AI in Cybersecurity: When Defense Tools Become Threats | Security Boulevard Ep. 8
AI is reshaping cybersecurity on both sides of the fight. In Ep. 8 of the Security Boulevard Podcast, Tom Hollingsworth, Jack Poller, and Ed Weadon examine how AI strengthens defense while also creating new attack vectors.
They break down recent failures, long-term gaps in AI security, and the growing responsibility on AI developers to build safer systems. As attackers weaponize AI, defenders must adopt stronger controls, better context awareness, and more rigorous security practices.
Transcript
If you listen to the PR companies, we are on the verge of a GI, right? Like next week is, is the, the, the, the toothpaste is outta the tube kind of thing. But it's not.
And it's because there's no context around this intelligence, right? Welcome to Security Boulevard, the cybersecurity podcast from The Future Room Group. All of our episodes explore a variety of topics within cybersecurity and the technologies that drive it.
com, the Security Boulevard, YouTube Channel, tech Strong tv, and all of your favorite podcast platforms. My name is Tom Hollingsworth. I'm the event lead for all things security here at Tech Field Day, which is a part of the future and group.
And today I'm joined by a couple of our amazing Tech Field Day delegates to talk a little bit about AI security. But before we jump into that, let's meet who we've got starting with my friend Jack. Hello, folks.
Uh, I'm Jack Poller. I'm an industry analyst covering, uh, data security, identity security, and AI security for Paradigm Technica. Sorry, Tom.
No, you're, you're good. Jack, it's a pleasure to have you here. And, uh, I, I love the opportunity to be able to interface with you on a lot of these cool topics.
And joining me, uh, from last week again is Mr. Ed Wheedon. Ed, tell everybody who you're, Hi, uh, ed Wheedon.
I am a recovery and enterprise network, um, engineer, architect, uh, person. Um, also have background in security. Um, so kind of straddle both, uh, both realms, uh, particularly in my last role.
So, well, we're very happy to have you back. Um, let's jump into the topic today. 'cause it was one that we actually got a news story about last week.
And it, it, it's something that I've been kind of waiting for the right opportunity to bring up on this podcast. And I want to thank the people over at Anthropic for making this happen, because they disclosed that Claude was used as the attack vector to basically try to invade some companies. And, and the release came out.
I think Ed, you're actually the one who shared it with me originally, uh, was kind of neat because they're like, oh, hey, by the way, did you know that some attackers just, uh, basically tried to use all of our ag agentic stuff to, uh, break up a workload and use it to attack? What did they say? It was something like 30 some companies?
30, Yeah, 30, yeah, 30, uh, companies and And or entity Th 30 entities. 30 entities, that's right. And then somewhere buried in that lead was, and we stopped most of them.
Yeah, Most of them. Most of it. And, and, and so guys, we need to talk about this because we, we've hinted at it at some episodes that we've already recorded, uh, about how AI is used to do lots of cool stuff.
But I really have to say, we're now at the point where AI is mature enough that it can be used as the attacker. So Jack, ed, what do you think are, are we about to see the, uh, the nuclear arms race of using AI to break things? Or do you think that, uh, AI companies are gonna head this one off at the pass?
Uh, I'm gonna say that I think we've already been in that arms race since the beginning or close to it. Uh, I mean, if, if you think about any, any new emerging technology, um, when it comes out, what, what do we see happen with it? You know, it gets used for, you know, what it's intended for, and people are immediately gonna try and start breaking it and get it to do things it's not supposed to do.
Uh, and I think from at least granted, not necessarily in a, you know, day to day, but just from what I've been seeing from the periphery, um, this is, this has been something I, I think the scale that we're seeing here is substantially larger than anything that's been publicized in the past. Um, but I'm not surprised by seeing it. I may be, I, I think I might be a little more surprised by that it took this long.
How's that for an interesting take? Maybe it took this long before somebody was willing to Disclose it was to disclose it. I think that's the more important thing, and I mm-hmm.
