Sep 23, 2025 · 1h 0m · big-technology

Is Generative AI a Cybersecurity Disaster Waiting to Happen? — With Yinon Costica

Yinon Costica · 40m spoken Alex Kantrowitz · 14m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

Wiz co-founder Yinon Costica joins Alex Kantrowitz to examine the intersection of generative AI and cybersecurity, explaining why foundational cloud hygiene, human accountability in coding, and proactive defense matter far more than sensationalized AI threat narratives.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Alex holds 26.2% of the talking time here. How this is scored →

Alex as informed peer 4.8 Guest teaching 5.0 Guest disagreement 1.7 Alex pushing back 3.3
05100:0015:0030:0045:001:00:005:44–9:13 · Alex as informed peer 4/10 Securing AI Infrastructure and Cloud Data Storage Costica educates Kantrowitz on why cloud infrastructure misconfigurations and exposed buckets remain the primary AI vulnerability rather than novel prompt exploits. Kantrowitz translates the technical concepts for the audience and asks clarifying questions.9:13–13:55 · Alex as informed peer 4/10 Vibe Coding and Software Ownership Challenges Costica discusses the implications of vibe coding, highlighting that automated coding creates long-term ownership and maintenance liabilities. Kantrowitz follows along, asking if real-world breaches from vibe-coded apps are already appearing.13:55–16:45 · Alex as informed peer 5/10 Agentic Workflows and Accountability in Code Maintenance Kantrowitz challenges the vision of using AI agents to review code generated by other AI agents, arguing it compounds vulnerability and removes human diagnostic competency. Costica clarifies that human accountability remains essential regardless of automation.16:45–24:16 · Alex as informed peer 4/10 Threat Actor AI Utilization and Defender Asymmetry Costica breaks down the trifecta of AI attack surfaces and details the severe asymmetry between attackers and defenders, illustrating noise overwhelm with a fire alarm anecdote. Kantrowitz relates the dynamic to a DDoS attack on human security personnel.24:16–29:25 · Alex as informed peer 5/10 The Business of Cybercrime and Current Threat Realities Kantrowitz presses Costica on whether generative AI has actually caused an exponential escalation in breaches since ChatGPT's debut. Costica explains that cybercrime is run like a business and current threat levels remain largely 'more of the same' due to improving foundational defenses.29:25–32:37 · Alex as informed peer 4/10 AI-Driven Vulnerability Research and Zero-Day Threats Costica explains zero-day vulnerabilities and how automated AI vulnerability research could trigger a high-speed discovery race. Kantrowitz synthesizes how automated security tools mirror broader AI enterprise adoption trends.32:37–38:57 · Alex as informed peer 5/10 Wiz Cloud Architecture and the Google Acquisition Kantrowitz inquires about the strategic drivers behind Google's $32B planned acquisition of Wiz, noting Google Cloud's recent growth. Costica contextualizes AI as the third major migration wave to the cloud following cloud natives and the COVID-19 remote shift.38:58–45:53 · Alex as informed peer 7/10 The DeepSeek Security Incident and Media Hype Kantrowitz pushes back directly on Wiz's viral research report on DeepSeek, arguing the company sensationalized a routine database misconfiguration that happens across the industry. Costica defends the disclosure while acknowledging the media amplified the geopolitical framing.45:54–51:51 · Alex as informed peer 5/10 Superintelligence Concerns and Proactive AI Security Kantrowitz presents a hypothetical superintelligence scenario and tells Costica he is underrating existential risks due to industry optimism. Costica counters by pointing out that modern AI security discussions are happening proactively at the architecture stage rather than as an afterthought.51:51–57:19 · Alex as informed peer 5/10 Quantum Computing Risks and Post-Quantum Cryptography Kantrowitz challenges Costica to provide a realistic assessment of physical robotics and vehicle hacking risks without relying on canned optimism. Costica responds by explaining how threat actors creatively weaponize ordinary IoT devices for massive indirect disruption.57:20–1:00:44 · Alex as informed peer 5/10 Democratized Cybersecurity, AI Deepfakes, and Conclusion The conversation concludes with practical discussion around democratized security, AI voice cloning, and social engineering vigilance. Kantrowitz closes by balancing his initial alarmist assumptions with Costica's pragmatic optimism.5:44–9:13 · Guest teaching 7/10 Securing AI Infrastructure and Cloud Data Storage Costica educates Kantrowitz on why cloud infrastructure misconfigurations and exposed buckets remain the primary AI vulnerability rather than novel prompt exploits. Kantrowitz translates the technical concepts for the audience and asks clarifying questions.9:13–13:55 · Guest teaching 6/10 Vibe Coding and Software Ownership Challenges Costica discusses the implications of vibe coding, highlighting that automated coding creates long-term ownership and maintenance liabilities. Kantrowitz follows along, asking if real-world breaches from vibe-coded apps are already appearing.13:55–16:45 · Guest teaching 4/10 Agentic Workflows and Accountability in Code Maintenance