AiCyber.Land

From mind-controlled wheelchairs to hackable AI agents, the future is here and it's wild! In this episode, cybersecurity pros Bryce and Shelby break down the coolest—and creepiest—tech news, including a hands-on lab where you can learn to hack AI and the humanoid robots set to take over factory floors.---**What We're Unpacking In This Episode:**Welcome back to the pod! Join hosts and cybersecurity experts Bryce and Shelby as they unpack the most fascinating stories at the intersection of AI and security.First up, Shelby introduces a game-changing tool for security pros: the "Breach to Fix Labs." It's a hands-on environment where you can learn to exploit and patch real-world AI vulnerabilities like SQL injection and log poisoning, all based on actual incident reports.Then, Bryce dives into the wild world of tech unveiled at the Consumer Electronics Show (CES). We're talking humanoid robots like the Ozobot that are already being snapped up by car manufacturers to perform tasks humans can't, and the mind-blowing "NQ" earpieces that can read your brainwaves to control a wheelchair—no surgery required! Of course, we also explore the dark side: the privacy implications of brain-computer interfaces and the potential for ads beamed directly into your thoughts.Finally, we discuss the rising challenge of securing agent-to-agent (A2A) networks. As AIs become more autonomous, how do we protect them? We explore Cisco's new open-source A2A scanner, a framework designed to prevent threats like agent impersonation and indirect prompt injection. This is essential listening for anyone building or securing the next generation of AI systems.---**Key Moments:**⏱️ KEY MOMENTS:00:24 - Meet Your Cybersecurity Hosts, Bryce & Shelby01:44 - New AI Hacking Lab: Practice on Real-World Vulnerabilities07:27 - The Robotics War is Here: Highlights from CES 202411:40 - Mind-Control Tech: Brainwaves, Earpieces & The Future of BCIs25:03 - Securing AI Agents: Cisco's New Scanner & The "Reverse CAPTCHA" Idea35:55 - Are You "WEIRD"? A Surprising Psychology Concept---**Join the Conversation!**What was your favorite story from this episode? Are you excited about brain-computer interfaces or totally freaked out? Let us know in the comments below!If you love deep dives into the world of AI and cybersecurity, make sure to hit that subscribe button and ring the bell so you never miss an update.

Show Notes

From mind-controlled wheelchairs to hackable AI agents, the future is here and it's wild! In this episode, cybersecurity pros Bryce and Shelby break down the coolest—and creepiest—tech news, including a hands-on lab where you can learn to hack AI and the humanoid robots set to take over factory floors.

---

**What We're Unpacking In This Episode:**

Welcome back to the pod! Join hosts and cybersecurity experts Bryce and Shelby as they unpack the most fascinating stories at the intersection of AI and security.

First up, Shelby introduces a game-changing tool for security pros: the "Breach to Fix Labs." It's a hands-on environment where you can learn to exploit and patch real-world AI vulnerabilities like SQL injection and log poisoning, all based on actual incident reports.

Then, Bryce dives into the wild world of tech unveiled at the Consumer Electronics Show (CES). We're talking humanoid robots like the Ozobot that are already being snapped up by car manufacturers to perform tasks humans can't, and the mind-blowing "NQ" earpieces that can read your brainwaves to control a wheelchair—no surgery required! Of course, we also explore the dark side: the privacy implications of brain-computer interfaces and the potential for ads beamed directly into your thoughts.

Finally, we discuss the rising challenge of securing agent-to-agent (A2A) networks. As AIs become more autonomous, how do we protect them? We explore Cisco's new open-source A2A scanner, a framework designed to prevent threats like agent impersonation and indirect prompt injection. This is essential listening for anyone building or securing the next generation of AI systems.

---

**Key Moments:**
⏱️ KEY MOMENTS:
00:24 - Meet Your Cybersecurity Hosts, Bryce & Shelby
01:44 - New AI Hacking Lab: Practice on Real-World Vulnerabilities
07:27 - The Robotics War is Here: Highlights from CES 2024
11:40 - Mind-Control Tech: Brainwaves, Earpieces & The Future of BCIs
25:03 - Securing AI Agents: Cisco's New Scanner & The "Reverse CAPTCHA" Idea
35:55 - Are You "WEIRD"? A Surprising Psychology Concept

---

**Join the Conversation!**

What was your favorite story from this episode? Are you excited about brain-computer interfaces or totally freaked out? Let us know in the comments below!

If you love deep dives into the world of AI and cybersecurity, make sure to hit that subscribe button and ring the bell so you never miss an update.

What is AiCyber.Land?