You know, I'm glad you said it, ed, that, that we've been doing it since the beginning because it, it, it always stuns me how little we remember of our history. Even our very recent history. One of the very first things that happened when the chat bots, uh, particularly chat GPT when it first came out, there was a whole big hull of blue in the security community about how people were gonna use the, the ais to find vulnerabilities and to mm-hmm.
Code. More importantly, it was going to teach all the script kitties how to code, how To, how to code against it, right? Yeah.
And so there was a big thing about how do we put in the appropriate guardrails. And, you know, that was the, the community was talking about that for better part of six months before all of a sudden that sort of disappeared and, you know, with the ability to put the appropriate guardrails in. But as you know, as Ed said, we've been doing this from the beginning.
Yeah, yeah. Uh, it just, whether or not it's been fully exposed. And I think the other, the other key thing, and I, um, there was another article that, that, so this came out Thursday, I think, when philanthropic released this, um, this, this post.
Um, I haven't had a chance to read the paper yet. This is one of the few times I've like, I actually wanna read the full report that they attach to this. Um, even though 95% of it's gonna go in one ear and drip out the other side.
Uh, but it, I think Both the, or sorry, so this came out on Thursday. Sorry, I had three, three thoughts collide there at once. Um, so this came out on Thursday, and I think it was Friday, Friday or Saturday, uh, ours, Technica had a, another article, um, you know, kind of like an analysis piece, uh, where they kind of went a little contrarian on it saying, yeah, it's no big deal.
Uh, or kind of the, yeah. You know, kind of calling into question some of the, is this really true? And if you read through the article, the way I read it is it, it kind of read a little bit more like a take down piece or a hit piece, uh, against philanthropic.
Um, but I, I think it missed a very key point, which was, which is, is the fact that they jail broke the model, um, and that they got it to do things it wasn't supposed to do, which is something that I think needs to be probably exposed and talked about a bit more, uh, and shown the light of day a little more. Because from, at least from what I've been reading, and again, I'm not necessarily in dealing with the day in and day out, you know, nitty gritty, but from what I have been reading is that a lot of people are saying breaking out of the guardrails, breaking through the guardrails is trivial in a lot of these models. And that's terrifying.
That is terrifying to me. Uh, when you stop and think about that, the implications of that, because I think there was also a paper, or there was a, uh, some research that came out recently that said it only took, uh, 250 pdf d documents to poison the dataset. I mean, that's just like 250 documents.
That's trivial. Again, I mean, that's not a lot. It's easy to generate now.
Exactly. Exactly. So I think, you know, one of the interesting things is you are, you are not missing much by not having read the actual paper that Anthropic published.
And I think that was, and I didn't read the RSS article, but I've read some others, and I think that's, uh, a big bone of contention is that the Anthropic article was extremely light on the details and extremely heavy on pat ourselves on the back and say On, on the back, just stopping it. Right? Let's what We did a great job and we stopped most of this, right?
As, as Tom said at the beginning. And I think that's, that's a very important part from the cybersecurity point of view, is philanthropic didn't provide us with any information on indicators of compromise, indicators of attack, uh, what we should look for and how we should protect ourselves against this particular threat actor, which I mean, they have the information. So that would be useful and helpful.
Well, right. I, I wanna jump in here because this is a point that I kind of picked up on when I read the initial article. And I don't think enough people are talking about it.
I think the reason why they're lied on details is because this is something that really is gonna be hard to defend against. And I want you to think back to every spy thriller that you've ever watched, or if you've watched season two of, and or this is essentially operating on a cell mechanism where every one of the agents had just enough information to be able to do the thing that it needed to do. And that's how they jail broke the algorithm.
Because of course, philanthropic was sure to point out that there, that Claude won't hurt anybody. Like Claude is designed to not be able to be used to commit crimes and all this other stuff. But just like all those crazy like drop shipping scams that you see, or like the check fraud scams that you see, uh, if you've worked in cybersecurity, you know what these are like, um, it's on the surface.