Kantrowitz challenges the vision of using AI agents to review code generated by other AI agents, arguing it compounds vulnerability and removes human diagnostic competency. Costica clarifies that human accountability remains essential regardless of automation.16:45–24:16 · Guest teaching 7/10 Threat Actor AI Utilization and Defender Asymmetry Costica breaks down the trifecta of AI attack surfaces and details the severe asymmetry between attackers and defenders, illustrating noise overwhelm with a fire alarm anecdote. Kantrowitz relates the dynamic to a DDoS attack on human security personnel.24:16–29:25 · Guest teaching 5/10 The Business of Cybercrime and Current Threat Realities Kantrowitz presses Costica on whether generative AI has actually caused an exponential escalation in breaches since ChatGPT's debut. Costica explains that cybercrime is run like a business and current threat levels remain largely 'more of the same' due to improving foundational defenses.29:25–32:37 · Guest teaching 6/10 AI-Driven Vulnerability Research and Zero-Day Threats Costica explains zero-day vulnerabilities and how automated AI vulnerability research could trigger a high-speed discovery race. Kantrowitz synthesizes how automated security tools mirror broader AI enterprise adoption trends.32:37–38:57 · Guest teaching 4/10 Wiz Cloud Architecture and the Google Acquisition Kantrowitz inquires about the strategic drivers behind Google's $32B planned acquisition of Wiz, noting Google Cloud's recent growth. Costica contextualizes AI as the third major migration wave to the cloud following cloud natives and the COVID-19 remote shift.38:58–45:53 · Guest teaching 4/10 The DeepSeek Security Incident and Media Hype Kantrowitz pushes back directly on Wiz's viral research report on DeepSeek, arguing the company sensationalized a routine database misconfiguration that happens across the industry. Costica defends the disclosure while acknowledging the media amplified the geopolitical framing.45:54–51:51 · Guest teaching 4/10 Superintelligence Concerns and Proactive AI Security Kantrowitz presents a hypothetical superintelligence scenario and tells Costica he is underrating existential risks due to industry optimism. Costica counters by pointing out that modern AI security discussions are happening proactively at the architecture stage rather than as an afterthought.51:51–57:19 · Guest teaching 5/10 Quantum Computing Risks and Post-Quantum Cryptography Kantrowitz challenges Costica to provide a realistic assessment of physical robotics and vehicle hacking risks without relying on canned optimism. Costica responds by explaining how threat actors creatively weaponize ordinary IoT devices for massive indirect disruption.57:20–1:00:44 · Guest teaching 3/10 Democratized Cybersecurity, AI Deepfakes, and Conclusion The conversation concludes with practical discussion around democratized security, AI voice cloning, and social engineering vigilance. Kantrowitz closes by balancing his initial alarmist assumptions with Costica's pragmatic optimism.5:44–9:13 · Guest disagreement 1/10 Securing AI Infrastructure and Cloud Data Storage Costica educates Kantrowitz on why cloud infrastructure misconfigurations and exposed buckets remain the primary AI vulnerability rather than novel prompt exploits. Kantrowitz translates the technical concepts for the audience and asks clarifying questions.9:13–13:55 · Guest disagreement 2/10 Vibe Coding and Software Ownership Challenges Costica discusses the implications of vibe coding, highlighting that automated coding creates long-term ownership and maintenance liabilities. Kantrowitz follows along, asking if real-world breaches from vibe-coded apps are already appearing.13:55–16:45 · Guest disagreement 2/10 Agentic Workflows and Accountability in Code Maintenance Kantrowitz challenges the vision of using AI agents to review code generated by other AI agents, arguing it compounds vulnerability and removes human diagnostic competency. Costica clarifies that human accountability remains essential regardless of automation.16:45–24:16 · Guest disagreement 1/10 Threat Actor AI Utilization and Defender Asymmetry Costica breaks down the trifecta of AI attack surfaces and details the severe asymmetry between attackers and defenders, illustrating noise overwhelm with a fire alarm anecdote. Kantrowitz relates the dynamic to a DDoS attack on human security personnel.24:16–29:25 · Guest disagreement 2/10 The Business of Cybercrime and Current Threat Realities Kantrowitz presses Costica on whether generative AI has actually caused an exponential escalation in breaches since ChatGPT's debut. Costica explains that cybercrime is run like a business and current threat levels remain largely 'more of the same' due to improving foundational defenses.29:25–32:37 · Guest disagreement 1/10 AI-Driven Vulnerability Research and Zero-Day Threats Costica explains zero-day vulnerabilities and how automated AI vulnerability research could trigger a high-speed discovery race. Kantrowitz synthesizes how automated security tools mirror broader AI enterprise adoption trends.32:37–38:57 · Guest disagreement 1/10 Wiz Cloud Architecture and the Google Acquisition Kantrowitz inquires about the strategic drivers behind Google's $32B planned acquisition of Wiz, noting Google Cloud's recent growth. Costica contextualizes AI as the