Searchable transcript of AI agents can manage your passwords. Should we let them? Plus: The biggest Patch Tuesday ever. — IBM Technology (30:22). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 Panel, would you trust an AI agent to manage your passwords? Michelle, we'll go with you first. >> It depends. I think I need to know a little bit more about which agent and some more of the pros and cons of it managing my password. >> I'm not I would trust an AI agent to manage those passwords. Maybe at a a version 2.0 I would change my my stance. >> Not yet.
00:26 >> Hello and welcome to Security Intelligence, IBM's weekly cybersecurity podcast where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your host Matt Kuzinski and joining me this week we've got Michelle Alvarez, manager X-Force Strategic Threat Analysis. We've got Austin Zeizel, threat intelligence consultant and Erblin Marrero, X-Force principal incident response consultant.
00:49 So we're going to be covering Microsoft's biggest Patch Tuesday ever and the C-suite's growing acceptance of cybersecurity risk. But first we have to talk a little bit more about AI agents and passwords because Apple Intelligence has a nifty new feature that lets an agent change your hacked passwords for you. This was announced last week at WWDC 2026.
01:16 This new feature from Apple Intelligence can identify whether a user's passwords are weak or compromised and then it can go change them for you via agentic workflows. I can't help but like compare this to perhaps the biggest agentic news story of the year which was Open Claw and as I'm sure you all remember, we mostly talked about that as a security debacle.
01:35 So it's kind of interesting to see agents being put to use in a proactive security sense. But I'm wondering if we're ready for that yet and Michelle, I'll start with you first because I asked you first up top, you know, would you trust an AI agent and you said it depends. I'd like to know a little bit more about what does it depend on? Can you give me some insight there?
01:53 >> Yeah, absolutely and so I'm not entirely sure, right? Is the human in the loop? I think that's first and foremost and that's been touched on in numerous times on this podcast, right? I think that's what it depends on. Do I get to check, okay, great, you want to change my password. Thank you. I hope you're notifying me, right? There's some transparency there and I have some say in whether or not you get to change my password and then I can make that decision.
02:16 But again, I think it's great, right? Wherever we can integrate AI into security, um and but that there's guardrails in place and I understand what those guardrails are because as I'm learning all about a genetic AI and I think the rest of my panels would agree, like there's so much to learn and understand and know. It can be overwhelming. So as you sort of integrate all of these tools into your even personal life, right?
02:43 What are what are you introducing? Know a little bit more about first that tool and then make a decision from there. >> Absolutely. And I think you're right to point out the importance of human in the loop here. I mean, like you said, we talk about it a lot on the show. It's always important with AI, but especially something like an agent managing your passwords cuz right, I could imagine nightmare scenario, AI decides to change your passwords cuz they're weak and it doesn't tell you and then you're like, I can't get
03:10 into my accounts, right? I'm not saying that's what's going to happen, but you can see that happening through like a prompt injection or something. So I I share similar concerns. Austin, how about you? I'm wondering if you have any concerns yourself. You mentioned kind of waiting maybe for a version 2.0. What's What do you think about? >> Yeah, I mean it I mean what Apple's doing here, I think is is is pretty interesting, you know, shifting security from a user-driven action to AI automation, where you know, that
03:37 system can detect a compromise and immediately rotate those credentials on the user's behalf. And that really complete removes the friction of password hygiene that we're so accustomed to, but it also introduces a new layer of risk here. Um You know, you have an AI agent that has direct access to those credentials, and that's really where I become a little bit more concerned.
04:04 Where it can make those changes across accounts, and and will operate at a high level with, say, implicit trust. Um but I think the adage within the industry speaks volumes when you prioritize convenience, you sacrifice security, and that's really where my main concern is around. >> I think that's a very good point, and I'm glad that you bring up the issue of like standing privilege, because it does tie into this conversation we're having a lot more about like should you even have standing credentials at all, right?
04:33 Like should you be swapping these things that much more dynamically? Should you be switching over to passkeys, for example? And so, yeah, I mean, you know, as much as this helps reduce some of that friction, like you said, that old saying, when you get some rid of some of that friction, is the trade-off always worth it? What can happen there? So, I'm glad you're bringing up those those those kind of tangential almost issues that affect this.
