CyberRisk TV Live from RSAC Conference 2025 Day 4 Daily Intro – RSAC25 #4
Doug White, host of the Security Weekly News, and Matt Alderman, host of Business Security Weekly, kick off day 4!
Modernizing AppSec for the Vibe Coding Era – Shahar Man – RSAC25 #4
As 'vibe coding", the practice of using AI tools with specialized coding LLMs to develop software, is making waves, what are the implications for security teams? How can this new way of developing applications be made secure? Or have the horses already left the stable?
Segment Resources: https://www.backslash.security/press-releases/backslash-security-reveals-in-new-research-that-gpt-4-1-other-popular-llms-generate-insecure-code-unless-explicitly-prompted
https://www.backslash.security/blog/vibe-securing-4-1-pillars-of-appsec-for-vibe-coding
This segment is sponsored by Backslash. Visit https://securityweekly.com/backslashrsac to learn more about them!
Shahar Man is a seasoned technology leader with deep experience in engineering, AppsSec, DevOps and product management. As the co-founder and CEO of Backslash Security, he is dedicated to transforming application security by integrating business and security context into cloud-native risk management. Previously, Man held leadership roles at Aqua Security and SAP, where he spearheaded strategic cloud and DevOps initiatives.
Phishing 3.0: How Deepfakes and Agentic AI are Reinventing Cyber Threats – Eyal Benishti – RSAC25 #4
Phishing has evolved—fast. What started as basic email scams has transformed into AI-powered cyber deception.
Phishing 1.0: Early phishing relied on spam emails, fake banking alerts, and malware links to trick users into clicking. These attacks were easy to spot but still caused billions in damage.
Phishing 2.0: Attackers got smarter—instead of mass emails, they started impersonating real people. Techniques like BEC, VEC, and ATO used hacked credentials and real email threads to fool employees into wiring money or sharing sensitive data.
Phishing 3.0: Now, cybercriminals are using AI to generate fake but highly convincing voices, videos, and images. Imagine getting a video call from your CEO asking you to approve a wire transfer—except it’s not really them. Deepfake phishing makes this possible.
IRONSCALES will be discussing the current gaps in SEG technology and will showcase industry-first innovations for protection against deepfakes.
Assessing Organizational Readiness in the Face of Emerging Cyber Threat New research reveals that deepfake-driven attacks are rising fast, with over 94% of IT professionals expressing concern about their impact on security. Download the full research report now to learn how your organization can stay ahead of these evolving threats. Link: https://ironscales.com/fall-2024-threat-report/report-download
Using AI to Enhance Defensive Cybersecurity white paper Learn how AI is reshaping both cyberattacks and defenses in this comprehensive report from Osterman Research. Based on insights from 125 security leaders, this report explores how AI is transforming cybersecurity, revealing the technologies, strategies, and priorities that will define the next era of defense. Link: https://ironscales.com/using-ai-to-enhance-defensive-cybersecurity/report-download
The Hidden Gaps of SEG Protection white paper This research-backed report, based on data from 1,921 customer environments, reveals exactly how SEGs are failing, why modern phishing attacks bypass traditional defenses, and what security teams need to do next. Link: https://secure.ironscales.com/hidden-gaps-in-seg-protection-white-paper
This segment is sponsored by IRONSCALES. Visit https://securityweekly.com/ironscalesrsac to learn more about them!
Eyal Benishti is the CEO and Founder of IRONSCALES, pioneering the world’s first self-learning email security solution to combat advanced phishing, BEC, and account takeover attacks.
With over 15 years in the software industry, Eyal has held roles as a security researcher and malware analyst at Radware and a technical lead for information security solutions at Imperva. He also held R&D positions at Comverse and Amdocs.
Eyal earned his bachelor’s degree in computer science and mathematics from Bar-Ilan University in Israel and has been passionate about cybersecurity from a young age.
Open Source AI + How to Secure It – Brian Fox – RSAC25 #4
The rise of AI has largely mirrored the early days of open source software. With rapid adoption amongst developers who are trying to do more with less time, unmanaged open source AI presents serious risks to organizations. Brian Fox, CTO & Co-founder of Sonatype, will dive into the risks associated with open source AI and best practices to secure it.
