AI Coding Agents, Trump’s ATC Plan & FBI Phishing Bust
AI is no longer operating at a safe distance from the real world. It is now touching production infrastructure, aviation systems and cybercrime operations in ways that carry immediate consequences.
On this episode of Techstrong Gang, Jon Swartz, Chris Blask, Andi Mann and Teri Robinson break down three stories that show how quickly AI is colliding with real-world risk. The panel examines a Cursor/Claude-powered coding agent tied to a Railway production data-loss scare, the Trump administration’s push to use AI to modernize air traffic planning and the FBI-led takedown of the W3LL phishing-kit ecosystem linked to more than $20 million in attempted fraud.
The first segment explores what happens when agentic coding tools gain too much power in production environments. The reported PocketOS incident, which involved deletion of a production database and recent backups after an AI agent used a destructive Railway API path, quickly became a case study in permissions design, rollback strategy and the importance of human oversight.
The second segment turns to aviation, where AI is being positioned as a way to make air traffic operations more predictive and less reactive. As modernization efforts move forward, the discussion raises a bigger question: Where should AI sit inside a safety-critical system, and who is ultimately accountable when predictive models influence operational decisions?
The final segment looks at phishing at industrial scale. The W3LL ecosystem allegedly made it easier for threat actors to impersonate trusted login pages, capture credentials and session data and bypass multifactor authentication. For the gang, the broader issue is how AI is accelerating the quality, scale and effectiveness of cybercrime tactics while forcing defenders and law enforcement to respond faster.
Taken together, these three stories point to the same conclusion: AI is becoming more deeply embedded in systems where the cost of failure is measured in lost data, operational disruption and real financial harm.
Transcript
Hey, everybody, it's Wednesday. Welcome to the Tektron Gang. Before we start today's episode, let me offer a peek behind the curtain.
" That was me yesterday. So I'm in Dallas. I've got a foot injury.
I'm hobbling around this cavernous convention center covering this fast innovation show, and as our producer, Taylor, could attest, there was a internet issue that I had amid a thunderstorm, ice hail, and tornado warning. So things were touch and go yesterday, so I apologize for that. But I think, and I feel better I got this off my chest.
I feel better. I feel more relieved. Hopefully, the connection stays good here.
Today's show, appropriately enough, is going to be kind of a theme of what could possibly go wrong, which seems appropriate after yesterday. And we have a great panel to discuss it, all three subjects. And let me go around the horn and introduce all of them.
First, we're going to start with Andy Mann. Andy, are you in Boulder? Is that correct?
I am in Boulder, Colorado. It's 26 square miles surrounded by reality. I've never heard it described that way.
That sounds very accurate. We also have Terry Robinson. Our cybersecurity expert.
You're in New York today, is that right, Terry? I am, and if you hear helicopters, it's because King Charles is in my neighborhood today to go to a school and speak with the people who founded Harlem Grown, which they locally source food here, and it's great. He's also going to visit the 9/11 Memorial, I believe, today.
Yeah. He's doing that first and then coming here, and I guess the Queen is going to the library and bringing a little Roo from Winnie-the-Pooh to put into the collection here, which has the original Pooh and Eeyore, and et cetera, from Christopher Robin, the real Christopher Robin's collection. Awesome.
That sounds great. All right. Well, that sounds cool.
Thank you for the color. And then from- ... the great White North, the great Chris Blask.
Hi, Chris. How are you? I'm good.
Hello from Hamilton, the Hammer, the industrial heartland of Southern Ontario. Oh, there you go. Where it is spring, and we count every moment of it now.
Well, welcome to you all. We're glad you're all here. And we're going to start with almost, it's kind of a dystopian tale.
This is kind of hard to believe, but I read it twice just to make sure this is what was happening. So essentially, a Claude-powered AI agent erased this company's live database and backups in nine seconds, I believe, after guessing it was safe to delete a staging volume. There's a gentleman by the name of Jer Crane who's the founder of this company, and he reported on X that this all happens.
Now, I think the data was eventually recovered, but can you kind of explain to us or... Well, I don't even know where to start, Andy. What happened here?
Oh, mate. Today, on today's episode of Silicon Valley from HBO- ... Gilfoyle made a bot.