04:50 Erblin, I want to move on to you now. You know, you were slightly more stronger in saying no, I would not trust one. >> Well, I fully agree with with Austin Mitchell. I want to look a bit under the hood. Like you're you're saying that like compromised credentials. So, how Apple knows what's a compromised credentials? Uh so, most likely is discovery of of of leak passwords, for example, or info stealers, or information stealers in dark web.
05:16 And the question is how do you get this information? How what is the confidence? And basically, technically speaking, especially with with threat intelligence, it's very hard to determine. It's very false positive oriented. So, my biggest question is how does a company knows if your password is compromised with that confidence that they will reset everything automatically?
05:41 I think I like the idea that now it's more proactive, and it's not waiting for the user to basically go there and reset the passwords. Uh but if I take a look in this perspective of the risks and for example if the confidence of the leak credential is super high because it's infostealer in in one of the forums posting about your credentials, then I think it's it's it's a good move to to reset, but everything else I I think I I think it really depends how how we see it.
06:11 >> You know, just to sort of add on to that, right? With regards to the concerns, I think Matt you may have mentioned, right? What if you're locked out of your account? Um I think an even bigger issue, right? That's frustrating and it could cause some issues for you, but what if the underlying AI system itself is compromised? So now, right? There's that issue as well.
06:33 So I think the the risk with this can go from, you know, sort of minor frustrating, right? Getting locked out of your account, to significant um if the AI tool itself is compromised. >> Absolutely. It does it creates like a whole new attack vector, which is also like that's what happens anytime you introduce any new technology to a system, right? Like it can become a new attack vector in the wrong hands, and especially something like this, you can see how easily it could be, you know, uh manipulated through like prompt
07:01 injection or something like that. But I also wanted to highlight, you know, just stress Urban really like this point you made about like what threat intelligence is it using, right? Especially cuz I we have two people on this panel who are in threat intelligence. Like, you know, you know how important it is to like uh you need somebody sitting there looking, verifying what matters, what doesn't.
07:18 And can an agent do that yet? I I don't know that it can, you know? I I I don't, but I think this is an interesting step in in in a possible new direction. And so to kind of round out uh this this segment before we move on, I just want to kind of get takes from each of you on do you think that maybe AI agents like this, with the right guardrails in place, could help us make some progress finally in that like persistent uh uh issue of like basic security hygiene, right?
07:44 We always talk about how like you can have all the bells and whistles you want, but at the end of the day, are people changing their passwords? Are they using the strongest passwords? That's the hard part. Austin, I'll start with you. Do you think this could be part of our strategy to finally address that? What's your take? >> Yeah, I definitely think so.
07:59 I mean, the way I always look at AI is it's never a replacement for for humans. I think it it's supplemental to the work we do. So, I could see it being used as an assistant to help with password hygiene and management. But, it really is just too early to tell. But, I think the innovation is is great and I think we are going in the right direction. >> Absolutely.
08:24 Orban, how about you? Any thoughts there? >> Maybe for example, if it just a strong password, if it just calculation of do you really need AI? Maybe just simple automation. And I think maybe we don't have to be in pressure of just putting everything on AI and they still can be just pure automated. So, for example, if there is a discovery and in dark web just to disable the account, maybe is a solution.
08:48 So, not not fully automated. But, again, I think the most important part which we have is to understand first of all how we get this information. What is the confidence? And I can see a lot of of of difficulties in this case because you can see a lot of false positives. It's kind of uh dark web for example, it's most of it a garbage and not real data.
09:07 So, if just a fake news in dark web, it's going to disable my password. I think that's a really risky move which I don't trust yet. >> That's a really good point. We did do an episode not too long ago with Robert Gates here talking all about how most of what's on the dark web is kind of nonsense. It's lies, you know? And I didn't think about that aspect, but you're right.
09:28 Michelle, to close us out here, what do you think? Can can these agents be part of solving that hygiene problem for us? >> It's just like anything else, right? There we have a lot of tools in our tool belt um hanging from it. So, you know, we have to identify which ones are going to work the best together in a um secure and layered approach. So, it could be a good fit for some organizations, but not all.
09:52 So, I think every organization sort of has to vet the tools and technology that they're implementing in their own environment because not one shoe fits all. >> Absolutely. And I think it's especially important to stress with AI because it can be very easy to be like, AI will solve the problem. Okay, but like how? And will it actually solve it for us in our specific situation?
10:09 So, I like that you stressed that to close this out. Folks, I have to move this along, but before I do, to the listeners, viewers on YouTube, if you've got thoughts about incorporating AI agents into your security workflows, if you're using them to reset your passwords, let us know. I do read the comments. I do respond. But we're going to move on to another story this week about the intersection between AI and security.