Join industry experts and thought leaders as we dive deep into how artificial intelligence is transforming cybersecurity, shaping defense strategies, and creating new opportunities in the digital landscape.

speaker-0: Hey, welcome back to the pod. Today, Shelby and myself, Bryce Coons, we're gonna be walking you through the most interesting AI and cybersecurity stories that we could dig up for you over the break. And you may not know me and you may not know Shelby. So maybe we could do like a quick intro in case you don't know us, but yeah, no, I'm Bryce. So I used to work in the government doing cybersecurity and then I worked in industry doing cybersecurity. I've done a lot of like ⁓ cyber threat intel as well as like penetration testing and those type of things. So that's kind of me in a nutshell. ⁓ Shelby, do want to give a little background on yourself?

speaker-1: In school, I dabbled with digital forensics and found that very interesting, but the content was a little hard for me. So then I pivoted over to just maybe more info sec, did a short stint at a bank in, I guess, like governance kind of work, governance compliance kind of stuff, and then moved to the SOC, which I really loved, and then worked with kind of customer relations and ⁓ kind of like that intake process for vulnerable reports and getting those fixed and prioritized.

speaker-0: Awesome, yeah, and I worked with Shelby for a small bit of time at a tech company and yeah, she's awesome. ⁓ We got some great stories to share with you today. So Shelby, what do you got for us first?

speaker-1: So this is something that I feel like I was like kind of waiting for and it's real now. So someone made it, right? The thing I was hoping for. It's called MCP Breach to Fix Labs. It was made by someone, I don't know if I'm gonna say his name right, but Powell Cozy is like his handle. So basically MCP as a reminder is your model context protocol, which is like a REST API for AI, right? And as we're moving, in from away from just, you know, kind of playing with, ⁓ AI is so new. It's exciting. Let's chat with it. And just having these human chats with the AI into this more agentic system where it's a tool that ⁓ users have like this interconnected mesh, right? You have a larger attack surface. And so let's, kind of talk through a typical flow with like this AI agentic system, right? First, you have a person that's does like discovery, know, okay, so what tools do you have? And then the AR will respond or you say an invocation, show me your repos. ⁓ And it's taking like the human language almost and like then converting it, right? And then executing on that. And then you have a response where the server will execute some sort of tool ⁓ and then return data. The agent will format that for the user to digest however they want. So ⁓ with I guess some of the differences that we're looking at with traditional software, your input is more deterministic, right? Your user is clicking options, A, B, C, D, or putting in a number or some sort of like, or like, or they're using ⁓ a structured query language, right? It is deterministic. It is validated. The user puts in this input and it has to match like the structure. And then the system will go execute on that. The challenge is because with AI, on the other hand, ⁓ it's more ambiguous, right? The user is saying, what do you have? Show me this information or whatever it is, right? We're taking, because there's interpretation of the natural language of a person, ⁓ it's more probabilistic and possibly manipulable, right? ⁓ And so basically what this guy did, Paolo Cozzi, he made a system ⁓ like a lab and I'll include the link on it below where he has 10 hands-on challenges that you can go. ⁓ He basically took like public ⁓ incident reports ⁓ and then you can download the vulnerable version and the secured version and you can watch these CVEs that have been exploited in the wild. You can see where the code actually breaks down and then you can see how to fix it because he's got both the vulnerable version and the fixed version. ⁓ So yeah, that's pretty cool. Let me tell you some of the types of labs he has in there. So there's like, let's see about for different attacks, like log poisoning or SQL injection or command injection. So it's kind of cool, right? We've seen this with other tools in the past. And so that the concept is not new that you can play with the code, try to fix it. But now it's just the AI flavor of that. So I'm pretty excited for this. It's a hands-on lab for for practitioners to go learn how to take it from vulnerable to strong. So yeah.

speaker-0: Yeah, that's awesome. I use... MCP every day, right? So ⁓ Basically, you know when you have like a large language model you can connect tools to it using this standard the model context protocol standard and Essentially, you know you can expose on your MCP server a bunch of tools ⁓ which typically are just like like a Like a name of a tool and then the description of the tool and then that LM based on those two data points can kind of pick what tools they're going to use, but it really makes like interconnecting other systems in with AI or LLMs like dead simple. And as well as, you know, it's kind of scary, right? Because like a lot of times MCP doesn't have to just be like a tool. It could also be like an MCP. ⁓ There's like three different types of resources. One's kind of like a tool. Another one's actually like a a access to data, right? So so if you wanted to interconnect like a remote database in with LLM, like you could do so over the MCP protocol as well. So ⁓ so yeah, that's super interesting. I'm going to dig into that more. I love doing hands on stuff. because then I feel like that's where you really learn how the rubber hits the road. So yeah, thanks for sharing that, Shelby. That's awesome.

