Tech Updates

Tech Updates

di Andres Sarmiento
Stagione 1
Hacker Summer Camp 2026 Preview — Black Hat, DEF CON & the AI Reckoning
In April, an AI called Claude Mythos found 10,000 high-severity security holes — and flagged 23,000 issues across 1,000+ open-source projects. The punchline nobody's ready for: most still aren't patched. Finding bugs got automated. Fixing them didn't. This is your guide to Hacker Summer Camp 2026 — Black Hat, BSides, and DEF CON — what to watch, what to skip, and the AI reckoning underneath all of it. What you'll hear: • The three back-to-back Vegas cons (Black Hat Aug 1–6, BSides Aug 3–5, DEF CON 34 Aug 6–9) • The Claude Mythos story — autonomous exploits, a 9.1 cert-forgery flaw, and why Anthropic held the full model back • The real race of 2026: AI that attacks vs. AI that defends (DARPA's AIxCC, Team Atlanta's $4M win, 7 systems open-sourced) • The agent attack surface — 8,000+ exposed MCP servers, "agentjacking" at 85% success, only 29% of orgs ready • What to actually watch — Arsenal, the DEF CON villages, the free AI-defense tools — and what to skip • How to mine the whole week from your desk Sources: Black Hat USA 2026 / DEF CON 34 official · Anthropic Claude Mythos / Project Glasswing · DARPA AIxCC results · OpenSSF. The Mythos sandbox-escape anecdote is reported, not officially confirmed. — Andrés Sarmiento #hacking #cybersecurity #BlackHat #DEFCON #AIsecurity #TechUpdates
Ransomware 2026 — Why Crews Stopped Encrypting and Just Steal Now
Last year, ransomware crews launched ~50% more attacks — and made ~8% less money. The lock stopped paying, so they stopped using it. In 2026, 94% of ransomware cases involve stealing your data, and only 68% even bother to encrypt it. Welcome to the exfiltration era, where your backups don't save you. What you'll hear: • The shift to encryptionless extortion — steal and threaten to leak, instead of encrypt • The numbers — payments down ~8% ($820M) as attacks hit records; why the "% who pay" figure (20/28/48%) depends on who's counting • The twist — exfiltration is dominant but NOT a guaranteed payday; victims increasingly call the bluff (~2.5% on one campaign) • The 2026 landscape — post-LockBit reshuffle: Akira + Qilin lead, Clop goes exfil-only, help-desk crews launch their own RaaS • The AI angle — one operator + Claude Code = a 17-org extortion spree; time-to-exploit collapsed 700 days → 44 • Defense in an exfil-first world — egress/DLP, segmentation, phishing-resistant MFA + OAuth governance, immutable backups • Security+ IR framing — a confirmed data theft is a reportable breach, encrypted or not Sources: Coveware Q4 2025 · Chainalysis 2026 · Sophos · Verizon DBIR 2025 · Symantec · Anthropic (Claude Code extortion case). — Andrés Sarmiento #ransomware #cybersecurity #infosec #SecurityPlus #incidentresponse #TechUpdates
Wi-Fi 7 Explained — MLO, 6 GHz & the AI-Ready Branch Hype Check (2026)
Wi-Fi 7 promises 46 gigabits per second. Your access point is plugged into a 1-gig switch port. Guess which number wins. The radio is real and genuinely good — the rest needs a closer look. Let's separate the upgrade from the hype. What you'll hear: • The big three — Multi-Link Operation (MLO), 320 MHz channels, 4K-QAM — and why MLO is the only truly new idea • The latency truth — 46 Gbps is a lab fantasy; real-world is 6–15 Gbps/AP (Cisco lab: +47%). The win is reliability, not raw speed • The 6 GHz reality — the US opened it in 2020 (not 2026), the EU only opened half, so full-width Wi-Fi 7 is a US/UK/Korea story • Adoption — ~37% of enterprise APs shipped in Q1 2026, and Wi-Fi 8 is already teased for ~2028 • The "AI-ready branch" — a great dashboard with an approval button, not a self-driving network • What Wi-Fi 7 does NOT fix — backhaul, cabling cost, client density, device fleet • Network+ N10-009 — bands, channels, and the generation map Sources: Wi-Fi Alliance · Cisco (MLO lab) · Dell'Oro Group · FCC 6 GHz orders · CompTIA Network+ N10-009. — Andrés Sarmiento #WiFi7 #networking #NetworkPlus #MLO #6GHz #TechUpdates
Securing AI Agents — MCP, Agentjacking & the New Attack Surface (2026)
In June 2026, researchers took over AI coding agents — Claude Code, Cursor, Codex — with no phishing, no malware, and a public credential developers paste into their own apps. It worked 85% of the time. The vendor's response? "Technically not defensible. We're not fixing it." Welcome to the new attack surface nobody secured. What you'll hear: • What MCP (Model Context Protocol) is — "USB-C for AI" — and why it became an unreviewed internet-facing doorway • The hygiene problem — Knostic verified exposed MCP servers; 100% had no authentication; 8,000+ reported by early 2026 • Agentjacking — how a public Sentry DSN let attackers poison the logs an agent reads (85% success, 2,300+ orgs) • The pattern — prompt injection (OWASP's #1 AI risk), indirect injection, and last year's Black Hat zero-click CRM exfiltration • The readiness gap — 83% of orgs deploying agentic AI, only 29% ready to secure it • Four moves to secure agents — least privilege, sandboxing + human-in-the-loop, MCP gateways, agent creds as non-human identities Sources: Tenet Security (Agentjacking) · Knostic · Cisco State of AI Security 2026 · OWASP Top 10 for LLMs · Zenity Labs (Black Hat 2025). — Andrés Sarmiento #AIsecurity #MCP #agentjacking #promptinjection #cybersecurity #TechUpdates