third major migration wave to the cloud following cloud natives and the COVID-19 remote shift.38:58–45:53 · Guest disagreement 3/10 The DeepSeek Security Incident and Media Hype Kantrowitz pushes back directly on Wiz's viral research report on DeepSeek, arguing the company sensationalized a routine database misconfiguration that happens across the industry. Costica defends the disclosure while acknowledging the media amplified the geopolitical framing.45:54–51:51 · Guest disagreement 3/10 Superintelligence Concerns and Proactive AI Security Kantrowitz presents a hypothetical superintelligence scenario and tells Costica he is underrating existential risks due to industry optimism. Costica counters by pointing out that modern AI security discussions are happening proactively at the architecture stage rather than as an afterthought.51:51–57:19 · Guest disagreement 2/10 Quantum Computing Risks and Post-Quantum Cryptography Kantrowitz challenges Costica to provide a realistic assessment of physical robotics and vehicle hacking risks without relying on canned optimism. Costica responds by explaining how threat actors creatively weaponize ordinary IoT devices for massive indirect disruption.57:20–1:00:44 · Guest disagreement 1/10 Democratized Cybersecurity, AI Deepfakes, and Conclusion The conversation concludes with practical discussion around democratized security, AI voice cloning, and social engineering vigilance. Kantrowitz closes by balancing his initial alarmist assumptions with Costica's pragmatic optimism.5:44–9:13 · Alex pushing back 2/10 Securing AI Infrastructure and Cloud Data Storage Costica educates Kantrowitz on why cloud infrastructure misconfigurations and exposed buckets remain the primary AI vulnerability rather than novel prompt exploits. Kantrowitz translates the technical concepts for the audience and asks clarifying questions.9:13–13:55 · Alex pushing back 2/10 Vibe Coding and Software Ownership Challenges Costica discusses the implications of vibe coding, highlighting that automated coding creates long-term ownership and maintenance liabilities. Kantrowitz follows along, asking if real-world breaches from vibe-coded apps are already appearing.13:55–16:45 · Alex pushing back 5/10 Agentic Workflows and Accountability in Code Maintenance Kantrowitz challenges the vision of using AI agents to review code generated by other AI agents, arguing it compounds vulnerability and removes human diagnostic competency. Costica clarifies that human accountability remains essential regardless of automation.16:45–24:16 · Alex pushing back 1/10 Threat Actor AI Utilization and Defender Asymmetry Costica breaks down the trifecta of AI attack surfaces and details the severe asymmetry between attackers and defenders, illustrating noise overwhelm with a fire alarm anecdote. Kantrowitz relates the dynamic to a DDoS attack on human security personnel.24:16–29:25 · Alex pushing back 4/10 The Business of Cybercrime and Current Threat Realities Kantrowitz presses Costica on whether generative AI has actually caused an exponential escalation in breaches since ChatGPT's debut. Costica explains that cybercrime is run like a business and current threat levels remain largely 'more of the same' due to improving foundational defenses.29:25–32:37 · Alex pushing back 1/10 AI-Driven Vulnerability Research and Zero-Day Threats Costica explains zero-day vulnerabilities and how automated AI vulnerability research could trigger a high-speed discovery race. Kantrowitz synthesizes how automated security tools mirror broader AI enterprise adoption trends.32:37–38:57 · Alex pushing back 1/10 Wiz Cloud Architecture and the Google Acquisition Kantrowitz inquires about the strategic drivers behind Google's $32B planned acquisition of Wiz, noting Google Cloud's recent growth. Costica contextualizes AI as the third major migration wave to the cloud following cloud natives and the COVID-19 remote shift.38:58–45:53 · Alex pushing back 7/10 The DeepSeek Security Incident and Media Hype Kantrowitz pushes back directly on Wiz's viral research report on DeepSeek, arguing the company sensationalized a routine database misconfiguration that happens across the industry. Costica defends the disclosure while acknowledging the media amplified the geopolitical framing.45:54–51:51 · Alex pushing back 6/10 Superintelligence Concerns and Proactive AI Security Kantrowitz presents a hypothetical superintelligence scenario and tells Costica he is underrating existential risks due to industry optimism. Costica counters by pointing out that modern AI security discussions are happening proactively at the architecture stage rather than as an afterthought.51:51–57:19 · Alex pushing back 6/10 Quantum Computing Risks and Post-Quantum Cryptography Kantrowitz challenges Costica to provide a realistic assessment of physical robotics and vehicle hacking risks without relying on canned optimism. Costica responds by explaining how threat actors creatively weaponize ordinary IoT devices for massive indirect disruption.57:20–1:00:44 · Alex pushing back 1/10 Democratized Cybersecurity, AI Deepfakes, and Conclusion The conversation concludes with practical discussion around democratized security, AI voice cloning, and social engineering vigilance. Kantrowitz closes by balancing his initial alarmist assumptions with Costica's pragmatic optimism.