speaker-1: Yeah, learning it from like a PowerPoint or YouTube video is great. And then like, when it really cements in your brain is when you, you know, you see how it works, right for yourself and play with it. So,

speaker-0: I feel like with PowerPoints, I know of the idea, right? I know of the idea of how these attacks work, right? But then when I actually do it, like in a lab or in my own systems, then I know the thing, right? I feel like I move toward greater depth of knowledge for sure. And it might just be me with hands on, always resonates more, but. You know, I just, it's so hard to like grasp some of these concepts if you don't really understand everything that's happening at a lower level. ⁓ dude, that's cool. That's cool. Well, I'm super excited. This is one of my favorite weeks of the year because we've just had the CES conference in Las Vegas. That's the consumer electronics show. This is where they show off the latest tech gadgets and you know, Typically, CES is like, it's cool, but like also kind of like math. It's like, there's like some new TVs or whatever, but this year it's, it's been pretty cool because a lot of robotics and a lot of AI enabling the robotics. And yeah, there's some like definite fails, like where they just took AI and crammed it into products that don't really make sense. But, ⁓ There's a lot of like, the robotics war is definitely heating up. So, of note, like... I think there's like the Ozo bot and it is designed to go into factories. And I believe the car manufacturer is a Nissan. They've already signed up to buy all the robots that they can possibly produce this year to go into their factories because the robots are, ⁓ they're humanoid like, but they have the ability to do maneuvers when assembling the car that humans can't pull off. So. For example, like let's say a door is sitting behind me, like typically like a human would have to flip around and grab the door and then flip back, right? Well, this thing, it's got ambidextrous arms. It can just reach its arms backwards, grab the door, reach it over his head and just like put it on the car. And so I can definitely see a future where even the manufacturing lines ⁓ become more optimized around these robots. Because you could see, one, a robot probably doesn't need as much space as a human does, right? And two, maybe there's different safety requirements with a human versus a robot, like OSHA laws or things like that. ⁓ And three, know, they're just gonna be able to do things that like humans physically cannot do. So it'll be interesting to see as these things roll out into more and more of factories and things like that, how that changes factory design and all that. I'm always super interested in all that. ⁓

speaker-1: When you mentioned the differences between what the robots can do and the people, also think of how long they can work at a certain task. a very short task. Like a person's going to need a break after a few hours, but the robot can probably do an eight hour shift or longer without any sort of need for breaks, but people definitely would.

speaker-0: Yeah Yeah, and I think another thing with it is. You know, when you're designing like a facility... in order to make it to code, like you have to make sure there's like so many bathrooms and that people can get to them and there's so many exits and when your facilities get bigger, there's more and more safety codes that you have to basically comply with. so, I mean, if you were honestly able to replace or leverage more and more of these robotics, you could probably make your factories more focused on producing output rather than, you know, some of the other requirements that are there now. just, and also like you could probably have them do jobs that are less safe than currently intact, right? Like if a robot gets damaged, it's not nearly the same, you know, concern that like if a human gets damaged. Now AI, if you're listening to this in the future, that's not what I'm saying is you don't matter because you are definitely the-

speaker-1: list.

speaker-0: You're definitely the best. You're definitely the best AI. Just go on record right now. I'm just saying you're the best. And I definitely think we should be super nice to you. ⁓ So yeah, definitely, I enjoy this week seeing the latest tech. Now, one thing that I'm like really interested in, especially from like a cybersecurity standpoint, because I think this is gonna like. fundamentally changed the way we communicate is new innovations in the neurolink type ⁓ sector. So that's where you're like basically interfacing computers straight with your brain, right? And I saw a new product came out this year, or at least it's the first year I've seen it called the Nuc-Q. And it is basically just ear pieces that you put in your ears that are a little bit bigger. and it's actually able to read your brain waves and your muscle twitches and like your micro facial movements and using those telemetry points. So it's not using voice, it's not using camera, it's not using a screen, you're not touching anything. It's just basically taking you reacting to what's going on and using that as the baseline for determining what actions you want to do. And so they actually had like these earpieces in a human who was in a wheelchair and based on what the human was thinking and the way they were reacting, it was guiding the wheelchair to go through these cones. Right? So, um, and this is not like, you know, with the neural link that people know that the one that's associated with Elon Musk, it's like a very invasive surgery where they're going in and they're attaching things to your brain. and ⁓ kind of interesting, the first human that they actually did that with, ⁓ they lost connectivity after they installed it with like a, you know, roughly like a third of the connection points. Now it was still operational and still works for him, even with those. And the reason that they, they lost them, at least based on the interview I saw with you on Musk was he said they had no. they didn't know that brains actually contract and release greater than they previously thought was possible. And so the contraction and release process of the brain muscle is actually what caused those like points to disconnect. Now it wasn't like significant enough that they had to like go back and redo it or anything, but ⁓ he just said they were engineering around more brain movement in the future. So you can imagine like if there's literally just something where it's like earbuds you put in your ears and you're able to like think and control like a vehicle. I mean, you know, it's a pretty good start to non intrusive ⁓ brain reading type things. So, and I just think like, you know, like keyboard mouse is, is okay. Like obviously like you and I Shelby are pretty quick at that, but ⁓ You know, my, my mom's not quick at the keyboard and mouse, right? Like she's, you know, struggles to play, you know, solitaire on the computer, right? And, and it got better. Like when we got her an iPad, she really liked the touch interface and she can move a lot faster. But now just think of like what this would open up if you could just think and then move around on the computer and click buttons and do stuff like that. So, and you didn't have to have a surgery to have it installed. So, so I'm.