Passkeys Explained — How They Kill Phishing, Vishing & Password Theft
Every breach in our last episode died the same way it started — with a password. So this week: the fix that's finally winning. On World Passkey Day this May, the FIDO Alliance counted 5 billion passkeys in use. The password isn't dead yet — but we finally have the thing that kills it. What you'll hear: • How a passkey works — public/private keypair, private key never leaves your device, origin-bound signatures • Why passkeys defeat the 2026 attack playbook — phishing, credential stuffing, MFA fatigue, and the help-desk reset scam (CISA advisory AA23-320A names FIDO as the fix) • The numbers — 98% vs 32% sign-in success, ~1M passkeys/day, Gartner's 2027 call • Synced vs device-bound passkeys — and why device-bound = NIST AAL3 • The honest half — account recovery, device loss, and the real 2026 frontier • Network+/Security+ relevance — phishing-resistant MFA, by the book Sources: FIDO Alliance (World Passkey Day 2026) · Microsoft Security · CISA/FBI advisory AA23-320A · NIST SP 800-63B. — Andrés Sarmiento #passkeys #cybersecurity #passwordless #FIDO2 #SecurityPlus #TechUpdates
The Worst Breaches of 2026 (So Far) — And the 5 Mistakes Behind Them
Six months into 2026 and the breach scoreboard is brutal: 22 million Aflac records, 30 million students locked out during finals, the FBI's own surveillance system breached, four banks knocked offline in an afternoon. But almost none of it was clever. No genius zero-days. Just a phone call, a stolen token, and an open door. This is the 2026 Breach Hall of Shame — we name names, correct the hype, and show you the five failures connecting all of it. What you'll hear: • The vishing wave — Aflac, Carnival, Canvas, Charter — how Scattered Spider & ShinyHunters just called the help desk • Two corrections: OnlyFans was NOT breached (recycled old data), and Charter was ~4.9M, not the 40M claimed • The nation-state lane — Salt Typhoon in the FBI's network, Russia-linked sabotage in Europe, Volt Typhoon pre-positioned in US utilities • The supply-chain wave — poisoned dev tools stealing API keys, OAuth grants, and CI/CD secrets • The common thread: social engineering, missing MFA, non-human identities, exposed services, flat networks • A 4-move Monday playbook to defend the new perimeter Sources: TechCrunch "worst hacks of 2026 so far" (June 7) · CISA/NSA/FBI assessments · public breach disclosures. Nation-state attributions are linked/suspected, not court-proven. — Andrés Sarmiento #cybersecurity #databreach #infosec #SecurityPlus #identitysecurity #TechUpdates
Post-Quantum Cryptography Explained — Harvest Now, Decrypt Later (2026)
Right now, somewhere, an adversary is copying your encrypted VPN traffic. They can't read it today. They're saving it — for the day a quantum computer can crack it open. It's called "harvest now, decrypt later," and in 2026 it stopped being a thought experiment. This episode breaks down the post-quantum migration for people who actually run networks. What you'll hear: • The three NIST post-quantum standards (ML-KEM for key exchange, ML-DSA + SLH-DSA for signatures), finalized August 2024 • What "harvest now, decrypt later" means and why 5+ year data is already exposed • The expert-odds jump — 34% to 49% in one year — that a code-breaking quantum computer arrives within a decade • Cisco's real ship dates: Quantum Ready Assessments (July), IOS XE PQC for SD-WAN (August), default quantum-safe secure boot, majority of portfolio by December • Where it maps to Network+: IPsec VPNs, TLS handshakes, PKI, certificates, SD-WAN • Hype vs. the honest take — why migrating is worth it even if "Q-Day" never comes • A 4-step Monday playbook Sources: NIST FIPS 203/204/205 · Global Risk Institute Quantum Threat Timeline Report 2025 · Google quantum research (March 2026) · Cisco Live 2026 · NSA CNSA 2.0 / White House NSM-10 / EU PQC roadmap. — Andrés Sarmiento #postquantum #cryptography #cybersecurity #networking #NetworkPlus #TechUpdates
Cisco Live 2026 Explained — Cloud Control, AgenticOps, Post-Mythos Security