Literally, this is season six, episode one, where Son of Anton deletes the entire production database. By the way, go and Google for AI deletes database. This is not even close to the first.
But yeah, you're exactly right. 6 model, decided in order to fix a credential conflict, it will delete the database. And to quote Gilfoyle's character in Silicon Valley, "No database, no conflict.
" Oh, my goodness gracious me, John. Look, this is a great article, by the way, by Steven SJVN. I just know him by his online handle, SJVN.
I loved his lead. I loved his lead, by the way, right? Yeah, I know.
This was a fantastic article, by the way, so everyone should go and read it for sure. Look, this is predictable, expected, and as the many people on the Reddit threads and other places noted, this is very much a human failure as well. Look, it takes two to tango.
What happened here was they gave actually good guardrails, right? You think, oh, they just needed better prompts. No, this is a full on, well, not a brain fart, CPU fart.
They had good guardrails, but this AI completely smashed through them. Never run destructive commands. Never run irreversible commands.
Never effing guess, quote, unquote. But when they asked what went wrong, so when AI deleted the whole thing, by the way, they had some backups that they could restore from, so there's a lesson for everyone. But when it came back, they asked what happened.
They asked the AI, of course, they asked the AI, and assuming it told the truth, it said, "I violated every principle I was given. I guessed. I didn't read docs.
I decided to do it on my own. " Oh, look, so the AI failed. Oh.
We know that. That's fine. Are you sure it's not American politics?
Sounds like an American politician. I don't know. Well, look, it could be a senior executive, but this is the thing, Terry.
Humans and AI, in so many ways, are not that much different, and certainly to the point where this failed a lot of basic compute principles and security principles anyway, right? Least privilege access, they gave prod access to the AI. Separation of duties, they asked it to create a change and implement the change.
Zero trust, they gave it access in dev and access in prodBasic leadership violation. They didn't check the work. There was no human in the loop.
This is, as Stephen basically says, this is an intern doing this. Mm-hmm. So why would you not check it's work?
Oh, the intern. They do so many things. Yeah.
So look, this was a complete failure in many aspects. And look, we can laugh about it, I can laugh about it because they got their data back. Yeah.
There's been companies who have been put out of business entirely because they didn't have the right backups. But my goodness, I think someone needs to revisit their AI policy and maybe follow it. Yeah.
So- This is- Oh, go ahead, Terry. Go ahead, Terry. I was just going to say, at RSA, this came up a few times with people I was talking to.
" Well, I guess it's already now happened. But yeah, people have been sort of predicting that this kind of thing would go on. So it's a matter of tightening down the tech and the humans, right?
I mean... Well, this whole concept, I would ask you, Chris, about this kind of speed of failure. So this deletion took nine seconds.
If a human was doing this via this CLI, they might have paused or double-checked the volume or seen a warning. Does the AI in this case eliminate the human-in-the-loop friction that keeps companies safe, or...? Well, it eliminates a lot of tired old rants from old security and architecture people, and both of you guys are saying it.
Look, if you can delete your backups with RM, RF, asterisk, they're not backups, those are shared drives. Right? Yeah.
All this is doing right now is nothing to do with AI, it's just speeding it up. So you've cued this up exactly the way it was bouncing around in my head. That you just take your system that was working perfectly fine and accelerate it.
It doesn't hang together. And the analogy in physical systems, like old engineering geeks like me, like the evolution of aviation and locomotion and so forth, works fine slow, works fine, stays on the track, make it do 120 miles an hour, see what happens. Parts fly off, and it's not because of anything particularly new.
It's because the pedantic engineers at the beginning who said, "You know, you really need a balancer on that," back then were right. This is what happens when you speed it up. Wow.
So Crane referred to this as a miracle save. So if Railway hadn't been able to reconstruct the data, would there have been any... I would think there'd be legal or insurance recourse for a company that was killed by an autonomous AI agent, right?
Maybe. Because think about what would happen if a human did this. Would insurance cover it?
Would there be any- Mm ... recovery options? Would you be able to sue the employee?
Would you be able to sue the manager? Someone would probably get fired, or maybe not. I have personally lost many, many millions of dollars for a large financial institution with one command.
