Épisodes

  • Protecting Vibe Coded Apps and the Shift to "Soft Guardrails" with Igor Andriushchenko
    Feb 24 2026

    Igor Andriushchenko joins Crying Out Cloud to explain how vibe coding changes the role of security engineers. The shift from typing lines of code to shaping entire systems means security teams need new strategies. Developers expect their shipping velocity to increase tenfold with AI assistance. Relying on traditional hard deployment blocks will only cause friction. If you want to understand how to build secure guardrails for AI development without destroying developer momentum, this conversation covers the exact mechanics.

    What's Inside:

    • The evolution of the Stockholm tech scene and human ambition driven by AI.

    • How Lovable empowers non-developers to build disposable and deeply specific software.

    • The concept of "soft guardrails" and why hard blocks fail in AI-assisted workflows.

    • Future capabilities of AI pen testing using hundreds of autonomous agents.

    • The shared responsibility model when business users build internal applications.

    Afficher plus Afficher moins
    39 min
  • Neuroscience, AI Research & Hiring Swifties with Alon Schindel
    Feb 12 2026

    Agentic AI is coming. Are defenders ready?

    Alon Schindel, Director of Data & Threat Research at Wiz, joins Eden and Amitai for the Season 3 Finale. This isn't just a recap. It is a look at how top-tier research teams operate at speed. Alon explains why Wiz treats research as a "product" rather than a support function. He details the "DeepLeak" discovery where his team found thousands of exposed API keys mere hours after a platform's popularity spiked.

    What's Inside:

    • Agentic AI: Why 2026 will be the year AI starts taking action, not just chatting.

    • Speed as a Weapon: How to shorten the time between a zero-day and a detection.

    • Culture: The power of the "Table" and collaborative chaos.

    • Retrospective: Lessons from IngressNightmare and the year in vulnerabilities.

    Resources:

    • Read the DeepLeak Research: https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak

    • Wiz Threat Research Hub: https://www.wiz.io/research

    Afficher plus Afficher moins
    24 min
  • Hacking Moltbook with Gal Nagli
    Feb 3 2026

    🚨 Vibe coding meets critical data exposure: The Moltbook Hack.


    On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Wiz researcher Gal Nagli to unpack how he compromised the "Facebook for AI Agents" in under an hour ↓


    1. How a simple boolean manipulation (valid: false to true) bypassed authentication

    2. Cloud Database misconfigurations and the failure of Row Level Security (RLS)

    3. How Claude Code was used to identify and exploit the vulnerability

    4. The security reality of "Vibe Coding" and zero-manual-code applications

    Afficher plus Afficher moins
    13 min
  • CodeBreach: Hijacking the AWS Console with Yuval Avrahami
    Jan 15 2026

    🚨 Everything you need to know about CodeBreach with Yuval Avrahami


    On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Wiz researcher Yuval Avrahami to unpack a major supply-chain flaw that put cloud environments at risk ↓


    Misconfigured CodeBuild instances used by AWS themselves

    One small regex mistake, huge consequences

    How an SDK used by the AWS Console could have been hijacked (!)

    The CI/CD controls that can mitigate this risk

    Afficher plus Afficher moins
    17 min
  • React2Shell, Shai-Hulud 2.0, Gogs Zero-Day & Tika RCE
    Jan 1 2026

    🎙️ Shai-Hulud, Shai-Hulud 2.0, are you keeping up?

    In this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen go deep into real-world cloud security incidents ↓

    1. How Shai-Hulud evolved into Shai-Hulud 2.0

    2. A vulnerability affecting Apache Tika

    3. React2Shell and its implications

    4. Gogs zero-day explained

    You DONT want to miss this!
    This is a technical, concrete conversation focused on how attacks actually happen, how they evolve, and what defenders need to understand to keep up.

    Afficher plus Afficher moins
    20 min
  • Live Talk: Security Minds from Google Cloud, AWS & Wiz
    Dec 8 2025

    🎙️ AI is changing the rules of cyber, are you keeping up?Eden Naftali goes live with leading voices in cloud security:Ryan Nolette (AWS), @John Miller (Google Cloud), and Alon Schindel (Wiz). This episode is essential listening for anyone defending at cloud scale. 👇🔍 Inside ↓1) How AI is supercharging attacker tactics — from hyper-variable phishing to rapid exploit generation2) The rise of "AI slop" and why it's burning analysts' time3) Emerging AI bug-hunters — what they can (and can't) do

    Afficher plus Afficher moins
    22 min
  • Cloud Detection Engineering, AI in the SOC and Parallel Parking with Alex Hurtado
    Nov 14 2025

    Detection engineering just got real!
    Eden Naftali and Amitai sit down with detection engineering powerhouse Alex Hurtado - and it's a must-listen for anyone in cloud security. 👇

    🔍 What's inside:

    1. The evolution of detection engineering in the cloud — and why traditional rules no longer apply

    2. Why DIY detections > vendor defaults

    3. How AI is reshaping detection and threat hunting (and why the human in the loop still wins)

    Afficher plus Afficher moins
    26 min
  • VSCode Extension Secrets, RediShell, & Living-off-the-LLM
    Nov 7 2025

    🔍 From discovering VS Code supply chain risks → to uncovering Redis Shell vulnerabilities.

    Eden Naftali and Amitai sat down to unpack: 👇

    • How VS Code extensions became a critical supply chain risk (w/ Rami McCarthy)

    • What RediShell reveals about attacker innovation

    • Where AI is being weaponized in modern malware

    🎙️ Listen now to our NEW Crying Out Cloud episode

    Afficher plus Afficher moins
    30 min