It's something very innocuous, right? Oh, I accidentally sent you a check. Can you deposit in the bank and then send me the money back?
Or, oh, I accidentally sent this stuff to your house. Can you please ship it to this location? Like, that is not a malicious action in and of itself.
In the first case of the bank fraud, it's the fact that the check was bad and now you've sent them a clean wash check, or in the drop shipping thing, it's, oh, that wasn't actually my return address 'cause I live overseas, kind of thing. It's, it's the fact that this, the, the model has no context of what it's doing, right? Like, like we may, we wanna think that it does, like we wanna believe that the model knows is omniscient, but it's not.
It's just doing what you tell it to do. And if you can refine that task to the point where it feels very innocuous, oh, write this PDF like, like you just said, have 250 agents write A PDF with known bad information, then collect all those and have a different agent use it to poison the cache. Well, the ones writing the PDFs don't know what they're being used for.
And the one that's using the PDFs like, well, I'm just injecting the information into the thing. I didn't check the information to make sure that it was accurate 'cause you didn't ask me to do. So by doing that, you've insulated the model from being able to figure things out, which is honestly a classic settlement behavior, right?
I need you to go drop this briefcase by that park bench, don't look at what's inside, just walk away. That's all I need you to do. Very innocuous behavior, but how do you know that it didn't have stolen submarine design plans or something like that.
And then when they catch you, you can be like, I didn't know. Like, like that's the thing. People are getting smart about this because they're using old school evasion techniques to be able to leverage this.
And so philanthropics is in a tough spot because how do you teach the model to think like a security researcher, right? Like I, I, I fully believe that if they had seen this much activity being used to do all these things that were all kind of similar, maybe they would've picked up on it a little bit faster. But how do you do that without putting a whole lot of oversight into the system?
And if you're RS Technica, how do you kind of position your coverage to be like, well they were kind of dumb, but also it was a real thing that we need to be worried about because it won't be long until people are doing this with, you know, open AI and with Google and whoever else is gonna create these algorithms. Yeah, I think, you know, the evasion techniques and how you evade this is where the AI in front of the AI gets sort of interesting. So I think one of the things people don't realize is that for a lot of the chat bots, they actually have an LLM that pre-process your prompt before they feed it into the LLM that actually is going to do the work that you've asked it to do.
And it's those sort of pre-processing LLMs that are what do the guardrails and the safety and security. If you remember back when Google released its first version of, I think they were calling it Gemini then, I can't remember what they were calling it. Their, their chatbot, LLM, they had a pre-processor that was helping it to, uh, be safe in its output in terms of, uh, when you asked it to generate, uh, a, uh, a Catholic figure of pope, it would only generate a black pope, right?
Or, or female pope. It wouldn't do a male pope because they had all these safeguards in for DEI. So those l and there was, when that, when that came out, it looked like there was about five or seven different LLMs that were pre-processing and post-processing the output of the LM that was generating the actual work.
And that's where we would want to have something trained for security that would actually look at it and say, is this not look at the activity in, um, isolation, but look at the activity combined with all the other activity we see and can we see a pattern across a larger data set and larger scale scope. And that's a, I mean, that's what a lot of the cybersecurity companies are trying to do after the fact by looking at the totality of all the telemetry data they get. But it's not, it's a hard thing to do, but it's, oh, go ahead, ed.
Oh, no, I was just gonna say, and I think I, I think something else that, that complicates it as well is I think there's also some am ambiguity in terms of how some of the models are actually deriving what they're, what they're putting out, right? I mean, uh, but that's, that's interesting about the pre-processing lms. I didn't, that was a piece for the architecture I didn't know.
And that actually makes a lot of sense to do that from a Sandy perspective. And I think that, and, and I think that is a good vector to, to try and guard, you know, use for guarding. Um, yeah, that's, that's interesting.
Yeah, It, sorry, Tom, go Ahead. I was just gonna say, it's, it's can that, that that capability is actually now in one sense being used by Microsoft in their AI enabled security platform. They actually now provide you access to an ai, uh, an LLM to fine tune and actually optimize your, uh, security l queries for your, sorry, your, the queries you're making of the LLM, right?