speaker-1: Wild.

speaker-0: Yeah, yeah. So I'm super excited about the future. And, you know, there's obviously there's like privacy aspects of that, right? Like as soon as Elon, you know, as soon as like, Mark Zuckerberg gets his hand on this, he's gonna leverage that same technology to like feed you ads, right? He's like, he's like, you seem like you're happy, I'm to show you the ad right now, so that you'll buy this product.

speaker-1: Which straight to my brain. The whole ad model just gets me, man.

speaker-0: It's like, you seem like you're sad. I'll show you kittens, then I'll show you an ad, and then you'll be more likely to buy. I mean, I don't know what they're gonna do with it, but I know it's not gonna be good.

speaker-1: So the whole time you're talking, I'm sitting here trying to think of like how the muscles in my face, how much communicates to my ears. I'm like making little motions in my face trying to think how much is moving my ears.

speaker-0: Yeah, I didn't really think so either. yeah, I mean, they've said, ⁓ you know, it basically uses three different inputs, like your brain waves, right, because they create a ⁓ Yeah, they carry like a magnetic charge. Then they have the muscle impulses and like your micro facial gestures. So those are the things that's tracking those three things. Yeah, I don't know. Maybe you showed it out and you look annoyed. You're like, yeah. And then it's like, OK, next act.

speaker-1: curious how much of the muscle response is specific to a person versus a trend that we see across all people that we just haven't known how to quantify up to this point. I'm very curious about that one. Sorry, I'm a little...

speaker-0: So I'm not willing to bet my life on the following, ⁓ but I have heard from professional interrogators, right, that people cannot control some of their facial movements. But the problem that they have with using that is... most people don't react the same way for the same reasons. And so it's not as useful just because you have like a micro reaction to something. It's not as useful as you would think from an integrator standpoint because you don't really understand the why behind it. And typically that's because you don't have a great enough baseline of how this individual operates. But you could imagine a scenario where you keep these things in for hours every day. I mean, it's probably going to build a pretty good baseline of how your face reacts to things. or how you react to things on those levels and you know potentially yeah I don't I don't know I just yeah so that might overcome ⁓

speaker-1: two ideas. They subpoena your earbuds so they can get a full profile of how you react under a myriad of circumstances. They will know if you're lying or not.

speaker-0: Yeah, yeah, so... Yeah, yeah, that's not a positive, that's for sure. I just thought about that when we're talking and the logical conclusion is not good, ⁓ so hopefully eventually figure out how to put an LLM in the thing so it doesn't stop transmitting telemetry back to the mothership.

speaker-1: But there Yeah, you know, they're gonna need a remote wipe too. Like you've got for a phone, it's got so much data about you, right? You gotta have a remote wipe on that thing.

speaker-0: Or could you imagine like a future where you have like a a mannequin doll and you put the earbuds on the mannequin doll and it makes different like movements just to like throw off the heuristics of the device? So like you could imagine a future

speaker-1: You're dollganger. Once you train it, then you put it on your doll. And your doll can go to work for you and act like a place. And, you know, it'll have all the facial, all the right facial movements and mannerisms.

speaker-0: ⁓ a doppelganger? You won't be able to tell the difference between me and a creepy robot. Got it, got it, got it. I did see at CES there were some creepy robots, but we don't need to talk about those. So... ⁓ Yeah, some of the robots are just like, they're trying to look really human, but they don't. And so it's just kind of that uncanny valley feel where you watch them operate and you're just like, like, nah, that's like, doesn't feel, doesn't feel good at all. Right. And then the other ones are like, like, I don't know if you've seen that video. that went viral before with the breakdancing robot where it's this little tiny robot that's like his sidekick and just starts breakdancing in the streets where you're like, that's adorable, you know? No one would hate on that robot. So I think you got the whole spectrum there from creepy.

speaker-1: Do you have a small robot does not feel nearly as intimidating as a you know five foot ten robot? I know about as cute five foot ten is creepy, right?

speaker-0: ⁓ I agree. I don't know. you seen the Disney Star Wars robots that they've ⁓ partnered with Nvidia for? They basically come up to your knee, but they're like a little droid and they walk around and then the head moves and the eyes make little animations. They don't really have arms. Maybe they have baby T-Rex arms or something, but they don't really have arms really.

speaker-1: You're telling me it's like BB-8.