10:28 This is the biggest Patch Tuesday ever. June 2026 was Microsoft's biggest Patch Tuesday on record addressing 206 unique CVEs. And Microsoft VP of Engineering Tom Gallagher thinks that Patch Tuesdays of this size will be the norm going forward thanks in part to AI vulnerability discovery. And and a lot of other people agree, right? I've got a quote here from Tenable's Satnam Narang talking to Dark Reading.
10:57 He said, quote, "The days of 50 CVE Patch Tuesdays are over. I would expect at a minimum 100 plus CVEs each month to become the norm across Patch Tuesday." Now, that sounds a little intimidating to me, but Austin, I want to start with you. What do you think? Are massive Patch Tuesdays becoming a norm? Is this a problem for us? Or or is the volume something we should be concerned about?
11:19 What what do you think? >> Yeah, I mean, it's not your typical Patch Tuesday anymore. It does reflect a structural shift in vulnerability discovery um with that record number of over 200 CVEs. And I do think that is becoming the new baseline, especially as AI helps scale CV research. Um but I think what's important here is it's not the software that's suddenly less secure and that there's more uh flaws, you know, coming out.
11:49 It's rather that AI is just dramatically increasing the speed, scale, but also the depth of that discovery um of those vulnerabilities. And it's becoming um more visible with these flaws that have always been there. So, overall, I think it is a net positive um and it's not something to to be alarmed about. >> Yeah, I like how you framed that, you know, um it's not that the software is suddenly getting less secure, right?
12:16 Cuz it can feel that way, but it's not that the AI is like inventing vulnerabilities. It's finding them. And we have stories from like, you know, when Mythos preview came out a few months ago of it finding vulnerabilities in like 16-year-old code, for example. You know, or I think about I forget whose code it was. It was somebody at Microsoft, but they tried it on like a 40-year-old utility they had written and they found flaws there.
12:36 So, it's like the flaws were always there. It's just the AI is kind of surfacing them. And that can be intimidating, but it's also more visibility for us as defenders. Urban, I want to ask you something, you know, there are some who say that like, look, the volume it looks intimidating, but it's not that big of deal because the vast majority of CVEs don't really end up exploited anyway.
12:53 I'm I'm wondering what your thought is there. Do you think it's that's kind of the right way to approach this or or how do you feel about that? >> I think definitely like if it's exploitable or not, it's it's it's key here information because that's a differentiation that that makes, but I I fully agree with us as Austin stated that we have to see also the other side because then the patching is faster with AI, so it's not pure that we are now against only the bad side or red team and we are getting more and more
13:23 patchable. I can see also automation in in the blue team and and their architecture. So, I I think that this is is is important, but in the same time you have those like not fully transparent, which makes definitely sounds that we have to set also like what is the impact, what do we have exploit in wild. And something which I want to highlight is that we are some sometimes forgetting, especially in in in the securities area as well, exploit Wednesday, which means that everything which being published now tomorrow, most
13:55 likely, it will be seen. And that's something as well which which we have to make sure that you have basically as soon as possible updates before the the bad guys they will go there and develop exploits even if it wasn't yet published. >> Absolutely, Erdal. I really like that you, like Austin, stress this matter of Look, these things are finding vulnerabilities, and yes, it's giving more, you know, ammo to attackers, but it's also more ammo for us as defenders.
14:22 Like you could incorporate AI into your blue teaming, for example. Like it's not just for the bad guys. And, you know, the thing is, I think a lot of times when we talk about AI vulnerability scanners, at least I'm guilty of this, I know, it can feel like I'm treating them like they are just an attacker's tool, right? But like the vulnerability scanners are for us.
14:38 Like we are using we're supposed to be using them to find the stuff and fix it before they can. And it's it's important to remind ourselves of that. Michelle, I want to get your take too on, you know, this kind of increasing volume of patches on Patch Tuesday. Is this something you're concerned about? How do you feel about How does it affect our job as defenders?
14:55 >> Yeah, sure. And I definitely do think it depends on your role and the environment. So, if I may, um, in looking at this, uh, topic, I reached out to our vulnerability manager, Sondra Hill, so I'll give her a shout-out. She's dealing with this, um, vuln-cop-alypse, if you would want to call it that, or vuln-launch, a vulnerability avalanche. Um, and it's not just Microsoft.
