We catch up on the news, including AI vuln hunting; also more RSAC interviews! - John Wilson, Mark Lambert, Georges Bossert, Samuel Hassine - ESW #454
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内。而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述即可。好的,我得先仔细看看文章内容。 文章分为几个部分,首先是企业新闻,然后是RSAC访谈,涉及ArmorCode、Filigran、Sekoia和Fortra。ArmorCode讨论了AI暴露管理解决方案,帮助企业更好地管理和监控AI的使用,减少风险。Filigran则讲了如何将威胁情报与攻击模拟结合,形成持续威胁暴露管理框架。Sekoia提到在安全运营中心使用AI时需要可靠上下文和结构化手册,避免只是加快错误速度。Fortra则介绍了Scripted Sparrow这个活跃的BEC团伙,他们每月发送大量钓鱼邮件。 我需要把这些要点浓缩到100字以内。可能需要突出每个公司的主要贡献或发现。比如ArmorCode的AI管理、Filigran的威胁框架、Sekoia的AI SOC平台以及Fortra的BEC报告。 现在组织语言:RSAC访谈涉及多个公司,涵盖AI风险管理、威胁情报、SOC自动化和BEC诈骗。ArmorCode谈AI暴露管理,Filigran讲威胁框架,Sekoia讨论SOC中的AI应用,Fortra揭示BEC团伙活动。 这样大概在100字左右吧?再检查一下有没有遗漏的重要信息。 </think> RSAC访谈涵盖企业级安全创新与挑战:ArmorCode推出AI暴露管理解决方案以应对快速发展的AI风险;Filigran探讨基于威胁情报的主动防御框架;Sekoia强调可靠上下文对安全运营中心自动化的重要性;Fortra揭示活跃的商业电邮欺诈团伙及其大规模诈骗活动。 2026-4-13 09:0:0 Author: sites.libsyn.com(查看原文) 阅读量:9 收藏

Apr 13, 2026

Segment 1: We cover the weekly enterprise news!

Segment 2: RSAC interviews from ArmorCode and Filigran

ArmorCode: AI Exposure Management and Governing Shadow AI

AI is moving faster than most governance models can keep up. As organizations race to adopt new AI tools, developer workflows, agents and MCP servers, security leaders must enable innovation without losing control over risk, accountability and oversight. In this segment, ArmorCode will discuss its new AI Exposure Management (AIEM) solution, as part of the ArmorCode Agentic AI Platform. ArmorCode will highlight how AIEM gives enterprises clearer visibility into where AI is being used, who owns it and the potential risks it introduces across heterogeneous environments. By turning AI usage and signals from existing security and IT systems into governed, auditable outcomes, AIEM helps organizations reduce shadow AI risk, assign accountability and accelerate AI adoption with stronger control and board-ready governance. ArmorCode will also share findings from its new 2026 State of AI Risk Management report, developed in partnership with The Purple Book Community and based on responses from more than 650 enterprise security leaders. The discussion will connect ArmorCode’s latest product innovation to the broader industry need for scalable, enterprise-ready AI risk governance.

ArmorCode AI Exposure Management is available now as a solution deployed on the ArmorCode Agentic AI Platform. To learn more, visit https://securityweekly.com/armorcodersac.

Beyond IOCs: A Framework for High-Impact Cyber Threat Intelligence

In a time where the ability to turn intelligence into decisive action is a true competitive advantage, organizations must move beyond reactive alert triage to a proactive, threat-informed defense. This segment explores how unifying threat intelligence with adversarial attack simulation enables a Continuous Threat Exposure Management (CTEM) framework that replaces hype with measurable outcomes. We will discuss why these are no longer just technical security conversations, but critical business strategies that provide the board and C-suite with the clarity and confidence to reduce risk and focus resources where they matter most.

This segment is sponsored by Filigran. Visit https://securityweekly.com/filigranrsac to learn more about them!

Segment 3: RSAC interviews with Sekioa and Fortra

Agentic AI: Don't Make Your SOC Faster at Being Wrong

Adding AI agents to an unprepared SOC doesn't make it smarter; it just makes it "faster at being wrong." Georges Bossert challenges the industry hype to explain why true autonomy relies on reliable context and structured runbooks, not just prompts. He will discuss how to build the necessary foundations to automate rapidly without losing control.

This segment is sponsored by Sekoia.io. Visit https://securityweekly.com/sekoiarsac to discover their AI SOC Platform!

Scripted Sparrow: A Prolific BEC Group

In December, Fortra Intelligence and Research Experts (FIRE) released a major report exposing Scripted Sparrow, one of the most active Business Email Compromise (BEC) collectives operating today. The group sends an estimated 6 million highly targeted scam emails each month, impersonating executive coaching firms and leveraging spoofed reply chains, missing attachment lures, and evolving multilingual campaigns. FIRE’s investigation links the collective to 119 domains, 245 webmail accounts, and 256 bank accounts, with members operating across three continents and continually refining their fraud techniques at scale.

This segment is sponsored by Fortra. Visit https://securityweekly.com/fortrarsac to learn more about them!

Visit https://www.securityweekly.com/esw for all the latest episodes!

Show Notes: https://securityweekly.com/esw-454


文章来源: http://sites.libsyn.com/18678/we-catch-up-on-the-news-including-ai-vuln-hunting-also-more-rsac-interviews-john-wilson-mark-lambert-georges-bossert-samuel-hassine-esw-454
如有侵权请联系:admin#unsafe.sh