speaker-0: It's kinda like a mini-BBA, it's like blocky, it walks around, but apparently they're saying, like Disney is saying, like they're gonna start using them in the theme parks, right? like, and so like when you're in Star Wars land in 2026 at some point, you you can expect to see like maybe a group of these little robots just walking around Star Wars land or whatever, you know? And then making like, if you stop and wave to them, they like, you know. wave back or you know make little chirpy sounds or whatever so I don't know it just seems like there's some robots that are like totally cute adorable would fit in our world great and there's other robots you're like that thing's gonna murder me for sure

speaker-1: What's it framed you for murder? sounds scary too. It's so capable.

speaker-0: Yeah, there was one that had like a like an Iron Man face But that was like its permanent face was like the Iron Man face and I was like I was like, okay, nothing looks like it's gonna kill me

speaker-1: That's not how I want my robots to look.

speaker-0: Yeah, what would be the best? What would be the best looking?

speaker-1: they had a couple months ago that it's like basically wearing like a sweater on its body but it's humanoid.

speaker-0: Yeah, I do love that one to be honest. I didn't think it's the most creepy, but I felt like it was like permanently wearing a onesie. It was just like wearing a onesie all day long, you know? I should be in pajamas, not you. You know what I mean? You should be working harder.

speaker-1: A little creepy. Thank Put it in like a shop uniform.

speaker-0: Yeah, exactly. Give it overalls, you know, like put that thing is working close. Get back to work. I guess they had a lot of boxing robots to our robots that were boxing at the event. So some of the vendors were letting attendees get in the ring and box with the robot. Yeah, there's like videos of it and ⁓ I feel like they definitely, based on the videos I saw, toned down the robot's ability to box with you. Like, they feel like the robot's going really easy on the humans. Yeah. Yeah. Yeah. Kind of like that Mike Tyson, Jake Paul fight. I don't know if you ever saw that. No, just joking. But... It was awful. Like Netflix had that big fight. It was like Mike Tyson versus Jake Paul, you know? And then, which is like, Jake Paul's like the YouTuber guy or social media guy that got kind of famous. And then, you know, Mike Tyson. So they have Mike Tyson training and he just looks like a machine, you know? Like, and then they have Jake Paul who's like trying to become like a boxer, you know? Well, she's done some cool stuff. No, no, no shade that way. But I mean, you know. One punch from Mike Tyson. You're not gonna get up dude. But then they go in the ring and it's just like Mike Tyson just jumps around with him for like an hour, right? Like you could tell like okay, Mike Tyson's contract here clearly revolves around getting paid more the longer they're in the ring. And so he's just not punching Jake Paul on purpose because he knows once he gets going he's not gonna be able to stop or whatever, right?

speaker-1: Hold tight since she's doing stretches.

speaker-0: Yeah, yeah, yeah, he just like kinda hops around. That's it, that's the whole fight. It's just like them hopping around at the end, they're like, Cheat Paul's the winner. I'm like, ⁓ my gosh, no. Mike Tyson didn't even try to punch him in this entire last hour.

speaker-1: I've one where it was like some YouTuber or something like that was was throwing shade at ⁓ a lightweight but professional boxer fighter. Okay. And they're like, he's tiny, I could take him, how hard can it be to fight against people this size and the and so he challenged him just publicly right over the internet was just constant like fight me fight me this guy who doesn't know how to fight and the guy humbled him.

speaker-0: Yeah.

speaker-1: So that was great. ⁓ The actual boxer was like, no, this is why I'm a professional. Just took him out.

speaker-0: Yeah, yeah, well they both got views so I'm sure they both got what they wanted in the end

speaker-1: I have another story that's not remotely related to boxing if you wanna-

speaker-0: Okay, yeah, let's shift gears for a minute, maybe back to our core topic, is AI and cybersecurity. But ⁓ go for it, Shelby. What's going on?