This segment is sponsored by Sonatype. Visit https://securityweekly.com/sonatypersac to learn more about Sonatype's AI SCA solutions!
Segment Resources: https://www.sonatype.com/solutions/open-source-ai https://www.sonatype.com/blog/beyond-open-vs.-closed-understanding-the-spectrum-of-ai-transparency https://www.sonatype.com/resources/whitepapers/modern-development-in-ai-era
Brian Fox, CTO and co-founder of Sonatype, is a Governing Board Member for the Open Source Security Foundation (OpenSSF), a Governing Board Member for the Fintech Open Source Foundation (FINOS), a member of the Monetary Authority of Singapore Cyber and Technology Resilience Experts (CTREX) Panel, a member of the Apache Software Foundation and former Chair of the Apache Maven project. Brian has over 20 years of experience driving the vision behind, as well as developing and leading the development of software for organizations ranging from startups to large enterprises.
A Middle Market Roadmap for Cyber Resiliency – Chad Alessi – RSAC25 #4
Middle market companies face unique challenges in the ever-evolving cyber environment – and the question is not whether an attack will happen but rather when and its implications on its business operations and reputation. Developing a comprehensive cybersecurity approach is a business imperative for middle market companies, and Chad Alessi will discuss the threat landscape, what’s keeping IT decision-makers awkward at night, and the best approach to creating a proactive security measure.
Cyber Resilience in Action: A Guide for Mid-Market Firms
This segment is sponsored by CTG. Visit https://securityweekly.com/ctgrsac to learn more about them!
Since 2024, Chad Alessi has been managing director of cybersecurity at CTG, a Cegeka company. Alessi focuses on CTG’s local resources and adapting Cegeka’s proven global cybersecurity offerings to help U.S. clients navigate today’s increasingly challenging security landscape, especially in highly regulated industries.
Previously, Alessi served as Technology and Cybersecurity Solution Director for CTG’s U.S. Energy practice, where he led the implementation of comprehensive cybersecurity measures. His experience also includes senior roles at Gannett Fleming, where he oversaw cybersecurity initiatives, and Capgemini, where he led Intelligent Operations Transformation for North America.
Alessi holds a bachelor’s degree in chemical engineering from the University of Alabama, as well as an MBA and a Master of Information Systems with Advanced Studies in Information Security from the University of Alabama and Syracuse University, respectively.
A U.S. Marine Corps veteran, he also serves on the board of several non-profit organizations, dedicating his efforts to community impact and mentorship.
Blumira’s Vision: Security Built for MSPs & SMBs – Matthew Warner – RSAC25 #4
In the evolving world of cybersecurity, the shift from a purely threat-centric mindset to a focus on operational excellence is no longer just a trend—it’s a necessity. Matthew Warner, CEO and co-founder of Blumira, argues that this shift is particularly crucial for small and mid-sized businesses (SMBs) and the managed service providers (MSPs) that support them. Matthew believes that traditional SIEM and detection solutions have historically fallen short for these organizations, often due to their complexity, high cost, and steep learning curves. As a result, many SMBs have struggled to keep up with the sophistication of modern threats. Blumira was founded to change that.
Matthew’s vision is rooted in democratizing security—making powerful, automated detection and response tools simple, affordable, and accessible for everyone, especially those who need them most. By designing platforms that prioritize operational excellence—efficiency, usability, and actionable intelligence—Blumira enables organizations to be proactive rather than reactive. During the conversation, Matthew will share insights into the latest technologies and trends transforming the cybersecurity space, and offer actionable guidance for IT decision-makers. He'll explore how shifting strategy from chasing every alert to building a solid, efficient operational foundation can lead to better outcomes and stronger protection in the long run.