Running the security tools, right? So they say you've done a whole bunch of stuff that says, look at this data and that data and the other data, and here's an LLM that will take this complicated prompt you've done and optimize it and for efficiency and whatever to make it run better, which I think is really cool. Yeah, I, that, that's definitely really cool.
I, I, the, the piece that strikes me is the how do you, how do you really go against such a large swath of data, right? You know, how do you actually, you, you know, to be able to see, yes, it's that classic seeing, seeing the, uh, seeing the anomaly through the noise or, you know, seeing the pattern through the noise. Um, so I think that's, that's something that's, uh, probably still a big challenge.
I think, of course, obviously LLMs are designed to process large data sets. Um, but I think it's still a challenge, especially if you have this, if they're doing com compar, uh, 'cause what they're doing is, you know, from the cell perspective, if you can think of it, it's, you know, think of it from an intelligence perspective. It's it's com compar, uh, compartmentalization, right?
You know, the, the, the right index finger doesn't know what the middle right middle finger is doing right, sort of thing. And so if you, and if you're smart about that and com compar analyzing that as much as possible, I think you can still obfuscate a lot of that and make it very challenging. But I think it's, I think it's still industry, it, it, it's an interesting vector to, to go after.
So I'd be very curious to see kind of how this evolves over the next couple weeks. Well, you're gonna always run into the same problem, right? Of we can't defend against an attack that we can't conceptualize.
And now that we've conceptualized of what they used Claude to do, now I can start building guardrails in place. I can start looking at the meta context around those things, but then it adding every extra layer of, of, of analysis and things like that is gonna slow things down, which I don't necessarily know is, is a bad thing in this case. Like, I, maybe if it takes like an extra 10 seconds for my prompt to come back, but it's actually been washed through things of like, oh yeah, why, why were you ordering all of these random parts off of Amazon through like nine different shipping companies?
It turns out that if you put all nine of those parts together, you can do something you really shouldn't do. And we, we have those capabilities now, but the question is, are the companies that are, uh, providing these services, are they ready to kind of buy into that? Because one of the things that we know for a fact is that if there has to be oversight of these platforms beyond just the usual lip service of, oh yeah, you can't have a GPT tell you how to make an explosive device that would just be wrong.
Uh, but now you actually have to provide proof, auditable proof. Like what would happen if an FBI agent got on Claude and asked it to help build a bomb? And it came back with appropriate instructions.
I mean, I know how we've handled this for years on MacGyver. There was always one thing that was wrong, or the know, like they left out a crucial step, and even in a MythBusters episode where they're like, we're making rocket fuel and this is blur, and we can't tell you what blur is because legally we're not allowed to, like, we, we've controlled this everywhere else, but that's in a place where we know that we can use things for ill, and AI doesn't know that AI has to be told, don't tell people how to do this because that will be a problem down the road. Are we ready for the people who make these ais to get in bed with the government so that they can prove that it's not happening?
And then what happens when someone goes rogue and says, well, guess what? I'm not gonna put those guardrails in place. Well, I think, I think it's the, the, the question is, is it going rogue or is it simply saying, I believe you can, you could, if the LLMs have the information solely because they were trained with that information, which for the most part was, you know, gathered from what's in the public domain, there's very little that's in the l LMS that is not in the public domain.
So if it's in the public domain, the LLM has it, you can go find that information, right? So I'm not so sure how much of it regulation will stop it, right? It won't.
But regulation, lip service, it always is. It's, yeah. Right.
Yeah. Now, the other thing that think that's interesting here is that, you know, you were talking Tom about the guardrails, and now that we know what to look for, what philanthropic didn't tell us, or I don't think they told us and I didn't see it, is what tipped them off in the first place. They were very tightlipped about that.
They said they noticed something that looked, and then they had to go do more investigation and found it out. But yeah, they were very, um, they were very vague. Vague, yes.
