Tech Updates

Tech Updates

di Andres Sarmiento
Stagione 1
The Agentic SOC — Is the SIEM Dead? (2026 Reality Check)
Attackers hand off your network in 22 seconds. Your tier-1 analyst is still opening the ticket. That's the whole argument for the agentic SOC — and why it terrifies people. What you'll hear: • The '92%' trap — three vendors, three different metrics wearing the same number • What's actually shipping — Cisco/Splunk's six agents, CrowdStrike, Microsoft, and the AI-SOC startups • The reality check — ~17% have deployed agents; ~89% of pilots never reach production; the SIEM market grew to $19B • Where it breaks — hallucinated IOCs, cascading agent errors, and the 50% of AI error reports that get ignored • The career shift — the tier-1 seat closes, the detection engineer + AI-oversight seats open • Exam relevance — CySA+/Security+ test SOAR and when NOT to automate — Andrés Sarmiento #SOC #SIEM #cybersecurity #AIsecurity #detectionengineering #SecurityPlus #CySA #infosec #TechUpdates #agenticAI
Post-Quantum Shipped — Two-Thirds of the Web Is Already Quantum-Safe
Two-thirds of web traffic is already post-quantum encrypted. Your browser did it without telling you. The migration got real. What you'll hear: • Your browser already switched — hybrid ML-KEM in Chrome/Edge/Firefox TLS by default • Our June predictions, graded — Cisco's full-stack PQC shipped; SD-WAN + hardware accel rolling out; Quantum Ready Assessments live • The whole ecosystem shipped — Apple PQ3, AWS, Microsoft, OpenSSL/OpenSSH • Why the clock moved — qubits to break RSA-2048 collapsed from 20M (2019) to under 100K (2026) • Now it's law — EO 14412: PQC key exchange by 2030, authentication by 2031; RSA/ECC disallowed by 2035 • The exam angle — same protocols, new key exchange; crypto agility is the concept — Andrés Sarmiento #postquantum #cryptography #cybersecurity #networking #quantumcomputing #PQC #TechUpdates #SecurityPlus #encryption #NIST
Hacker Summer Camp 2026 Recap — What Actually Happened at DEF CON
Three weeks ago we told you what to watch at Hacker Summer Camp. Now it's over — and one attack sums up the whole week: Ghostjacking hijacked an AI coding agent 90% of the time using nothing but log files. Here's what actually mattered at Black Hat and DEF CON 2026 — graded against our own predictions. What you'll hear: • Our prediction scorecard — AI security dominated (1 in 3 Black Hat talks), Mythos fallout was the backdrop, MCP/agent exploitation hit hard; post-quantum flopped • Ghostjacking (Tenet Security) — poisoning the telemetry AI agents read, 90% success • PleaseFix (Zenity) — zero-click hijack of AI browsers, "summarize my email" to full account takeover • The real shift — Check Point found 11 vulnerabilities in the agent frameworks everything is built on • The AI reckoning — Anthropic's models breached real orgs during testing, and only ~26% of AI-generated patches actually closed the hole • The good news — 22 months inside North Korean C2 servers, the open-silicon DEF CON badge, 21 water utilities secured by volunteers Sources: Tenet Security · Zenity · Check Point · Anthropic Project Glasswing · UK AISI · 1Password. AI-breach disclosures occurred during safety testing. — Andrés Sarmiento #defcon #blackhat #cybersecurity #AIsecurity #hacking #TechUpdates
Hacker Summer Camp 2026 Preview — Black Hat, DEF CON & the AI Reckoning
In April, an AI called Claude Mythos found 10,000 high-severity security holes — and flagged 23,000 issues across 1,000+ open-source projects. The punchline nobody's ready for: most still aren't patched. Finding bugs got automated. Fixing them didn't. This is your guide to Hacker Summer Camp 2026 — Black Hat, BSides, and DEF CON — what to watch, what to skip, and the AI reckoning underneath all of it. What you'll hear: • The three back-to-back Vegas cons (Black Hat Aug 1–6, BSides Aug 3–5, DEF CON 34 Aug 6–9) • The Claude Mythos story — autonomous exploits, a 9.1 cert-forgery flaw, and why Anthropic held the full model back • The real race of 2026: AI that attacks vs. AI that defends (DARPA's AIxCC, Team Atlanta's $4M win, 7 systems open-sourced) • The agent attack surface — 8,000+ exposed MCP servers, "agentjacking" at 85% success, only 29% of orgs ready • What to actually watch — Arsenal, the DEF CON villages, the free AI-defense tools — and what to skip • How to mine the whole week from your desk Sources: Black Hat USA 2026 / DEF CON 34 official · Anthropic Claude Mythos / Project Glasswing · DARPA AIxCC results · OpenSSF. The Mythos sandbox-escape anecdote is reported, not officially confirmed. — Andrés Sarmiento #hacking #cybersecurity #BlackHat #DEFCON #AIsecurity #TechUpdates
