aggrava…”
Costica: AI currently only accelerates automation of existing cyber risks
“AI is another layer that allows us to automate more right now. Okay, I'm not talking, because we're not seeing the crazy new threats yet, we are right now at the phase where we're seeing accelerated automation of the known threats, known risks, and this is a j…”
Costica: DeepSeek's database leak was a typical cloud exposure, not an exotic exploit
“It was a very, ah, what I would say, typical exposure that exposed a lot of sensitive data, but yet, ah, if we look historically, there were similar incidents, for instance, with Microsoft releasing a token that had access to sensitive data in, you know, a buc…”
Costica: Four of six AI technologies at Pwn2Own had critical RCE vulnerabilities
“Six technologies were presented. Out of these six technologies, four were actually Researched and found to be vulnerable at what we call the highest impactful vulnerability, which is remote code execution, RCE, which means that you can do anything with the tec…”
Costica: Ransomware groups reliably return data to protect their business reputation
“If you think about ransomware, it's a business. It has rules to it, right? You know, when you pay the ransom, you get the data, right? It's a rule. You don't, you're not tricked into it because it's a business and they need to maintain their reputation.”
Costica: AI Security Is Being Addressed Much Earlier Than Prior Tech Waves
“And the concepts behind, I think, today, AI security are actually well thought today rather than much later. And it shows a bit on the maturity of not only the security teams, by the way, it shows a lot on the maturity of the industry that we are having the di…”
Costica: AI security relies on standard cloud infrastructure fundamentals
“When we think about AI, it's not all new. It's new software. It's existing infrastructure. And when we think about securing it, the basics apply. And it's very important to remember it. The fundamentals apply. The fundamentals of patching vulnerabilities, secu…”
Costica: Security teams must prioritize foundational hygiene over alert detection
“It's actually reducing the noise by investing more in the fundamentals and less on the detection. Ok, so if we are always trying to detect It's going to be hard. We're going to be bombarded with alerts. If we're proactively reducing the risk and the chance of …”
Costica: Vulnerability research is the primary bottleneck in cybersecurity
“The ability to research and find vulnerabilities, this is kind of the bottleneck of the security space, ok? Because vulnerabilities are what allow threat actors to move from, you know, lower trust to higher trust environments”
Costica: Almost 10% of organizations adopted DeepSeek within one week
“Within a week, almost 10% of organizations were using DeepSeq.”
Costica: Hackers steal encrypted data now to decrypt with future quantum computing
“I think the one thing that has changed around quantum computing is a sort of, maybe it is closer than we think, and then the threat actors are, you know, stealing data now, so they will be able to decrypt it later once they, you know, figure it out.”
Costica: Cybersecurity cannot scale without democratizing responsibility to all employees
“Because if we think about just security teams doing security for the whole world, it's not going to scale. But if we think about our responsibility as employees, humans, developers, Security teams, IT teams, and how can we contribute to this resilience of our …”
Costica: Hackers are actively using AI voice spoofing in live cyberattacks
“That's happening. That's happening. We've seen live cases.”