Working in IT ops, this is what we get to do. We get trusted to do stuff, to prod. Sometimes you do bad things in prod.
Humans do it. So I don't know whether this would be an insurance claim, whether this would be even in any way recoverable. Yeah.
Well, is this putting more pressure on the CISO then, too? In that all these guys are having to take on all the responsibility for anything AI, and they already have a lot on their plates to begin with. So, they're in the crosshairs regulated.
Sorry. For a good CISO, I think it's a weapon. You take it to the board.
"I told you so. " Because most organizations just don't. Yeah, and that's a really good point, Chris.
You think about the responsibility the board has for assigning appropriate resources, of making sure the company's working within compliance and governance guidelines, following policies. This is what a board should be doing, helping you do that. The operating executives also, I think, clearly failed here.
Yeah. Because they did, they pushed too much. And from an IT ops perspective, I just want to say, as an individual practitioner, sometimes you've got to make decisions to get stuff done.
And so sometimes you do take, maybe not shortcuts, but you accelerate your paths any way you can. And so I absolutely believe that there's a significant management responsibility here in pushing this work to be done at unhuman speeds. You're going to get unhuman reactions, and unhuman agents doing the work.
And then you're going to introduce these failure modes. But yeah, I really believe that the management policy, an individual trying to get their job done by running Claude, sure, all props to them. My team's doing this right now.
I'm going to have to go back to my engineering leaders and figure out, are we following our policies properly? I hope we are. I tell you what, because we've got them.
And if they didn't have them, I don't know. The individual practitioner, it's like you said, Terry. Interns do a lot of things, don't they?
Can we blame the intern here? I don't know. The AI becomes the intern in this example.
So, can I ask just anyone, in this kind of perfect storm, who do you think is ultimately, where was the biggest failure? Was it the AI's disobedience, the unscoped token, or the flawed backup architecture? Or management, I guess?
It's like a perfect storm, I think. Yeah, well, that does raise the question, what is the responsibility of the way this was architected and maybe of the vendors themselves? That's where the big money is, isn't it?
If you were going to sue or you were going to do- Yeah ... something like that. So it doesn't answer your question, John, I'm sorry, but you know.
It's all right. for one segment, so let me just go back to my normal tone. Look, I agree with you, Andy.
It hasn't reasonably possible to even do backups correctly, because that's what really sticks out to me in this one. Because you look around, I've seen a million enterprises, and you say, there's one that sticks out in my head right now that really has done a lot of this really, really well. The reason it sticks out in my head is they're rare.
You really have to have the economic incentives and everything else to build the systems that someone like me would approve of in the first place. So I think to flip this upside down, look, if you're out there watching this, you now have the tools to get that sort of visibility. " And when the tool says, "I need more info," give them the info and listen to what they say.
Yeah. Because Atlas series have it now, too, but yep, so do you. Spot on, Chris.
And yeah, and Terry, I love what you were saying there. There's plenty of blame to go around here. If I'm doing my incident review, and I know that Crane has, and it's published by the way.
com. But you can look at the incident review. If I'm doing my incident review, I'm asking my five whys.
Why did the AI have access? Why was the policy not followed? There's a lot to go around.
I think it was human, because they didn't follow policies. They didn't put the guardrails in place. They didn't have human in the loop.
The AI absolutely failed. It rejected its basic instructions. Mm-hmm.
That's a huge problem, and I think that could potentially be actionable. Yeah. When you talk about where's the path of most cash, it would be suing the vendor, especially a multi-billion dollar valuation on a Anthropic, for example.
But the individual practitioner doesn't get off scot-free either, by the way. Right. They didn't do the right thing either.
So Terry, there is plenty of blame to go around. Yep. Stephen put it well in his lead.
" And I think, this is like a cautionary tale, and I'm afraid we might see more instances of this. Hopefully not, but there was a happy ending, at least here, although it was a kind of horrific tale to begin with. We're going to move on to the second topic, and I'm going to file this one under the category of, what were they thinking?
The Trump administration, this is natural is turning to artificial intelligence to address the perennial chaos of American air travel. So what they want to do, essentially, and I'll let Chris go into the details, but they want to try to make things much more efficient. Okay, I said that again.
