
Lay of the Land: How Attackers Move in '26
mnemonic security podcast
05/25/26
•40m
About
Comments
Featured In
The security world is a noisy place lately. What's actually going on in the trenches?
Candid Wüest, Principal Security Advocate at xorlab, joins Robby to cut through the hype and take a look at how attackers are actually operating in 2026.
They open with a reference to their last discussion about LLM-infused malware, and touch upon using deception techniques such as honey tokens, fake password files and prompt injections to derail automated attackers. From there, they walk through the actual lay of the land: edge device exploits, credential abuse via infostealers, supply chain attacks targeting GitHub repositories, and why ClickFix social engineering is still working just as well as ever. They also dig into the growing connection between AI-assisted development and supply chain risk and what organisations should actually be doing about it.
The episode closes on the bug bounty market, where AI is quietly disrupting the economics of responsible disclosure, and what that might mean for how vulnerabilities get reported, priced, and exploited going forward.
Previous Episode

Auditing AI
May 4
•34m
How do you audit machine learning models, and where do you start on your AI governance journey?
In this episode, Robby is joined by Gaute Brynildsen, Chief Audit Executive at Gjensidige, one of the leading Nordic insurance groups. Gjensidige has built a mature and tested approach to AI governance, and Gaute shares what they’ve learned along the way.
Gaute explains how they went about auditing their in-house machine learning model trained solely on their own data, before expanding into broader governance across security, policies, roles, training, and risk.
He also covers where he recommends starting when building AI governance, highlighting the risks of shadow AI and how to monitor it, the importance of cloud competence and the value of an AI risk officer role.
They also discuss the level of automation among organisations in the Nordics, exploring agentic agents, and whether it’s overhyped or the next real shift.
Next Episode

Everything Is Being Recorded
June 8
•38m
In this episode of the mnemonic security podcast, we're joined by Joe Sullivan - former Chief Security Officer at Uber, Facebook, and Cloudflare, federal cybercrime prosecutor, and one of the most consequential figures in the history of the CISO role.
The conversation explores the security implications of AI becoming part of everyday life, from AI note-takers to wearables and humanoid robots. Joe discusses the privacy, legal, and security challenges these technologies introduce, why organisations need clear policies and stronger governance to manage them, and how the role of the CISO is expanding as AI risk moves higher up the boardroom agenda.
If you like this episode you’ll love
Promoted