- https://www.blumira.com/partners
- https://www.businesswire.com/news/home/20250326177053/en/Blumira-Launches-New-Microsoft-365-Threat-Response-Feature-for-Faster-and-
More-Efficient-Security-Operations - https://www.youtube.com/watch?v=CeARYI1HuWo&list=PLf4cQhbLPf-seA7PiwFFXGYiiwl05VJgw - https://www.blumira.com/blog/blumira-enhances-msp-partner-program-with-new-tools-and-resources
Security should be accessible to everyone. At Blumira, we’re building the future of detection and response — simple, smart, and built to empower the teams who need it most. Check out https://securityweekly.com/blumirarsac and take control of your security today.
Matthew Warner is the CEO and co-founder of Blumira, bringing nearly two decades of hands-on cybersecurity experience to the company. Before launching Blumira, Matthew served as the director of security services at NetWorks Group, a Managed Security Services Provider (MSSP) with a strong focus on compliance and ethical hacking. During his time there, he worked closely with MSPs, gaining firsthand insight into their challenges in delivering effective, scalable security solutions to small and midsize businesses (SMBs). Identifying a gap in the market, Matthew envisioned a threat detection and response platform built with the needs of both SMBs and their MSP partners in mind—simple to deploy, easy to manage, and cost-effective. This vision became the foundation of Blumira, a solution designed to empower MSPs to offer robust cybersecurity protection without the overhead of traditional SIEMs.
Deeply committed to cybersecurity education, Matthew actively shares practical guidance through webinars, articles, podcasts, and other channels to help resource-constrained MSPs and SMBs improve their security maturity. His passion for helping underserved organizations—often the most vulnerable to cyber threats—continues to drive Blumira’s mission. In 2022, Matthew’s innovative leadership was recognized when he received the CTO of the Year award from the Globee Cybersecurity Global Excellence Awards. He was honored for his impactful research on additional Log4j vulnerabilities and his contributions to Blumira’s State of Threat Detection and Response Report.
Driving cyber resiliency and keeping up in an unprecedented threat landscape – Nick Carroll – RSAC25 #4
Nightwing divested from Raytheon in April 2024 and is entering another year of redefining national security. Amid emerging threats and shifting industry regulations and compliance frameworks, traditional security measures are no longer cutting it. As Cyber Incident Response Manager at Nightwing, Nick Carroll discusses how organizations can continue to build cyber resiliency and stay one step ahead in today’s threat landscape.
This segment is sponsored by Nightwing. Visit https://securityweekly.com/nightwingrsac to learn more about them!
Nick serves as Cyber Incident Response Manager at Nightwing. In a non-traditional sense, he is a hunter, scouring an evolving threat landscape for dangerous threats, from state and non-state actors, that underscore organization’s most critical systems. Nick and his team support multi-faceted threat hunting and monitoring operations for a diverse range of clients, including government agencies, major healthcare organizations, school systems, and Fortune 500 companies.
AQtive Guard Discover’s Defense Against the Non-Human Identity Explosion – Mo Aboul-Magd – RSAC25 #4
The surge in AI agents is creating a vast new cyber attack surface with Non-Human Identities (NHIs) becoming a prime target. This segment will explore how SandboxAQ's AQtive Guard Discover platform addresses this challenge by providing real-time vulnerability detection and mitigation for NHIs and cryptographic assets. We'll discuss the platform's AI-driven approach to inventory, threat detection, and automated remediation, and its crucial role in helping enterprises secure their AI-driven future.
To take control of your NHI security and proactively address the escalating threats posed by AI agents, visit https://securityweekly.com/sandboxaqrsac to schedule an early deployment and risk assessment.
Mohammed is VP of Product for SandboxAQ’s cybersecurity group, where he drives the development of innovative security solutions. Prior to SandboxAQ, he served as VP of Product at Snyk, the industry-leading developer security platform, where he led the launch of Snyk Code—an AI-powered SAST product that rapidly achieved $100M in ARR. He has also held a product leadership role at Akamai, leading their Edge Computing platform. Mohammed earned his degree in Computer Systems Engineering from Carleton University in Ottawa, Canada.
CyberRisk TV Live from RSAC Conference 2025 Day 4 Daily Recap – RSAC25 #4
Matt Alderman, host of Business Security Weekly, and Mandy Logan, host of Paul's Security Weekly, wrap-up another amazing RSAC conference! They'll include highlights from this year's event and what their favorite parts were!