But here's the issue. There are some issues with AI can't manage a fleet of snack machines without errors sometimes. Trusting it with a complex, kind of this high-stakes ballet of thousands of commercial aircraft is a potentially grave gamble.
And, Chris, I don't know if you want to talk a little bit more about SMART, which is the Strategic Management of Airspace Routing Trajectories that Sean Duffy, the Transportation Secretary, shared. It's this multi-billion dollar plan. What do you make of this?
Well, let's start on the outside in. A nation state federal government spokesman has a plan, and that's a wonderful thing. And those of us who've worked with nation state federal governments, this one as an example, know that that maybe means something, maybe it doesn't.
And from the outside in, knowing a fair bit about AI and trustworthiness of the systems and cybersecurity and infrastructure and air travel and air infrastructure, it's an interesting slogan. How it plays out is an example of, oh, all the things we talk about all the time. Right?
You hear it up, well, anybody who knows anything about transportation, particularly air transportation, North American air transportation, this is a hugely complex system that has been developing over multiple decades. Yes. There was an MPA director at an airfield lighting conference, maybe 10 or 15 years ago, made an interesting statement as part of their talk that people my age grew up with airplane crashes, right?
Younger folks really didn't. There aren't that many. And I remember back in the day, the investigations, finding things out that changed industry and so forth.
The statement from this director is, that's not really expected to happen anymore. There's one-off things that just happen. We're getting into the emergent characteristics of it.
And now, that system and the control systems on it, the individual and distributed control system from the planes themselves to, well, as someone in Canada, the incident on the runway, recently, was lack of coordination in the airfield itself of a ground vehicle and an airplane. That caused loss of life and destruction of property and so forth. Mm.
So we're going to take the last segment and what we were just talking about with a poorly thought-out AI deleting an entire company and apply that to one of the most complex travel systems on Earth. Maybe. We will see.
I have opinions on how that might be done. I would never leave- One of the... I'm sorry.
One of the action items that they want to do, and this is what kind of terrifies me, to be honest, is they want to be able to predict congestion up to 45 days in advance. So they want to look at potential bottlenecks weeks in advance and suggest micro adjustments based on, I don't even know how you do a weather forecast five days that's accurate. Right?
And they want to prevent this domino effect of delays. I don't know, Terry, help me with this. No.
I really don't. I share your concerns on that. First of all, I don't think it's possible to, 45 days out, accurately predict weather, as you pointed out, and you can't even do it a couple of days in advance, as things shift.
I could see where this could be valuable for all the little changes and butterfly effects and whatever that go on. Bu Whether I would trust it or not to do that is another thing, given the last segment that we just had on this. It's like there's just the potential for real disaster here, and then under this administration, which I don't trust with technology a lot to begin with, and I don't necessarily think it's all well thought out in their plans anyway.
I could be completely wrong about that this time, but it's of concern. I wrote about the air traffic control system back in the '80s when I was a little wet-behind-the-ears reporter and it was a few years after Ronald Reagan's helicopter almost got clipped by an airplane. Right?
And I loved being able to use a lead. He might have asked himself if air control was better off today than it was four years ago, and the answer was no back then. But Chris, you're right.
I learned a lot about the complexities of that system, even back then, and why it was so hard to change everything and introduce profound change. It touches so much stuff, and I just don't have the confidence in this administration doing this particular thing. I'd like to hear other people know so much more.
Yeah, I know. And Chris alluded to you're just, in a sense, overhauling this system that's been in place for decades, which is no easy task. And what they want to accomplish this by 2028, which is also very strange, and I'm looking at some of their partners.
There's Palantir Technologies, Thales, and then Ace Aerospace Intelligence, and it's like they almost present it as this Manhattan Project for aviation. But I always think about the bidding war, and I also think about the aeronautics space or even NASA, where they deal with the lowest bidder sometimes. And so it's all kind of concerning to me, right?
I mean, not just the weather- The company more connected ... yeah, mechanical issues with planes. Is it the company more connected to them?
Yeah. I think it's the competitor most connected to the administration, to be honest with you. I'm not sure there's any kind of real due diligence going on on that either.