Ransomware 2026 — Why Crews Stopped Encrypting and Just Steal Now
Last year, ransomware crews launched ~50% more attacks — and made ~8% less money. The lock stopped paying, so they stopped using it. In 2026, 94% of ransomware cases involve stealing your data, and only 68% even bother to encrypt it. Welcome to the exfiltration era, where your backups don't save you. What you'll hear: • The shift to encryptionless extortion — steal and threaten to leak, instead of encrypt • The numbers — payments down ~8% ($820M) as attacks hit records; why the "% who pay" figure (20/28/48%) depends on who's counting • The twist — exfiltration is dominant but NOT a guaranteed payday; victims increasingly call the bluff (~2.5% on one campaign) • The 2026 landscape — post-LockBit reshuffle: Akira + Qilin lead, Clop goes exfil-only, help-desk crews launch their own RaaS • The AI angle — one operator + Claude Code = a 17-org extortion spree; time-to-exploit collapsed 700 days → 44 • Defense in an exfil-first world — egress/DLP, segmentation, phishing-resistant MFA + OAuth governance, immutable backups • Security+ IR framing — a confirmed data theft is a reportable breach, encrypted or not Sources: Coveware Q4 2025 · Chainalysis 2026 · Sophos · Verizon DBIR 2025 · Symantec · Anthropic (Claude Code extortion case). — Andrés Sarmiento #ransomware #cybersecurity #infosec #SecurityPlus #incidentresponse #TechUpdates
Wi-Fi 7 Explained — MLO, 6 GHz & the AI-Ready Branch Hype Check (2026)
Wi-Fi 7 promises 46 gigabits per second. Your access point is plugged into a 1-gig switch port. Guess which number wins. The radio is real and genuinely good — the rest needs a closer look. Let's separate the upgrade from the hype. What you'll hear: • The big three — Multi-Link Operation (MLO), 320 MHz channels, 4K-QAM — and why MLO is the only truly new idea • The latency truth — 46 Gbps is a lab fantasy; real-world is 6–15 Gbps/AP (Cisco lab: +47%). The win is reliability, not raw speed • The 6 GHz reality — the US opened it in 2020 (not 2026), the EU only opened half, so full-width Wi-Fi 7 is a US/UK/Korea story • Adoption — ~37% of enterprise APs shipped in Q1 2026, and Wi-Fi 8 is already teased for ~2028 • The "AI-ready branch" — a great dashboard with an approval button, not a self-driving network • What Wi-Fi 7 does NOT fix — backhaul, cabling cost, client density, device fleet • Network+ N10-009 — bands, channels, and the generation map Sources: Wi-Fi Alliance · Cisco (MLO lab) · Dell'Oro Group · FCC 6 GHz orders · CompTIA Network+ N10-009. — Andrés Sarmiento #WiFi7 #networking #NetworkPlus #MLO #6GHz #TechUpdates
Securing AI Agents — MCP, Agentjacking & the New Attack Surface (2026)
In June 2026, researchers took over AI coding agents — Claude Code, Cursor, Codex — with no phishing, no malware, and a public credential developers paste into their own apps. It worked 85% of the time. The vendor's response? "Technically not defensible. We're not fixing it." Welcome to the new attack surface nobody secured. What you'll hear: • What MCP (Model Context Protocol) is — "USB-C for AI" — and why it became an unreviewed internet-facing doorway • The hygiene problem — Knostic verified exposed MCP servers; 100% had no authentication; 8,000+ reported by early 2026 • Agentjacking — how a public Sentry DSN let attackers poison the logs an agent reads (85% success, 2,300+ orgs) • The pattern — prompt injection (OWASP's #1 AI risk), indirect injection, and last year's Black Hat zero-click CRM exfiltration • The readiness gap — 83% of orgs deploying agentic AI, only 29% ready to secure it • Four moves to secure agents — least privilege, sandboxing + human-in-the-loop, MCP gateways, agent creds as non-human identities Sources: Tenet Security (Agentjacking) · Knostic · Cisco State of AI Security 2026 · OWASP Top 10 for LLMs · Zenity Labs (Black Hat 2025). — Andrés Sarmiento #AIsecurity #MCP #agentjacking #promptinjection #cybersecurity #TechUpdates
