Skip to content
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen - ASW #399

Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen - ASW #399

Feeds.Feedburner Mike Shema September 8, 2026

We showcase recordings from this year’s Black Hat. The Hidden Risks of the AI Supply Chain – Black Hat interview with Michael Leland, VP and Field CTO of Island. Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island’s research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called “AgentBaiting,” in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slow...

We showcase recordings from this year's Black Hat.

The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island

Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called “AgentBaiting,” in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption.

For more information Island's research, please visit

After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5

Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection.

The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro

Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it.

Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security

Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and into production.

Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster.

Michael Leland brings over 30 years of data networking, operations, and cybersecurity domain expertise. He formerly served as Head of Technical Marketing and Chief Cybersecurity Evangelist at SentinelOne where he was responsible for messaging and strategic development of their XDR product roadmap as well as the identity security portfolio. Prior to SentinelOne, he held the title of Chief Technical Strategist for McAfee. Michael was the co-founder and CTO of NitroSecurity – later acquired by McAfee – where he was responsible for developing and implementing their overall SIEM technology vision and roadmap and has held senior technical management positions at Cabletron and Avaya.

Dr. Sean Murphy is an accomplished cybersecurity executive with more than 20 years’ experience leading information security and risk management in highly regulated industries and fast-paced organizations in the military, healthcare, and financial services space. A 5X former CISO, he has had a wide range of responsibilities for providing and optimizing enterprise-wide security program and architecture that minimizes risk, enables business imperatives, and further strengthens the trust customers have in his organizations.

Sean retired from the U.S. Air Force (Medical Service Corps) after achieving the rank of Lieutenant Colonel. Sean has a Ph.D. in Information Security from Northwestern University, a master’s degree in business administration (advanced IT concentration) from the University of South Florida, a master’s degree in health services administration from Central Michigan University, and a bachelor’s degree in human resource management from the University of Maryland. He holds numerous industry-leading certifications, including NACD.DC, CCISO, CISSP, and ISSMP. He has served on many industry security boards and advisory groups. He is a sought-after speaker at a national level and the author of numerous industry whitepapers, articles, and educational materials. Dr Murphy is also an educator and is currently an adjunct professor at Central Washington University and over time, has held similar posts at several other colleges.

Idan is a serial entrepreneur and product strategist, bringing to Apiiro nearly 20 years of experience in cybersecurity. Previously, Idan was Director of Engineering at Microsoft following the acquisition of Aorato where he served as the founder and CEO.

Ido Geffen is the CEO and co-founder of Novee, the leader in AI-powered penetration testing. He brings over 20 years of experience across offensive and defensive cybersecurity, including nation-scale operations, vulnerability exploitation, and defense.

Through his work on national defense, he and fellow Novee co-founders Gon Chalamish and Omer Ninburg saw enterprises facing an impossible challenge: deploying code continuously while testing security only quarterly, even as attackers operate 24/7 with AI-powered tools. They founded Novee in May 2025 to clone their combined expertise into an agent that runs continuously, finding zero-days, business logic flaws, and complex attack chains that traditional tools miss.

You shipped it, but is it still exposed? Shadow APIs, forgotten endpoints, and unmanaged services are expanding your attack surface beyond what AppSec teams can track. So what’s still out there? At the Attack Surface Management Virtual Cybersecurity Summit on September 16th, learn how to discover exposed applications and APIs and reduce risk across your environment. Security Weekly listeners can register for free at using the promo code: CSS26-SW

You shipped it, but is it still exposed? Shadow APIs, forgotten endpoints, and unmanaged services are expanding your attack surface beyond what AppSec teams can track.

So what’s still out there?

At the Attack Surface Management Virtual Cybersecurity Summit on September 16th, learn how to discover exposed applications and APIs and reduce risk across your environment.

Security Weekly listeners can register for free at using the promo code: CSS26-SW

Unlock the full InfoSec World experience with the All Access Pass, featuring premium workshops, exclusive content, VIP experiences, and expanded opportunities to connect with cybersecurity leaders across industries. in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.

Unlock the full InfoSec World experience with the All Access Pass, featuring premium workshops, exclusive content, VIP experiences, and expanded opportunities to connect with cybersecurity leaders across industries. in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.

Stay in the Know, No Smoke and Mirrors – Join Our

Vulnerability Management Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet… – SWN #613

Vulnerability Management

Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet… – SWN #613

Vulnerability Management Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland – SWN #612

Vulnerability Management

Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland – SWN #612

Application security Fixing Software Weaknesses Rather Than Just Finding More Flaws – Nidhi Aggarwal, Gil Geron, Braden Russell – ASW #398

Fixing Software Weaknesses Rather Than Just Finding More Flaws – Nidhi Aggarwal, Gil Geron, Braden Russell – ASW #398

AI/ML Infosys and CrowdStrike partner on AI risks through Project QuiltWorks

Infosys and CrowdStrike partner on AI risks through Project QuiltWorks

Vulnerability Management PostGREShell vulnerability allows server takeover

Vulnerability Management

PostGREShell vulnerability allows server takeover

Patch/Configuration Management Plex urges immediate updates for media server and desktop clients due to security vulnerabilities

Patch/Configuration Management

Plex urges immediate updates for media server and desktop clients due to security vulnerabilities

You can skip this ad in 5 seconds

Extracted Entities

Attack Types (1)

Domains (1)

Vulnerabilities (1)