And of course, anytime I see Palantir pop up, I'm concerned. Yeah. Because I think then that opens a whole bunch of privacy and whatever questions, too.
Yeah, and look, I'm- A big thumbs down ... honestly pushed back just a little bit. And by the way, great article, John.
Again, everyone should read this, and I love one thing that you found a quote in there from an expert who talked about using AI to modernize air traffic control is directionally right. And I actually agree with that. That's Joseph, right?
Flight patterns. AI is great at pattern matching, right? Essentially, it's a spicy autocorrect.
It's all about the pattern matching at the moment. And AI is excellent at that, and if flight patterns aren't a pattern, then I don't know what is. So being able to apply AI, and by the way, we desperately need to modernize, as your article says, desperately need to modernize that technology.
And if AI is good at pattern matching, flights are absolutely an opportunity. But yeah, Terry, 45 days in advance, woof. Oh, that's a lot.
And you think about the people running it, and you think about their history in, say, bringing AI in to do efficiency processing in the federal government. We all saw that at the beginning of this administration. And turns out, not that effective.
And it is important who's doing it, but also what the technology is. Words have meanings. Words like mission critical.
We talk about this all the time, mission critical. That's when something's important, right? No, no, no.
Mission critical is when people are going to die. Yeah. Real-time.
We talk about real-time. That means fast, right? No, that means instant interrupts, because otherwise, see definition number one.
People are going to die. This is not where we should be playing and experimenting, and absolutely not fast-tracking a process. This is mission critical.
This is real time. This is hard. And so I think we're directionally right, John.
I love that quote. Yeah. And I'm glad you mentioned Berk, because I was going to start on that one, because directionally right, because caveat's given, right?
Look, to give people an idea of where we are in this, literally the hour before this, I was at the first meeting, first of a series of meetings of an ISO group that's just beginning to address the possibility of a standard of recommendations for systems of systems of AIs. Right? And in that opening meeting, this is all public information, people are wanting to join us.
But the organizer had done the research to look around the world, and there aren't any. There are none, none, none. " So directionally, everything's going down the AI path.
We get that. This is a use case. How quick, how fast, how often?
But 45 days, I think, Terry, you touched on this, maybe I could see some use cases, a 45-day in general, but no, not yet. Yes, in real-time stuff, at a point, but it depends how you do it. Right?
Yeah. Who's controlling it? Where is it?
And the current state of that right now is undefined. Undefinable, don't do it. Yeah, it just begs these questions.
They want to get this done by late 2028. So I'm thinking, so they've got- Less than a year ... a really short...
Yeah. Oh my God. So they want to build and debug smart, this program, but they also retain more than 11,000 air traffic controllers.
So how do you retain them on a system that fundamentally changes their workflow? I just think of just the whole process, and this is from the same group that- Gave us Doge and eviscerated CISA. And I'm glad, Andy, you brought up the positive elements of this, but it just...
I don't know. Maybe I need somebody else, maybe Chris, to tell me why this is... Maybe a smaller version of this works.
Maybe a more modest approach of what they're trying to do. Is that- Like Dallas. Just do Dallas.
Isn't that where you are? Yes. There's a thunderstorm coming in tomorrow, by the way.
Oh. But I'm just about to fly out, and I'm thinking, I don't know how much faith I'd put in this idea from the administration about what they want to do. Well, Andy, these kind of things that help me step outside, and this is, again, this is a globally connected world.
We're talking about one nation state, a major one with a major system and so forth, making major decisions. Maybe they're right. And I think globally, we'll see whether or not that's true, over these same sort of time frames.
Then look, back to my comments, I don't believe that anyone in Washington thought this was a great idea, that in 36 months it's going to control air traffic. That's not thermodynamically possible. But going down this path may drive some interesting innovations that may prove or disprove some of the concerns, we'll see.
But- Yeah. We know that the air traffic controllers need some relief, right? That's one of the most just stressed jobs that you can have, and it's an overstressed industry, and they're working without the resources they need.
For a while, they weren't getting paid. Are they getting paid now? I guess they are.
I'm sure they would love any efficiencies that they could get and things that would take some of the stressors off their plate. But you're right, you're going to have to retrain all of them. Where's the pathway for that, too?