15:18 So, we also had Google Chrome this month over 400 vulnerabilities released. So, that was huge. Um we have Oracle who's historically just done quarterly releases. Now, they're also moving to monthly plus their quarterly. Um so, and that's just three vendors. So, if you're tracking all of these vulnerabilities, um this is having significant impact on work streams.
15:42 Unfortunately, they are also leveraging AI to help with those workflows. Um so, again, depending on your role. So, they're, you know, looking at vulnerabilities, tracking those vulnerabilities. We have, you know, over three decades of uh vulnerability tracking. Um and so, this is a tremendous effort and service that we provide to our clients and um to IBM.
16:07 Uh and then also from the defender side of things, yes, of course, there's a bit of a shift here. We have to make sure that we um um disclose that not every vulnerability, like we've just talked about, is going to be exploited. Not everything is going to have a publicly available exploit. So, it is about prioritization um versus trying to uh patch everything.
16:31 >> Absolutely. And it's kind of like you read my mind there, Michelle, because there were two questions that I sort of were lingering and you addressed, I think, both of them. The first was that like this isn't just Microsoft, right? Like Microsoft is just the one doing Patch Tuesday, but like you pointed out, no, it's not. There's there's other organizations dealing with this, too.
16:45 And I think that's really important to keep in mind because we can say, "Oh, it's a historic Patch Tuesday." But it's also historic for a lot of these other organizations too now, right? And then the other thing I like you pointed out was, you know, how do we deal with this influx? Well, we can incorporate AI into our own workflows, too, right? And and that might help us do things like prioritize which ones are actually exploitable, right?
17:03 Or like prioritize the ones that might actually harm our organization in a way that matters, right? And I think about, you know, this idea that's come up a lot when I talk to people about patch management these days, which is that like you you shouldn't just treat every single patch the same, right? Some of them are more important to your organization than others, and you need to be making an informed decision about, you know, which ones actually matter and which ones you should prioritize.
17:23 So, as these vol- you know, as these volumes get bigger and bigger, maybe we can use AI to help with that. Um to round out this segment, I want to do another little quick round table for you folks. I'm going to I'm going to present you with a quote here from uh Justin Fier, who is the senior vice president at Darktrace. Uh he said to Dark Reading, "For enterprise security teams, the lesson is not simply patch faster."
17:42 My question for you folks is, what is the lesson then? Austin, I'll start with you. What's the lesson here if it's not patch faster? >> Well, the lesson, as Michelle mentioned previously, is prioritization of one, what's actually exploitable, but also what has the highest impact, cuz it's not just a numbers game, it really is that that quality over over quantity, that the majority of these CVEs probably aren't exploitable, but we need to prioritize which ones actually are and can have that impact on us.
18:15 >> Absolutely. Erblin, how about you? Any thoughts on what the lesson is here? >> I think the most key part is the shifting left, which it means that we have the secure development in early cycle in all products. And I can I can see also like the good developments in in this area in in in in the AI, because you can have like the right skills, and like most of the developers they they incorporate, for example, AI in early stage to basically patch and then to to push to production less vulnerable code.
18:46 So, it has to be simple just as early pen testing, patching everything before before pushing to prod this is is the right answer. >> I like that. I I like that you point out that, you know, um there's also a a proactive component to it, too, right? It's not just about reacting to the the patches that come out. We can also maybe make it so that there are few fewer vulnerabilities to address in the first place.
19:07 I Thank you for bringing that up. Uh Michelle, to close us out, and I know you kind of you almost answered this basically, but I just want to explicitly pose the question to you. What's the lesson here for folks to take away? >> Yeah, I'll just have to second Austin and obviously Rublon brings up some great points, but the prioritization and then also in terms of what Rublon had to say about reducing and shifting left, right?
19:28 Let's say there is a breach, right? What have you done to reduce the blast radius? So taking that into consideration as well. >> Folks, we're going to move on to our final story for the week. This is executives tolerating increasing cyber risk. So Gartner's Security and Risk Management Summit 2026 was held in Maryland at the beginning of the month and coverage of one of the sessions caught my eye as reported by Richard Livingston of TechTarget.
19:58 Gartner analyst Will Kendrick reported that C-suite cyber risk appetites are growing. Basically, executives are increasingly willing to accept greater levels of cyber risk to drive innovation and achieve their goals. Now now the shift is fueled in part by the fact that organizations have basically learned that it's impossible to prevent all cyber incidents, right?
