{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Distilled Security Podcast","title":"Episode 14: AI Risks, Threat Modeling, and The Future of Vibe Coding","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/d3155aef\"></iframe>","width":"100%","height":180,"duration":4950,"description":"Episode 14 of the Distilled Security Podcast is here!\nThis week, the team welcomes guest John Zeolla, a cybersecurity expert and AI enthusiast, for a deep dive into the risks, realities, and potential of artificial intelligence.\n\nTopics include:\nShadow AI in the Enterprise: Why business leaders are adopting AI faster than CISOs can assess the risks—and how features are outpacing controls.\nThird-Party AI Risk: Understanding vendor integrations with ChatGPT and others, and how contracts alone can’t guarantee security.\nData Sprawl and Provenance: How uncontrolled data flows and poor identity scoping create dangerous exposure in generative AI platforms.\nThreat Modeling for AI: Why traditional frameworks like STRIDE still apply—and how techniques like “LLM as a judge” are reshaping modern risk analysis.\nHallucinations, Misuse, and Insider Access: From AI-summarized HR documents to leaked board data, the team explores how improper permissions are amplified by intelligent agents.\nAI in Real Business Use: From customer support chatbots to code review tools, where AI adds value—and where it creates new points of failure.\nGovernance and Culture: The role of CISOs, legal, and finance leaders in aligning AI ambition with responsible oversight.\nBourbon Review – Elijah Craig Private Barrel Pick: A smooth 94-proof selection sponsored by Liberty Liquors (MD), bringing sweet caramel and balance to this week’s pour.\nBSides Pittsburgh Preview: With nearly 1,000 tickets sold, the team teases event highlights, panel interviews, and John's upcoming talk on \"vibe coding.\"\n\nTimestamps\n00:00 – Welcome & Introductions\n02:20 – What’s “Shadow AI”?\n06:45 – Third-Party Risk & AI Integrations\n11:10 – Contracts ≠ Security\n14:00 – Data Sprawl & Identity Challenges\n19:05 – Threat Modeling for AI\n23:40 – “LLM as a Judge” in Risk Analysis\n28:15 – Hallucinations & Misuse Scenarios\n33:00 – Insider Access Amplified by AI\n36:30 – Real-World Use Cases (Chatbots, Code Review, etc.)\n41:55 – Governance,...","thumbnail_url":"https://img.transistorcdn.com/MJdG3-EB1xgpmosNU-oEduyFhaC1R3HoELIm4f9vQDM/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMjk1/MTk1NTkwZTA3OThl/NzAxOGMwZjM4NTEy/MjVmOS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}