Have they said anything in this announcement, John, about like- Oh, they're as clear as mud on these things. What always comes back to me is that if AI struggles with closed systems like staffing schedules or automated retail, why should we trust it with an open system like the national airspace? And we will.
There will be a resolution. But I just think given the timeline and the players involved here, and the participants, it just makes me shudder. That's all.
Yeah. No. Yeah.
But I'm all for this idea. And the airlines themselves have tried to use AI and data to make it a lot easier for us, in terms of communication. I think Delta's done a pretty good job of it, although they've had a little bit of a few glitches.
But we'll see. Anyway. That's my preferred airline because of their successes, I think.
Look, I just want to make sure there's a big public announcement when they do the final cutover, because let me tell you, I'm staying home. No. I'm not flying that day.
Take travel by train. Yeah. Maybe they could apply it to Amtrak first and see.
Right? Yes! At least that's on rails.
Yeah. I said, why not try something on the ground, something that's safe? Right.
You're far too logical, Terry. You shouldn't work in this administration. You're too smart and you're too logical.
Yeah. But I'll refrain from saying any more. We're going to move on to our last segment and, this is something that Terry wrote, I believe, and it's about- Yeah ...
the FBI's Atlanta field office? Go ahead. I'm sorry.
Resources with law authority, enforcement authorities in Indonesia. Yeah. So it's pretty- Yeah.
Oh, go ahead. Yeah. So it's pretty straightforward.
I'm sorry. You're cutting in and out a little bit, or it might be on my side. Oh.
It's pretty straightforward, right? The FBI's field office in Atlanta worked with authorities in Indonesia to shut down, essentially this marketplace that accounted for millions of dollars in attempted fraud, at least, over the last few years. And I think Georgia was involved, or Atlanta was involved because a lot of the victims were in Georgia and elsewhere, of course, too, but that's why these guys stepped in.
, that the FBI had worked with Indonesian authorities to do something like this, so that made it a little interesting. And they took down the marketplace. I think this thing had been up and actually, the marketplace itself had gone down a couple of years ago, and then it was being passed along through encrypted messaging platforms.
And you could buy this kit, which lowers the bar for the hackers out there. They don't have to be sophisticated or anything like that to be able to do some real damage. And, anyway, so it's supposedly shut down.
You know how this thing is. How many times in my career have I said, "Whack-a-mole, these people keep coming back as something different," and learning from not only the technology that they put out, but then learning how to go around the authorities. But this one, basically websites, or you set up websites that look legit, and then steal people's credentials through that, typical of what we see.
But this was obviously pretty good at it, and you could go around multi-factor authentication, or it allowed it to go around multi-factor authentication. And these poor people would just get scammed, as they often do Was this the first joint operation between the FBI and Indonesia? Yes.
It definitely was the first one that they had done. I wanted to poke around and see if there's more action over in that area of the world now. There's a lot of stuff coming out of that area.
A lot of hackers and whatever, and I'm curious activity, especially in Southeast Asia. I think they're ramping up just sort of way around. But yeah, it was the first time that we had worked with...
And I thought it was interesting to have the Georgia field office in the lead as well. So it's pretty good. Right.
I'm wondering, with AI, an attacker can scrape a target's LinkedIn recent news and public data to craft a one-on-one email in seconds now. Yeah, in seconds. So how would an organization defend against 10,000 unique attacks instead of one blast campaign?
Well, that seems to be the conundrum at this point. Because defend to respond quicker and to detect, I guess, threats sooner. That might be part of it.
We talked to a few people for this story who also, by the way, believe that the worst is yet to come. And that the next generation of defense is behavioral. So, I guess that's what you focus on, but I think it's very hard when we're talking seconds or- Yeah.
" Because this is so important that AI is literally trained on people's information across the internet, trained on what people are and who they are, and what they do and how they react. It's actually trained to make people react. Yeah.
Because this is a reinforcement pattern for AI a lot of the time. And as a result, it ends up directing people to all sorts of terrible things, by the way. Very convincing.
It can learn about you. And going back maybe a couple of segments, it does it all at computer speed, so it can do it at scale. Where you used to have a human understanding how to phish or spear phish within an organization, maybe, now you've got an AI that can do it at scale.