20:18 Everyone's kind of going to face one at some point no matter how many security controls you put in place. So as Kendrick says, cybersecurity's new mandate is to more holistically minimize harm and impact to the business before during and after a cyber attack as opposed to maximizing outright prevention, which is not achievable no matter how much we spend.
20:38 Rublon as the incident response guy on this panel, I want to ask your thoughts on this take about executives increasingly embracing cyber risk. You got any You got any worries there? Any concerns? How you feeling? >> I think like seeing from the field directly with with incident response cases is that like we have a shift from cybersecurity mindset to cyber resilience, which means that everyone is accepting that yes, we're going to get breached, we're going to get attacked and then we're just going to minimize the risk.
21:06 The issue is with this approach, basically accepting the risk, is sometimes that you have less visibility and basically you're sacrificing the detection. Which then even during the incident response, for example, or reactive approach, it will be very difficult to to to keep up because what you have basically minimize your budget, detection, uh agents, for example, everything.
21:31 And that's very complex because that's basically will damage and would basically make very hard for for incident response to be successful. So, uh just to sum it up, I think that is very important to keep in mind that those two go directly with itself. So, it's not that now you're going to ignore the the the the prevention part and then somehow when you have incident, you have a good team, you're going to be successful.
21:58 No, they go together. So, everything in incident response is good visibility, it's good preparations. And I'm okay some sometimes with with this approach that this cyber side resilience and we have to response in the proper way, but you have to do your homework first before the day comes. >> Yeah, you can't throw the baby out of the bathwater, right?
22:19 Like you can't be like, well, we can't prevent attacks, we might as well stop spending on prevention. Like that's that's not the way to approach this. Um but I I am glad that that you brought up, you you know, the these questions of budget and how the spend is allocated because, you know, part of the shift here comes from the fact that is I'm quoting Kendrick here.
22:36 He says that um executives have learned that more spending on security means more business costs, slower speed to market, stalled innovation, day-to-day IT tools, more red tape, excessive fear-mongering, and drained productivity. Is that a fair assessment? It seems a little harsh to me. Austin, I'm going to ask you, do you think that's a it's a fair assessment of what we get for spending on security?
22:54 How you feel about that? >> I mean, yeah, it all goes back to, you know, prioritizing that risk and also in intentionally accepting that you know, you're not going to stop every threat. Um, but it's about managing that overall impact and that's not just preventing uh incidents. We really have to look at the the broader picture here. So, as those executive risk appetites grow, the role of uh security kind of shifts from less technical to more of a strategic risk standpoint and looking at the bigger picture there.
23:28 Um, where the ability to communicate business impact and guide those uh key business decision-making um outcomes becomes just as critical as stopping the threat in the first place. So, as defenders, you know, there is explicit trade-offs here. Um, but I think, you know, where you're allocating resources, uh business continuity and growth can outweigh those strict uh security controls.
23:56 >> I like Austin's take on sort of the strategic outlook. Of course, we're both on the strategic threat intelligence team, so that makes sense, but um, you know, it just to kind of put that into sort of an a use case, right? And I'll bring Erblin into this and maybe he has some thoughts as well. Uh, you know, if you're going to do, for instance, an active threat assessment in your environment, you're going to make sure that it's very focused, right?
24:17 Looking for the TTPs of threat actors that are most likely to target your environment. You're not going to try to look for everything and everybody that might try to target somebody out there, right? You're going to be very focused and that I think then translate um, to what, you know, the business leaders can understand is this is my actual risk and this is where I should put my security budget is for um, this tailored approach to my environment.
24:45 Um, and then we're going to see a return on investment and, you know, of course, bigger risk for cyber breach, but also, obviously, having a bigger appetite for risk doesn't mean that security isn't important and I think that's a good point, right? That I don't think the security leaders out there and the CISO's teams are saying that it's not important.
25:08 So, just sort of round that out with an exact actual example. >> No, I'm glad that you put it in those those terms and and you know, it kind of you and and and Austin both you know, talking about this more strategic kind of role that security can kind of play. It reminds me of you know, something that Jeff Crum often says when he's on the show which is that like security can't be in the business of saying no, we should be in the business of saying yes and here's how to do it securely, right?
25:31 And I feel like that mindset helps to you know, maybe shift some of the thinking towards that cyber resilience mindset, but without making some too big of a sacrifice. You know what I mean? Like you're still you're saying look, we're going to enable the business, but like we're going to enable it securely. And and maybe that's where the balance lives.