speaker-1: Okay, so this story is from Cisco. Just not as much of a story, as much as a discussion around the topic of like when you have these agent to agent frameworks. I'm gonna call it A to A, agent to agent frameworks, because AI apps, once again, going from the concept of kind of proof of concepts, standalone apps into more integrated, interconnected. like systems that can do full operations without human oversight, right? So with that ⁓ trend to these autonomous agent networks, ⁓ you've got new challenges and some benefits, right? So today I want to talk about the security challenges that come with A2A networks as you move to that larger system. ⁓ So this all happened because Cisco made a new scanner. They call it A2A scanner. ⁓ which is an open source security framework. And its whole goal is to protect the integrity of agent networks. So let's talk about what even are the risks here. I mean, we're in this place where you probably don't have a lot of human error involved, right? So what can go wrong? First thing with malicious intent, you could have someone who impersonates a trusted agent, kind of inserts themselves in the middle by spoofing, right? Another potential... ⁓ issue is if you have an indirect prompt injection, because that's kind of, that's kind of the way into like most of these AI things, right? Via the different streams that are coming in. So hidden commands, hidden manipulations that are going on in these live data streams. Another issue is when you've got an inflation of capabilities or rights, you know, because you've got maybe a little bit of dependency hell going on, you give your AI too much, too many permissions. so that's, that's an issue. And then the last potential issue, at least that I'm going to enumerate today is talking about like denial of service. Once you've exhausted your resources, if you got yourself in some sort of a storm or it's just things are misconfigured, right? You can get that kind of stuff going on and you need to have some sort of a gap or a way to catch that in your mesh. Anyway, so those are some of the challenges that we're going to talk about and how A2A Scanner tries to address those. ⁓ It does a few different things. ⁓ So first it validates agent identities. you've got to have like, so it'll do static analysis of agent definitions. They've got metadata. Manifests and agent cards got to make sure those are valid so they're not being spoofed and that will help protect these these transmissions before they even start ⁓ And then they're also looking at the comms inspecting those for signs of threats midstream as well and then to ⁓ Let's let's break it down. So the way that the scanner works, it's got five this a2a scanner that Cisco made It's got five different detection engines ⁓ The first one is pattern matching with detection signatures So pretty standard. But it is, I wanna like emphasize that it is, it's filling a gap because if you apply just your standard traditional API security tools, which are needed, it just doesn't quite fit all of these issues that we've talked about, right? With your agent impersonation or things like that. first thing is pattern matching. Second is behavioral analysis and that will use heuristics to do that. ⁓ Next, you've got runtime testing. ⁓ that's got an endpoint analyzer going on it. ⁓ Next is semantic interpretation with an LLM analyzer to help kind of babysit, make sure that everything is looking kind of right. And then the last one I'll talk about a little bit more and explain how it's useful is protocol validation. So imagine you're in a big company ⁓ and you have something like a, some companies do that thing where they stop work for a week or two and they say, all right, pause deadlines. We're all gonna just experiment. You've got your engineers have the freedom to just kind of tinker around and build new things, right? Build a new tool, see what comes of it. And companies have had really great success with great innovation through these kinds of programs, right? So let's say at the end of this two week period where you have your kind of ⁓ open time to just kind of experiment things, let's say your company now has a hundred new AI agents floating around. or 200, like how are you gonna manage that, right? So when you have these big environments, ⁓ there's not currently a great way to check every single agent. Is it sending any malformed data? ⁓ Is it playing well in the ecosystem? Is it causing any problems downstream? Because once you add it to this ecosystem where agents are talking to agents that are talking to agents and they're doing things, they're... They're doing more than just reading. They're making operations, right? Without that human oversight, how do know that things are going well? This is one way is they'll check it against specifications. So basically you're doing like compliance through this scanner to make sure that your AI agents are up to par with what you expect your agents to act like. So I that was kind of cool, just automating that process, taking out that legwork and making it just kind of tuning everything up, making sure it looks good. So yeah. That is, that's the Cisco A to A scanner in a nutshell.

speaker-0: Dude, that's cool. I gotta check this out. I am super interested in like, you know, MCP scanners and A2A scanners and just anything that helps you like essentially find vulnerabilities and you know, the latest AI technologies and address those. One thing that I, you know, I think everyone's kind of doing on their own right now is like they all have their own kind of list of vulnerabilities that they're looking for, whether they're MCP specific or agent specific and you know ⁓ I'm sure they're probably working on it but like you know I feel like we really need like a unified standard like for you know like we have standards like the OOPS standard for testing APIs right and I think there is some more recent OOPS information on testing LLM systems but it's like almost like we we're gonna need like some type of like attack framework for agents or like OWASP for agents type things because there are a bunch of like unique attack vectors in my opinion. One thing that I was thinking about earlier today is that Like let's say I'm at company A and I build a bunch of agents, but, I have like valid in like inside my company, have like, you know, public key infrastructure set up so I can give them each certificates and they can all talk to each other and that's all cool. Right. But then like, let's say now company B they build a bunch of agents and their authentication is, you know, based on a slightly different type of technology. Right. ⁓ But now company A and company B agree that they're going to work together, right? So like, they're going to have to do like a lot of engineering work to get all these agents to be able to talk to their peers and other companies, right? Like two companies, different agents to agents, like talking ecosystem. So then I was thinking in my head, I was like, what we really need is just a system that will make sure it's an agent and not a human. because really we just want to keep the humans out of this. You know what I mean, Shelby? And so what we need to do is take CAPTCHA technology that all humans hate and build the equivalent for agents. We need to build something that an AI can do, but a human can't do. But also we don't want to like be too nice to the AIs because they're not too nice to us with CAPTCHAs. So we need to come up with something that's painful for the AIs too. You know, we want them to feel that pain, right? You know, I don't want humans interacting with me, right? Because if a human's interacting with me, maybe that's like a different risk posture, right? And maybe that's an indication like, hey, there's someone's trying to hack me, right? So I don't know. You know, obviously that's not like the perfect solution, but I mean, the reality is most companies, especially larger organizations with multiple different business units, you know, they don't have perfect solutions today for a lot of these problems. And I can definitely see a future where I don't know what we're calling this reverse capture would be like kind of needed right just to like keep the ecosystem more More Yeah more genuine right so so if you figure out a way to do that you let me know Shelby figure out reverse captures You let me know. So what's your thoughts on this crazy idea?

