
Sep 18, 2026 · 35 min
Cybersecurity’s old assumptions meet AI’s new risks
The Department of Know: Passkeys phished, Cisco hits root, nuclear red lines for AI
The episode connects exploited infrastructure, weak hiring controls, and immature AI governance to a broader need for resilience under uncertainty.
- 1Passkeys remain strong against credential theft, but social engineering can still bypass the people using them.
- 2A Cisco zero-day and airline cyber rules show why compliance cannot substitute for resilience when attacks disrupt essential systems.
- 3AI-assisted intelligence and incomplete catastrophe planning expose governance gaps that security leaders cannot solve with automation alone.
Don't miss
The panel examines a Cisco Secure Email Gateway zero-day that let unauthenticated attackers obtain root-level access, treating it as the new normal for edge-device exploitation.
The brief
Sarah Lane, Jason Thomas, and Jay Wilson open with a practical question: how should security leaders respond when authentication, hiring, and AI capabilities are all changing at once?
The panel defends passkeys as robust technology while stressing that social engineering remains a human vulnerability; they also question claims about fraudulent hires entering organizations undetected.
A Cisco Secure Email Gateway zero-day granting unauthenticated attackers root access becomes a warning about network-edge exposure, while airline cyber rules reveal the limits of compliance.
The discussion then turns to AI-assisted intelligence, delayed U.S. safety legislation, and criticism that AI companies’ catastrophic-hacking plans lack serious security expertise.
The closing advice is deliberately skeptical: security leaders should track frontier AI closely, distrust promises of complete coverage, and plan for vulnerabilities to be exploited.