25:50 Erblin, to shift tack slightly here, I you know, I want to ask you about something that that kind of came to mind for me which is that like and and Kendrick doesn't say this outright, so I don't want to make it sound like this is his idea, but like I suspect AI is part of the puzzle here in the sense that like organizations want to adapt AI and deploy it quickly and maybe they feel like or security is stopping them.
26:09 But I wanted to ask you, you know, somebody who's actually working in the field every day, you know, do you think maybe how do you think AI fits in this picture? Does it fit in the picture? What's your take there? >> If I can, I want to basically first touch on another topic which is related to this. I don't think the biggest reason why it's kind of this feeling of insecurity and you are not properly responding to incidents.
26:28 I think sometimes we are missing the technical people. Especially you have CISOs which they are less technical on understanding the the threat. And you have as well this vendor oriented when when special like the C-level sees that the vendor is like a silver bullet against all the attacks and you are missing the key parts. Which means that if you don't understand how the field works, if don't know your environment, if you cannot do your homework as I said, like keeping the hygiene, network security, documentation and
26:57 others, I think it's very difficult and then the incident happens, you don't have the basic stuff, but you are only depending in very specific product, then you realize that basically your overall security or posture is not the right one. So, I think AI is helping, but then I think also AI is shifting in this uh high-level knowledge of security overall and everyone wants to be the manager, everyone wants to basically use AI to basically build and lead, but where are the technical people in this case?
27:32 So, therefore, I think we need to more focus on on on on the skills, people that understand basically how how the infrastructure works, what are the key things to make your your environment safe and not just pure like high-level GRC oriented. And that's something that we are observing through different cases when you have people doing things that they are don't really understand in like el- elements, but only in high-level, which I think is very important to mention here.
28:06 >> Absolutely. And that, you know, reminds me again of something that's come up on the show, which is, you know, you know, Dustin Heywood has often said that like we're framing a lot of AI stuff as a technical problem, but a lot of it's also a people problem. Like like where are the technical people? Are we still investing in them or are we like you said, everybody everybody want to be a manager so much that like you know, we we we don't have the technical boots on the ground.
28:25 I you know, I I think that's a serious concern. Um we're we're coming up on the end here, but the uh before I close this out, Michelle, any final thoughts on, you know, how we deal with uh CISOs or executives in general just having a bigger appetite for risk, what our role might be, what your role might be as like an a threat intelligence person, any thoughts there for us?
28:45 >> Yes, so I think the theme or one of the themes from our discussion today is prioritization and then enabling that to allow for business continuity, which is going to be probably one of the most important things for our C-suite, right? When they consider what are the revenue-generating processes that we want to keep up and not be have disrupted due to a cyber incident.
29:12 And so being able to prioritize to allow that to be mitigated as best as possible. >> Absolutely. And Austin, any last words for us before we close out? Any final thoughts there? >> Yeah, just one point. I think a lot of it has to do with you striking a balance between those more technical-minded folks and but also the strategic side. You know, you need both but also to look more broadly beyond just your organization.
29:41 Seeing that if you are breached or you have any sort of data theft as a result of an incident, you have to look at those trickle-down effects on you know, your your vendors and your third parties and just overall the business impact. >> Absolutely. I think it's a great note to end it on, folks. That does it for this episode. I want to thank our panelists Michelle and Erblin and Austin.
30:02 Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode and stay safe out there.
Not yet for unrestricted use; AI password management becomes more acceptable with human approval, transparency, guardrails, and high-confidence compromise detection.
The days of 50 CVE Patch Tuesdays are over.
Security can't be in the business of saying no, we should be in the business of saying yes and here's how to do it securely.
The lesson is not simply patch faster.
Frequently cited Security Intelligence guest associated with enabling business securely.
25:25Previously cited Security Intelligence guest associated with the people dimension of AI.
28:10Company whose Apple Intelligence feature can identify weak or compromised passwords and change them through agentic workflows.
01:03Browser mentioned as having more than 400 vulnerabilities released in the month discussed.
15:19Company described as moving from quarterly vulnerability releases to monthly releases plus quarterly releases.
15:25Company whose senior vice president Justin Fier was quoted on enterprise patching priorities.
17:36Organization that held the Security and Risk Management Summit 2026 and reported on C-suite cyber-risk appetites.
19:49