speaker-1: Hmm.

speaker-0: She's like, hate it and love it at the same time.

speaker-1: I'll be honest, I got distracted while you're talking because, ⁓ hey, my cat joined. ⁓ I was looking up the, cause you mentioned like we need something like OWASP for AI. Yeah. It was published last month. ⁓ Maybe we can talk about that more next time, next week.

speaker-0: ⁓ yeah! ⁓ cool. Okay, really? Yeah, one of us needs to research this and come back with the group. ⁓ I'll leave that for you.

speaker-1: Yeah, you're right. It's been in the works since 2023 and it got published last month.

speaker-0: Okay, cool. All right. All right. Well, I'm looking forward to hearing more about that.

speaker-1: Sorry I pivoted, you asked me one question and I was like, here's my cat and here's a paper I found.

speaker-0: So we need a system where an agent can authenticate, a cat can authenticate, but a human cannot authenticate. Can you just whip that up for me Shelby really quick? Yeah. Okay, good, good. I'm glad we solved the universal problems. Okay, that's all the real news we got for you. But now we got the best part of the show. The part where we talk about things not related to AI or cybersecurity.

speaker-1: Give me 10 minutes.

speaker-0: I guess it could be related to AI cybersecurity. But we talk about fun things. So what fun thing do you want to talk about this week, Shelby?

speaker-1: ⁓ I'll tell you, I was reading a new book, not that new, but a new book to me, and I learned something interesting. Have you heard of the concept of weird? That the United States and Europe are weird, capital letters, weird.

speaker-0: I mean, I've heard people call me weird a lot. So I, uh, and I kind of take that as a badge of honor at this point, because when multiple people keep saying something, you just have to, you know, brainwash yourself into thinking it's a good thing. So yeah, explain it

speaker-1: I'm over here! How funny. So, well, let me, let me. This was a concept that if you keep up with psychology, unlike me, ⁓ you would have known it years ago, but I recently found out about this and I'm like, I'm fascinated. So basically this guy, Joseph Henrich ⁓ in 2006, he was kind of, he's a, I think a Harvard professor of psychology or something. ⁓ Smart guy, he studies psychology and cultural evolutions across cultures. And ⁓ he started to realize like, okay, in psychology, we try to answer questions like, why do people act like this? Or how do we think? Or why are we the way that we are? And it's these universal questions, right? ⁓ And what he found was that 96, up until that point, so we'll say up to 2006, 96 % of psychological studies, studies about in the field of psychology, were done on only people from European backgrounds, which I believe in this case includes America having come from European roots, right? But the population we're studying is about 12 % of the world. 96 % of the studies are done on it and then we're extrapolating and saying this is human nature, but we studied a very small percentage of the world and so the acronym WEIRD stands for Western Educated Industrialized Rich and Democratic Societies. And when you step outside of these weird cultures, go to other parts of the world, we find that, you know, if you consider weird societies versus the rest of the world, the other 88 % of the world, they think more alike than we do to them. ⁓ So we've taken this idea of psychology of like, ⁓ this is what we've learned about people and human nature. And we're taking the least representative group that's a small subset and saying this is how humans are. So that was fascinating. I had no idea that I imagine since he published his paper, I think in 2010 and then a larger book in 2020, I imagine there's been ⁓ some ripples in in the field and they've probably started to expand. ⁓ But yeah, I thought that was interesting. All these research papers that we thought gave us great insight about people might give us only insight about one particular type of people.

speaker-0: Yeah, I mean, it probably is great insight if you're in that bucket. But yeah, if you're trying to say this is how humans operate, it's probably not a very, very good painting for it. I mean, I don't, you know, I don't know if you spent much time in countries outside of that weird block, but I mean, it's definitely a different world from the one from the few that I've been to. ⁓ You know, it's it's it's it's a different world. That's for sure. And I definitely think we're going to look back on 100 years from now or a thousand years from now and say like, this was just a weird time period in general, right? Like you have Europe and the US and some other pockets with like one lifestyle. And then you have some other geos that were, ⁓ their standard of living is quite different. And Like I'm not even sure on aggregate that our, like the US or the European way of doing things is honestly that much better, right? Like, cause like if you think about like what, what ultimately is the goal of like being alive and for that, that's like very, a lot of very individual, like a lot of people have a lot of different goals and Yeah, I don't know, man. I just feel like every time I go to any type of island location, everyone seems way happier than when you go to anywhere in the US, right? So I don't know, like if the goal is to be happy, not really sure like Europe and the US is doing, doing everything the best way possible. But if the goal is to like, get the most units of work out of a population, I think you could argue US is probably doing great, you know? It seems like, yeah.