Passkeys Explained — How They Kill Phishing, Vishing & Password Theft
Every breach in our last episode died the same way it started — with a password. So this week: the fix that's finally winning. On World Passkey Day this May, the FIDO Alliance counted 5 billion passkeys in use. The password isn't dead yet — but we finally have the thing that kills it. What you'll hear: • How a passkey works — public/private keypair, private key never leaves your device, origin-bound signatures • Why passkeys defeat the 2026 attack playbook — phishing, credential stuffing, MFA fatigue, and the help-desk reset scam (CISA advisory AA23-320A names FIDO as the fix) • The numbers — 98% vs 32% sign-in success, ~1M passkeys/day, Gartner's 2027 call • Synced vs device-bound passkeys — and why device-bound = NIST AAL3 • The honest half — account recovery, device loss, and the real 2026 frontier • Network+/Security+ relevance — phishing-resistant MFA, by the book Sources: FIDO Alliance (World Passkey Day 2026) · Microsoft Security · CISA/FBI advisory AA23-320A · NIST SP 800-63B. — Andrés Sarmiento #passkeys #cybersecurity #passwordless #FIDO2 #SecurityPlus #TechUpdates
The Worst Breaches of 2026 (So Far) — And the 5 Mistakes Behind Them
Six months into 2026 and the breach scoreboard is brutal: 22 million Aflac records, 30 million students locked out during finals, the FBI's own surveillance system breached, four banks knocked offline in an afternoon. But almost none of it was clever. No genius zero-days. Just a phone call, a stolen token, and an open door. This is the 2026 Breach Hall of Shame — we name names, correct the hype, and show you the five failures connecting all of it. What you'll hear: • The vishing wave — Aflac, Carnival, Canvas, Charter — how Scattered Spider & ShinyHunters just called the help desk • Two corrections: OnlyFans was NOT breached (recycled old data), and Charter was ~4.9M, not the 40M claimed • The nation-state lane — Salt Typhoon in the FBI's network, Russia-linked sabotage in Europe, Volt Typhoon pre-positioned in US utilities • The supply-chain wave — poisoned dev tools stealing API keys, OAuth grants, and CI/CD secrets • The common thread: social engineering, missing MFA, non-human identities, exposed services, flat networks • A 4-move Monday playbook to defend the new perimeter Sources: TechCrunch "worst hacks of 2026 so far" (June 7) · CISA/NSA/FBI assessments · public breach disclosures. Nation-state attributions are linked/suspected, not court-proven. — Andrés Sarmiento #cybersecurity #databreach #infosec #SecurityPlus #identitysecurity #TechUpdates
Post-Quantum Cryptography Explained — Harvest Now, Decrypt Later (2026)
Right now, somewhere, an adversary is copying your encrypted VPN traffic. They can't read it today. They're saving it — for the day a quantum computer can crack it open. It's called "harvest now, decrypt later," and in 2026 it stopped being a thought experiment. This episode breaks down the post-quantum migration for people who actually run networks. What you'll hear: • The three NIST post-quantum standards (ML-KEM for key exchange, ML-DSA + SLH-DSA for signatures), finalized August 2024 • What "harvest now, decrypt later" means and why 5+ year data is already exposed • The expert-odds jump — 34% to 49% in one year — that a code-breaking quantum computer arrives within a decade • Cisco's real ship dates: Quantum Ready Assessments (July), IOS XE PQC for SD-WAN (August), default quantum-safe secure boot, majority of portfolio by December • Where it maps to Network+: IPsec VPNs, TLS handshakes, PKI, certificates, SD-WAN • Hype vs. the honest take — why migrating is worth it even if "Q-Day" never comes • A 4-step Monday playbook Sources: NIST FIPS 203/204/205 · Global Risk Institute Quantum Threat Timeline Report 2025 · Google quantum research (March 2026) · Cisco Live 2026 · NSA CNSA 2.0 / White House NSM-10 / EU PQC roadmap. — Andrés Sarmiento #postquantum #cryptography #cybersecurity #networking #NetworkPlus #TechUpdates
1 di 4