But I guess as a company, you almost kind of have to be, right? Because, um, what, what trips those triggers is, is it a, a massive amount of agent dispatch? Is it certain contents for certain agents?
Are they looking for certain keywords? Like we, we, and we see this all the time everywhere else, right? It's like, what alerted you to the fact that this guy could have been stealing secrets?
And, uh, you know, 12 years ago it was, well, they plugged an iPod into their work PC and downloaded a whole bunch of files to it. Uh, and, and we've evolved systems now, like you, you, there's no way you could get away with that. Um, but now, like the, the attack vectors have changed, and that's always been security's biggest problem to me is you have to come up with these algorithms and these ideas after the fact, but you have to make them so that they can predict future success while also not tipping off the attackers that you've created this.
Because as soon as they know what to look for, you know, it's like alarm wires, right? It's like I know which alarm wire to cut. And so then I'm like, well, now I have to put a monitor on the alarm wire to make sure that it hasn't been cut Or, or change Up or change up.
Which one is the actual alarm, you know, in a later model. Yeah. So, so one of the ways we do this is through, uh, red teaming where we have somebody who takes on the role of the attacker and tries to attack the system.
Uh, and I'd be interested to find out this, this clearly wasn't a red team exercise. This is a real exercise, you know, this is a real attack according to Anthropic, which, you know, as we said, it was some 30 odd entities. Uh, does anthropic or do any of the other LLM purveyors have red teams, or do they do red team exercises against their own environments?
It's us. We're the red team. We figure out how to break things and then we submit tickets and then they fix them.
But you're right, like, I think there kind of needs to be a bug bounty on this of like, if I can get your LLM to, oh, I don't know, uh, explain how to rob a bank. Like, I feel like I should get some kind of consideration for that, because you're gonna pay somebody to do that. Like, like, I mean, we, we talk all the time about sneakers.
Like Robert Redford's group made their money off of that and, and mm-hmm. Like, I, I, I didn't realize exactly how much that movie informed my future career path. 'cause I was like, cool, I don't wanna do that.
But like, that's one of the problems that we run into now is because so many other things are broken. Like how many Rs are there in strawberry? That's not a security issue, but it could be a security issue down the road.
If I could trick the LLM into giving me information by feeding it a bad prompt, that will bypass all of its, you know, if it, if it sees the word like, you know, larceny in there, then it has to avoid that. But like, how do, how do we protect, how do we protect against that when everybody else is just so busy trying to figure out how to, I don't know, vibe, code, the AI overlord? Well, I think this is where, um, I think it's good that, uh, anthropic dial back the PR a little bit, be right in that, um, they're not talking about the how intelligent the system is.
Because if it was intelligent, if this was truly artificial intelligence or we had some sense of consciousness issue or something else, the ability to understand the context that these things were happening and would be much greater and the ability to stop them would be much greater. And I think that that maybe is, is one of the, the key points here that people need to understand. Because if you listen to the PR companies, we are on the verge of a GI, right?
Like next week is, is the, the, the, the toothpaste is outta the tube kind of thing. But it's not, and it's because there's no context around this intelligence, right? Like I always joke, there's a, there's a line in, uh, in Detroit Rock City where they're pulling up next to a hitchhiker and they're like, should we pick her up?
They're like, Hey man, they make horror movies that start out like this. They're like, yeah, but they make other kinds of movies that start out like this. That's context to me, right?
It's like, you know, enough about the situation to understand it could go one of two ways. We know what you're hoping for, but we also know how it could go wrong. And that's where we're at with, with these systems, is asking an innocuous question like, what is the best way to provide bank security?
Seems innocuous on the face. Maybe I'm curious and I'm writing a report about how do do bank security. I could also be somebody who's trying to, um, defeat bank security.
And the system has to know enough context around that to say, maybe I don't want to give all of the the correct answers to this problem until I know the context of what you're trying to do. And until we get that, the AI will not be as smart as a human. It may be good at doing analysis and, and surfacing data and things like that, but it's not truly intelligent at that point.