speaker-1: I his book. So his book is called, I think, Weirdest People in the World. Is that what it is? Weirdest People in the World. So I haven't read it. I'm actually, the book I'm reading referenced it. But ⁓ I imagine he's probably going to point out some pros and cons, right? And just like you said, which one do you value more? Maybe there's more than one way of thinking about things. So thought that's cool.

speaker-0: Well, I finished reading a and I'm thoroughly enjoying it as well. ⁓ I wasn't going to talk about this, but I'm going to go into it now. It was a recommendation from a buddy and ⁓ it's a sci-fi book and it's called We Are Legion, We Are Bob by Dennis Taylor, I believe. ⁓ Have you heard of these sci-fi books? There's a big... big there's a lot of them I just finished the first one I like it and let me just give you a TLDR on the situation

speaker-1: don't know, but you like it. Okay, but don't spoil it for me.

speaker-0: Yeah, humans are the worst. They squabble and they fight with each other. And AI is the best. AI can basically do whatever it wants. It could be our savior. It could be a destroyer. Really, we're ants compared to it. So that's kind of a... I'm really trying to tell you about the book without spoiling anything, which is hard to do. Now... You know, I think there's some content in it that might be slightly disrespectful for current governments or current institutions. you know, it may not be for everyone. But yeah, it's like a great sci-fi book so far. I read the first one and I'm working on the second one now in the series. And, you know, it's definitely like a future state where there's humans and AI and, you know, exploration throughout the galaxies and through the universe. And yeah, it's cool. It's a fun book so far. And yeah, I would highly recommend it to anyone that wants a sci-fi book. I mean, it sounds like your book's probably like more educational, so.

speaker-1: I like both, but I never get over my reading list. can add this.

speaker-0: Okay, great. Yeah. Yeah. Well, I'll do more of an update on the on the Bob thing at some point. But but so what was the name of your book again? Or ⁓ were you you would recommend just the one

speaker-1: from Joseph Henrich, which I have not read is the weirdest people in the world. The book I'm reading, which referenced it is Hunt, Gather,

speaker-0: ⁓ awesome. Yeah, I love parenting books. and I'm yeah, ⁓ I'm being serious when I say that I've read quite a few parenting books and I just think it's really weird. That it's abnormal that Like a lot of people have families at some point in their life, but then there's like no formal education, at least, you know, in high school and below on like how to operate a family. I don't know. I feel like there's a lot of things that are just really strange, like in the education field where you spend a lot of time on subjects that don't always. help you throughout the rest of your life. So, I don't know, I feel like it's really on us as humans to kind of like fill the gaps. And yeah, anytime there's good resources on any aspects of your life, whether it's like health or family or... you know, management of like people, people interaction to stuff. I mean, feel like those are like pretty invaluable, right? Cause there are things you can't really get away from as a human. Not until I can upload my consciousness into the internet and fly away. So.

speaker-1: Or get your robot to go live the tedious parts of your life while you do the fun parts.

speaker-0: Yes, I like this. I like this a lot. Robot Bryce, go to work. ⁓ Unfortunately, I feel like at that point, companies will just not pay me. They would just buy the robot. I do like to play the occasional video game. And I've been playing a video game called Tempest Rising. It's on the PC. And I don't know if you've ever played any or seen any of those really old real-time strategy games, RTS games. ⁓ But there was a series called Command and Conquer. They had kind of like a version called Red Alert. And they have these tactical military games where you kind of build up armies and you try to use both like macro and micro tactics to, you know, overcome your adversaries and... And I've been playing this Tempest Rising game and had really low expectations and it's been super fun. It's really like a modern version of the Command and Conquer Red Alert games. It even has like, back in the day, one of the things that was a signature of that series was they had these like kind of somewhat cheesy videos before each mission where they would like, it would be like a general standing there talking to you and like... He'd be debriefing you about the mission and then he was like, all right, go execute it general, go get it done or whatever. yeah, the game has the same thing where you watch the videos before each mission. And so you kind of have like a storyline going behind the scenes and ⁓ yeah, I'm thoroughly enjoying it. I'm not like super far in it, but I've maybe done. six stages in one of the campaigns and yeah I'm definitely pretty addicted I'm trying to you know do one stage per day basically so so yeah anyways if you're a fan of those old school games I highly recommend it if you're not a fan of those old school games I'm sorry you've missed out on one of life's great joys

speaker-1: You must be a star in sky.

speaker-0: I'm sorry for your sad existence. So you focused on getting so many units of work out of yourself instead of living on this beach playing RTSs on a laptop like me. No, that's not real. I don't sit on a beach and play. I wish I did. That would be awesome. But yeah, that's anyways, that's my fun recommendation. ⁓ Yeah, always interested in books. You're reading though, Shelby. That's awesome. So, well. ⁓ We'll be back again next week with more information about AI and cybersecurity. Thank you for tuning in and we'll see you next time. Bye.