speaking balance: gold is Alex, purple is the guest (3 minute bins)

0:00 · Alex 34.9% · guest 65.1%0:00 · Alex 34.9% · guest 65.1%3:00 · Alex 40.5% · guest 59.5%3:00 · Alex 40.5% · guest 59.5%6:00 · Alex 41.4% · guest 58.6%6:00 · Alex 41.4% · guest 58.6%9:00 · Alex 16.3% · guest 83.7%9:00 · Alex 16.3% · guest 83.7%12:00 · Alex 46% · guest 54%12:00 · Alex 46% · guest 54%15:00 · Alex 30.4% · guest 69.6%15:00 · Alex 30.4% · guest 69.6%18:00 · Alex 0% · guest 100%18:00 · Alex 0% · guest 100%21:00 · Alex 11.7% · guest 88.3%21:00 · Alex 11.7% · guest 88.3%24:00 · Alex 19.4% · guest 80.6%24:00 · Alex 19.4% · guest 80.6%27:00 · Alex 34.4% · guest 65.6%27:00 · Alex 34.4% · guest 65.6%30:00 · Alex 12.7% · guest 87.3%30:00 · Alex 12.7% · guest 87.3%33:00 · Alex 4.3% · guest 95.7%33:00 · Alex 4.3% · guest 95.7%36:00 · Alex 29.2% · guest 70.8%36:00 · Alex 29.2% · guest 70.8%39:00 · Alex 40.7% · guest 59.3%39:00 · Alex 40.7% · guest 59.3%42:00 · Alex 16.1% · guest 83.9%42:00 · Alex 16.1% · guest 83.9%45:00 · Alex 56.3% · guest 43.7%45:00 · Alex 56.3% · guest 43.7%48:00 · Alex 4% · guest 96%48:00 · Alex 4% · guest 96%51:00 · Alex 18.3% · guest 81.7%51:00 · Alex 18.3% · guest 81.7%54:00 · Alex 23.5% · guest 76.5%54:00 · Alex 23.5% · guest 76.5%57:00 · Alex 27.4% · guest 72.6%57:00 · Alex 27.4% · guest 72.6%1:00:00 · Alex 95% · guest 5%1:00:00 · Alex 95% · guest 5%
Sharpest disagreement ▶ 47:15 Costica rejects hypothetical superintelligence doom framing

Costica brushes aside Kantrowitz's apocalyptic thought experiment about superintelligence deleting competitors, insisting on reframing the problem around defensive engineering and historical precedent.

Hardest push from Alex ▶ 39:50 Host challenges Wiz's DeepSeek vulnerability reporting

Kantrowitz directly challenges Costica on Wiz's blog post regarding DeepSeek, asserting that Wiz sensationalized a routine database exposure that happens across tech companies every day.