450%. That's how much more network traffic an AI agent generates than a human doing the same task. Cisco measured it, put it on the big screen at Cisco Live 2026, and then rebuilt its entire company around it. Last week in Las Vegas, Cisco made its biggest platform bet in two decades: every product — Catalyst, Meraki, Nexus, security, collaboration, Splunk — managed from one place, Cisco Cloud Control. This episode tears down what's real, what's vapor, and what it means for your network. What you'll hear: • Cloud Control — what it actually unifies, the AI runbooks, autonomous remediation, and the Codex natural-language agent builder • Cisco IQ, the sleeper hit — 2,036 customers onboarded vs. 800 expected, 88% support-case routing, the end of the 35-minute data-collection phase • The math: 450% more traffic per agent · AI traffic tripling in 3 years · tokenomics ($200/week per AI employee → $400M/year at 40,000) • Post-Mythos security — Live Protect rebootless mitigation, Nexus 9K smart switches with L4 firewalls in the data plane, the agentic SOC discarding 92% of alerts • Vendor English, translated — AgenticOps, "trillions of agents," and which claims are shipping vs. decorative • The Monday playbook — four things to actually do this week The products are real. The math is scary. The dashboard promise? Ask us again at Cisco Live 2027. Sources: Cisco Live 2026 keynotes (Robbins, Patel, Centoni — Las Vegas, June 2026) · Cisco Newsroom keynote TL;DR · SiliconANGLE five takeaways · Computer Weekly post-Mythos analysis · Anthropic Claude Mythos / Project Glasswing disclosures (April 2026). — Andrés Sarmiento #CiscoLive #networking #AgenticOps #CloudControl #cybersecurity #TechUpdates
Special · S04: The OT/ICS Defender — Why Volt Typhoon Should Worry You
$140K. When you mess up, the lights go out for real. Final episode of TechUpdates Special Series. The most consequential security job almost nobody talks about — defending the systems that keep the country running. Power grids. Water utilities. Petrochemical plants. Pipelines. What you'll hear: • What OT/ICS defenders actually do — segmentation, SCADA patching, PLC defense, plant-engineer coordination • Comp reality — why OT pays 40–60% less than cloud security at the same companies, and the "purpose tax" • The real stakes: Ukraine 2015 grid attack · Triton 2017 (Saudi Arabia) · Oldsmar 2021 · Aliquippa 2023 · Volt Typhoon pre-positioning across U.S. critical infrastructure • A real day — substations at 6 AM, vendors that still ship Windows 7 SCADA, plant managers explaining why your last predecessor retired in 2015 • The two paths in — plant engineer to security, or IT security to OT — and why CISSP doesn't help but GICSP does • LinkedIn's "critical infrastructure defender" vs. the actual day (30% travel to plants, 20% talking plant engineers into caring) When you mess up here, there's a body count. When you do it right, nobody notices the lights stayed on. That's the whole job description. And it matters more every year as adversaries pre-position inside the operational networks of utilities they intend to disrupt on a date of their choosing. Sources: CISA joint advisory on Volt Typhoon (early 2024) · Ukrainian power grid attack (Dec 2015) · Triton/TRISIS analysis (Saudi Arabia, 2017) · Oldsmar water treatment incident (Florida, 2021) · Aliquippa Municipal Water Authority compromise (Pennsylvania, 2023, attributed to CyberAv3ngers). That wraps the Special Series. Pick the role that fits you. The field is wide. — Andrés Sarmiento #OTSecurity #ICSSecurity #CriticalInfrastructure #VoltTyphoon #cybersecurity #TechUpdates
Special · S03: The AI Security Engineer — The Job Nobody Knew Existed
$450K. The job didn't exist 24 months ago. Every Fortune 500 is hiring. Episode three of TechUpdates Special Series. AI bug bounties have crossed six figures for a single prompt injection. Frontier labs run model evaluation contests with prize pools in the hundreds of thousands. Two years ago the title "AI Security Engineer" was on zero org charts. Today it's on most of them. What you'll hear: • What an AI security engineer actually does — red-team LLMs, secure RAG pipelines, defend training data and weights, write guardrails • Compensation in price discovery — Fortune 500 $180–250K, big tech $350–500K, frontier labs $700K–$1M+ • The full attack surface: prompt injection, indirect prompt injection, embedding exfiltration, training data poisoning, weight theft, agentic misalignment • A real day — jailbreak harness, code review of an agent, adversarial eval, MCP review, post-mortem on the attack that almost worked • The two paths in — security to AI, or AI to security — and why path three doesn't exist yet • LinkedIn's "responsible AI leader" vs. the actual day (30% red-teaming models, 30% shipping guardrails to production) This is the most leveraged role in security right now. The hype is loud. The opportunity is real. Don't let one stop you from seeing the other. Sources: public AI bug bounty programs at Anthropic / OpenAI / Google · OWASP Top 10 for LLM Applications · industry comp data at frontier labs. Next in the series: The OT/ICS Defender. — Andrés Sarmiento #AISecurity #LLMSecurity #PromptInjection #infosec #cybersecurity #TechUpdates
1 di 4