CyberWire Daily

CVEs don’t sleep.

Jan 14, 2026
Ian Swanson, AI security leader at Palo Alto Networks and former CEO of Protect AI, discusses the critical need for AI supply chain security. He emphasizes that organizations must manage dependencies and blind spots in AI systems aggressively. Swanson also highlights the risks of many operational models that can be exploited and the importance of vigilant monitoring. He shares insights on vulnerabilities in machine learning, like malicious models and credential theft, underscoring why securing AI is now an urgent priority.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Low-Scoring Zero-Day Still Dangerous

  • Microsoft's Patch Tuesday fixed a zero-day in the Windows desktop window manager that's already exploited despite a low CVSS.
  • Chaining such flaws can undermine core protections, making rapid patching critical.
INSIGHT

China Sidelines Western Security Vendors

  • China instructed firms to stop using some U.S. and Israeli cybersecurity vendors amid national-security concerns.
  • Beijing aims to replace Western tools with domestic alternatives over data exfiltration fears.
INSIGHT

Models Are The Hidden Engine

  • Machine learning models are the AI 'engine' and can harbor hidden risks beyond data vulnerabilities.
  • Organizations often run tens of thousands of models in production without realizing the full scale.
Get the Snipd Podcast app to discover more snips from this episode
Get the app