Biggest teaching moment ▶ 20:10 Costica details attacker-defender asymmetry and alert fatigue

Costica educates Kantrowitz on the mathematical asymmetry of defense using the fire alarm story, demonstrating that false-positive noise is far more destructive to security operations than sophisticated attack tools.

Alex holds their own ▶ 53:35 Host demands analysis beyond founder optimism

Kantrowitz demonstrates sharp interviewing acumen by explicitly preempting Costica's default vendor optimism and forcing a concrete analysis of catastrophic physical IoT attack vectors.

the scores for every segment, with the reasoning behind each
ChapterTopicAlex as informed peerGuest teachingGuest disagreementAlex pushing backWhy
Securing AI Infrastructure and Cloud Data Storage 4712 Costica educates Kantrowitz on why cloud infrastructure misconfigurations and exposed buckets remain the primary AI vulnerability rather than novel prompt exploits. Kantrowitz translates the technical concepts for the audience and asks clarifying questions.
Vibe Coding and Software Ownership Challenges 4622 Costica discusses the implications of vibe coding, highlighting that automated coding creates long-term ownership and maintenance liabilities. Kantrowitz follows along, asking if real-world breaches from vibe-coded apps are already appearing.
Agentic Workflows and Accountability in Code Maintenance 5425 Kantrowitz challenges the vision of using AI agents to review code generated by other AI agents, arguing it compounds vulnerability and removes human diagnostic competency. Costica clarifies that human accountability remains essential regardless of automation.
Threat Actor AI Utilization and Defender Asymmetry 4711 Costica breaks down the trifecta of AI attack surfaces and details the severe asymmetry between attackers and defenders, illustrating noise overwhelm with a fire alarm anecdote. Kantrowitz relates the dynamic to a DDoS attack on human security personnel.
The Business of Cybercrime and Current Threat Realities 5524 Kantrowitz presses Costica on whether generative AI has actually caused an exponential escalation in breaches since ChatGPT's debut. Costica explains that cybercrime is run like a business and current threat levels remain largely 'more of the same' due to improving foundational defenses.
AI-Driven Vulnerability Research and Zero-Day Threats 4611 Costica explains zero-day vulnerabilities and how automated AI vulnerability research could trigger a high-speed discovery race. Kantrowitz synthesizes how automated security tools mirror broader AI enterprise adoption trends.
Wiz Cloud Architecture and the Google Acquisition 5411 Kantrowitz inquires about the strategic drivers behind Google's $32B planned acquisition of Wiz, noting Google Cloud's recent growth. Costica contextualizes AI as the third major migration wave to the cloud following cloud natives and the COVID-19 remote shift.
The DeepSeek Security Incident and Media Hype 7437 Kantrowitz pushes back directly on Wiz's viral research report on DeepSeek, arguing the company sensationalized a routine database misconfiguration that happens across the industry. Costica defends the disclosure while acknowledging the media amplified the geopolitical framing.
Superintelligence Concerns and Proactive AI Security 5436 Kantrowitz presents a hypothetical superintelligence scenario and tells Costica he is underrating existential risks due to industry optimism. Costica counters by pointing out that modern AI security discussions are happening proactively at the architecture stage rather than as an afterthought.
Quantum Computing Risks and Post-Quantum Cryptography 5526 Kantrowitz challenges Costica to provide a realistic assessment of physical robotics and vehicle hacking risks without relying on canned optimism. Costica responds by explaining how threat actors creatively weaponize ordinary IoT devices for massive indirect disruption.
Democratized Cybersecurity, AI Deepfakes, and Conclusion 5311 The conversation concludes with practical discussion around democratized security, AI voice cloning, and social engineering vigilance. Kantrowitz closes by balancing his initial alarmist assumptions with Costica's pragmatic optimism.