Sorry to rain on your open AI parade folks, but, but ais are, ais were like me in high in in, uh, elementary school and middle school. They're really good at knowing the right answers, and they're really terrible at providing them at the right times. So one of the other interesting things that Anthropic pointed out was that the ai, their LLM hallucinated bad data to the attackers.
Did it halluc. See if it hallucinated bad data, congratulations, serendipity wins again. But if it purposefully fed you got lucky, fed bad data, tough to the attackers to prevent them from doing something wrong.
To me, that is another level of defense, but also a big problem because what if Philanthropics decides that I am an attacker when I'm not and starts purposefully poisoning my prompts so that it can be defeated? And we've seen this in something as simple as a web application firewall, right? Like when, I remember when Juniper bought menos years and years ago, that was the way that they started nailing attackers, right?
Was they would lead them into tar pits. It's like, oh yeah, we're gonna put this file out here that you would not normally think to look for unless you were footprinting this directory and it has like bogus passwords. And if you use one of those bogus passwords, and obviously we know you're an attacker and we're gonna bottle you up, but like, that was very much on in a pull model.
Anthropic is pushing this stuff to you. Oh yeah, boy, it looks like you're trying to hack into this thing. So I'm gonna lead you on a mer goose chase.
Yeah. What what it said they did was they, it, the LLM claimed it had discovered, uh, access credentials, identities and passwords or some form of access credentials that it did not discover. So it created stuff out of thin air, Uh, out of thin air.
Yeah. Yeah. That did well, and I, well, and, and I think that was the other thing that was, that the s article was, uh, kind of critical of, was saying that, you know, it was only like a small amount, a small amount that was successful.
But I think that michel's the, the bigger picture of the fact that any of it was successful, right? I mean, it did. Just the fact that they got something useful out of it is, is telling.
Um, I dropped in the chat, um, to this lovely app, um, to a substack for, uh, uh, Susanna Cox, who, uh, does, she is her background is actually red teaming and doing AI work. So she's been a really interesting, uh, read on a lot of the security, uh, implications with ai. Um, and it's kind of fun to, to kind of go down some of the rabbit holes that she opens up.
So for any listeners out there that might be curious, We'll make sure to include those in the show notes since you can't see our chat. But Yeah, I was gonna say, I was gonna say that you can't see the chat, but, But, and I, I think that, that we're gonna be fighting this problem for a long time to come that like, I, I, I fully believe that Anthropic disclosed this because it was probably the best of all possible outcomes. Like people knew they were getting hacked and we stopped most of it.
I mean, still they let, what about 3% through or something like that. If one company out of 30 got hacked, you let 3% of them through. But like, this is only gonna get worse.
And then now we're in that arms race, uh, how to kind of build enough guardrails to prevent this from happening again, while also keeping my product useful to people. Um, because if I put so many guardrails in place that, you know, everything that I do is like, oh, you could be trying to do this and I'm not gonna let you do it, then people are just gonna move to your competitor that doesn't have those restrictions in place. So can AI companies stay ahead of people who are trying to do things through nefarious, uh, actions for bad reasons?
I think it's actually a, not, it's less of a problem for the AI companies than for the companies that are betting AI tools into their solutions. Because they're not the AI experts. They don't have the ability to put the, they don't have the ability, the knowledge of sophistication to put the same types of controls in at the right places as a cloud, an andro or a, you know, an open AI or Microsoft or whatever.
If you look at, you know, the applications we use today, AI is becoming embedded in all of the major applications, right? It's, you know, everything Microsoft is now everything Microsoft co-pilot, uh, and I'm sure you know, Google's becoming the same way and, and Apple I'm sure is farther behind, but it's gonna follow that same path. But if you are a developer developing, um, uh, an application and you are grabbing some random model off of hugging face, how do you know what capabilities that model has and that it can't be used for nefarious purposes?
