Security Weekly Podcast Network (Audio)

The smell of victory, Bongo Fury, Sysmon, Looker, Openclaw, Kimwolf, Josh Marpet - SWN #553

Feb 6, 2026
Josh Marpet, cybersecurity practitioner and commentator, weighs in on AI agent risks and enterprise defenses. Conversation covers built-in Sysmon in Windows, Looker vulnerabilities and unknown inventory dangers, and malicious OpenClaw skills in AI agents. They also debate convenience versus security and the need for default-deny controls.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ADVICE

Enable Sysmon Enterprise-Wide

  • Install and enable Sysmon to monitor process and file activity across endpoints.
  • Use centralized policies (e.g., Group Policy) to deploy and enable it enterprise-wide for consistent logging.
ADVICE

Act On End-Of-Support Edge Devices

  • Identify and decommission edge devices that are end-of-support to reduce exploitation risk.
  • Implement continuous discovery and inventory processes to track EOS devices within 24 months.
INSIGHT

Analytics Platforms Are High-Value Targets

  • Vulnerabilities in analytics platforms expose internal databases and can enable RCE even when developer permissions are required.
  • Hidden or forgotten deployments (old servers, closets) increase real-world risk beyond headline services.
Get the Snipd Podcast app to discover more snips from this episode
Get the app