Statements from this episode (15)

Assertion Supported
Costica: Four of six AI technologies at Pwn2Own had critical RCE vulnerabilities
“Six technologies were presented. Out of these six technologies, four were actually Researched and found to be vulnerable at what we call the highest impactful vulnerability, which is remote code execution, RCE, which means that you can do anything with the tec…”
Yinon Costica Sep 23, 2025 ▶ 2:41
Insight
Costica: AI security relies on standard cloud infrastructure fundamentals
“When we think about AI, it's not all new. It's new software. It's existing infrastructure. And when we think about securing it, the basics apply. And it's very important to remember it. The fundamentals apply. The fundamentals of patching vulnerabilities, secu…”
Yinon Costica Sep 23, 2025 ▶ 7:20
Assertion Supported
Costica: Most AI security incidents stem from insecure cloud infrastructure
“Actually, when we look at AI related incidents, the majority of them is within this layer of Using the infrastructure in an insecure manner that allows threat actors to just do what they are used to do in cloud in the past.”
Yinon Costica Sep 23, 2025 ▶ 8:56
Insight
Costica: Vibe coding does not absolve developers of understanding their code
“The way I'm looking at it is that vibing code is a great way to accelerate, but it doesn't remove you from the responsibility of actually knowing your code, being able to address issues within the code, and guide AI farther into the, you know, maintenance proc…”
Yinon Costica Sep 23, 2025 ▶ 12:36
Insight
Costica: AI automation disproportionately benefits cyber attackers over cybersecurity defenders
“And now with AI, the interesting thing that the threat actors can automate a lot more, but from a defense perspective, it doesn't give me the same order of magnitude of, let's say, improvement that the threat actor can gain. So, in essence, there is an aggrava…”
Yinon Costica Sep 23, 2025 ▶ 20:53
Insight
Costica: Security teams must prioritize foundational hygiene over alert detection
“It's actually reducing the noise by investing more in the fundamentals and less on the detection. Ok, so if we are always trying to detect It's going to be hard. We're going to be bombarded with alerts. If we're proactively reducing the risk and the chance of …”
Yinon Costica Sep 23, 2025 ▶ 23:40
Insight
Costica: Ransomware groups reliably return data to protect their business reputation
“If you think about ransomware, it's a business. It has rules to it, right? You know, when you pay the ransom, you get the data, right? It's a rule. You don't, you're not tricked into it because it's a business and they need to maintain their reputation.”
Yinon Costica Sep 23, 2025 ▶ 25:19
Insight
Costica: AI currently only accelerates automation of existing cyber risks
“AI is another layer that allows us to automate more right now. Okay, I'm not talking, because we're not seeing the crazy new threats yet, we are right now at the phase where we're seeing accelerated automation of the known threats, known risks, and this is a j…”
Yinon Costica Sep 23, 2025 ▶ 29:04
Insight
Costica: Vulnerability research is the primary bottleneck in cybersecurity
“The ability to research and find vulnerabilities, this is kind of the bottleneck of the security space, ok? Because vulnerabilities are what allow threat actors to move from, you know, lower trust to higher trust environments”
Yinon Costica Sep 23, 2025 ▶ 30:56
Assertion Partly supported
Costica: Almost 10% of organizations adopted DeepSeek within one week
“Within a week, almost 10% of organizations were using DeepSeq.”
Yinon Costica Sep 23, 2025 ▶ 41:25
Opinion
Costica: DeepSeek's database leak was a typical cloud exposure, not an exotic exploit
“It was a very, ah, what I would say, typical exposure that exposed a lot of sensitive data, but yet, ah, if we look historically, there were similar incidents, for instance, with Microsoft releasing a token that had access to sensitive data in, you know, a buc…”
Yinon Costica Sep 23, 2025 ▶ 44:22
Insight
Costica: AI Security Is Being Addressed Much Earlier Than Prior Tech Waves
“And the concepts behind, I think, today, AI security are actually well thought today rather than much later. And it shows a bit on the maturity of not only the security teams, by the way, it shows a lot on the maturity of the industry that we are having the di…”
Yinon Costica Sep 23, 2025 ▶ 49:05
Insight
Costica: Hackers steal encrypted data now to decrypt with future quantum computing
“I think the one thing that has changed around quantum computing is a sort of, maybe it is closer than we think, and then the threat actors are, you know, stealing data now, so they will be able to decrypt it later once they, you know, figure it out.”
Yinon Costica Sep 23, 2025 ▶ 52:56
Insight
Costica: Cybersecurity cannot scale without democratizing responsibility to all employees
“Because if we think about just security teams doing security for the whole world, it's not going to scale. But if we think about our responsibility as employees, humans, developers, Security teams, IT teams, and how can we contribute to this resilience of our …”
Yinon Costica Sep 23, 2025 ▶ 57:35
Assertion Not checkable as stated
Costica: Hackers are actively using AI voice spoofing in live cyberattacks
“That's happening. That's happening. We've seen live cases.”
Yinon Costica Sep 23, 2025 ▶ 58:28
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.