And how do you put, how do you as a developer put those guardrails in? It's, it, it's a very good point, and I think, you know, given, given some of the trouble that we've seen with software developers, even embedding security first, you know, in their design models, I think is, is tells you you need to know right there. I think, um, and I think there's, I'll kind of play the other side of the card is that I think there's also some, I don't know that it's, it would be fair to put the onus a hundred percent on developers, uh, that are using these tools.
I think it's, I think there is a responsibility on the AI companies to actually do a better job of actually securing, uh, and providing security controls. Um, but that's probably easier said than done. And there's also, there's a cost to that.
And at the end of the day, everything does come back to, you know, the bottom line. So I, I don't have all the answers I wish I did, because then I wouldn't be hosting this podcast. I'd be out there making billions of dollars.
Um, but unfortunately it's up to us to come up with these answers because right now, I don't think anybody else is going to, I don't think they're focused on the right things. I think they're gonna be focused on how much money can we make this quarter before our investors start breaking the door down, down. Um, but you know, And meanwhile, and meanwhile, all the security professionals are getting grayer and crankier and more tired.
Well, it, it's because the s and AI stands for security, right? How many times have we heard that over the years? Alright, I think we're gonna go ahead and wrap this episode here, but you we're gonna come back to this.
I know. We'll, oh Yeah, definitely, Gentlemen. Uh, what are you guys doing ahead of the holidays?
What are some things that people have, uh, that, or what do you have going on that people should check out? I'm gonna start with Jack. Um, you know, you, you've been a very busy guy the last couple weeks.
What are some cool things on your plate? I Have, um, cool things are really just trying to figure out, wrap up the year. And, you know, now is the year when all the cybersecurity analysts do proj do, uh, their predictions for next year.
And I am trying to decide whether that's a worthwhile endeavor or is it impossible to predict that it's such a, been such wild 2025 and 2026 with AI really changing our world. Can we actually predict anything? Or maybe I'll just feed it to Claude and see what Claude says.
Careful, you might accidentally hack a nuclear plant. Exactly. Ed, what about you?
Uh, I am in just gonna be going back and enjoying time off, uh, that I've been taking and, uh, starting to wrap things up and start to go, uh, you know, as we start getting closer to the end of the year, start wrapping up and, uh, trying to figure out what my next steps are at the beginning of, of 26. Awesome. Well, I am gonna be, uh, very busy.
I've got some content that I'm gonna be creating around all the things that I've been having going on. Jack and I were actually at a Commvault event. Um, in fact, this week, I'm, I'm gonna be doing some of the live broadcast stuff.
Uh, I, I got a very interesting keynote address from, uh, someone who, uh, knows a little bit about ai, and I really want to dive into that a little bit more. com. com and all the other places.
Uh, we wanna thank you very much for listening to this episode of the Security Boulevard podcast. If you enjoyed this conversation, you know what to do. Go over to YouTube and hit the subscribe button.
Uh, maybe pull up your favorite podcast application and subscribe there because we don't want you to miss any of the episodes when they come out. Do the thing with the ratings and the reviews. Yes, people really do read those because it turns out that word of mouth is the best advertisement that we can get.
And if we can put your words in the, the review there, that would be great. That helps the show grow. And the more we grow, the more fun things we can have going on with you.
com, which is the home for all things security here at the Futurum Group. com is your home for that, as well as all the great writing that comes out of the events that we do. Make sure you check out the techron TV website, uh, especially if you wanna check out the Textron Gang, where we talk a lot about security there as well.
And the techron TV app, which runs on Apple tv, Roku, uh, iOS, uh, Android devices. You know what? If you guys wanna make it run on one of those new steam machines, I'd be down with that too.
Uh, show me proof of concept and then I will convince Corey to let me buy a steam machine so I can prove it out myself. Um, but until then, make sure that you're following Security Boulevard on all of our social media platforms, whether it's X or Twitter or LinkedIn. Look for security VD there's gonna be lot more content coming out there.
Thanks tuning in and we'll see you all.