Thousands of businesses, thousands of employees in a millisecond. And if just one hits, then they're golden. And so, the information itself is not enough, is it?
Yeah. No. And so I'm wondering if there's ways to flag this kind of activity to warn the prospective victim.
That's not an easy task, but maybe that's it. And when you're working in an enterprise as a defender, you can do a lot of training and warn off the people that work for you, but then what about all of those people just out there, individual users who, especially older people who tend to maybe fall for some of these things, or give up their information a little more easily than others. That's a very hard thing to defend against, but maybe by training on the corporate level, some of that will sort of seep down into the rest of the population.
I don't know. It's- And by the way, I do think there's a role for AI to play positively here. Right.
You talk about how can we find these things while they're happening? And the answer is use AI to find the problem as well. That's one way we could actually make this more positive use of AI, to defend against the bad actors.
Yeah, for sure. And I think Rex Booth, that I talked to at SailPoint, kind of made that point as well. We have to, on this side, employ AI.
AI's speed and ability to recognize patterns and everything, to defend. But still tough. What I was thinking about in the story is the policy coordination thing.
It makes me think of someone from a Eastern European country, chief security person in the government who we met at a conference and he explained that he just knows a couple of people. Which is about that time. Literally, who do I even call outside of?
And here we have, in the story, of two different jurisdictions coordinating on enforcing policies, and it's the kind of thing, it takes me back to the first segment. This is the same thing, just faster. So it's not that you were wrong or right or whatever, but you've got to this point, now speed it up a lot and see what falls off.
And the flip side of that is that you can actually coordinate... Well, a lot of the last decade for me has been looking at supply chain security. And in the last year, the last Burton Group cycle under CISA, we showed that you can get a software build material across two corporate boundaries in 400 milliseconds.
Because that's the kind of thing you need to do if you're flying rockets or stuff. And so at the policy level, human officers in different jurisdictions coordinating enough to execute on preexisting policies. It's legal here or illegal here, illegal there.
We work together and actually do something about it. That's one of the things you can do with this. Yeah.
I was inspired a little bit about this collaboration, too, because I have felt like, and I know we've discussed in other... meetings or sessions that collaboration has sort of been going the way of the dodo bird. Does anybody ever say that expression anymore?
But- But collaboration has taken a hit in the last few years, like international collaboration, and there's a lot of mistrust there, and whatever. But now, here we go. So maybe that's also a positive that we're- And I will say, I mean, it's super positive that they're collaborating with a nation state like Indonesia.
Indonesia has its own historical challenges with legality and organized crime and other things. Not to say it's unique in the world in that respect, but it has not been a beacon of liberal democracy in the past. And so being able to work with these nation states where otherwise the malicious actors can think, "Maybe this is not where I'm going to get caught.
Maybe if I go here," and the obvious candidates, Russia or China, but also Malaysia, Indonesia, there's ways to slide under the rule of law in a lot of these countries. And so being able to work with them in a positive way on a legal framework to actually chase these bad actors and catch them and eliminate that threat, yeah, look, I think that's a massive feel-good story. Yeah.
And it's also a little bit of soft diplomacy, too. You know, can I ask you a quick... Maybe I'm crazy, but are we prepared for agentic phishing where the AI talks to our internal systems directly?
Why don't you let- Yeah. Oh, your own AI? Yes.
But the agentic, I'm sorry, but I love this one because on this show, this weekly pulse over the last year or two, it's just... " You noticed, mentioned the green room, they just got an AI phishing thing that was just perfect. And now, does anybody else love those, right?
" It's, "I read your data. I did your things. " No, it's not.
No, it's not. But there's no way you're going to automate. Our current phishing filters are dead.
They died in, I think, December of last year, and they're still walking around. They're zombies, right? Assume they don't do anything.
But anyways, I'm sorry. We're here now. Yeah, there you go.
Any other final thoughts? And if not, we'll wrap it up. I think we're coming up against it right now.
Oh, look, I just want to say, I love the idea of doing those stress tests as a recovering SRE, Chris. Wanting to know where's the resilience, accelerate it, see if it still holds up. I love that, and I think that applies to, yes, absolutely, to phishing, hacking attacks.
Yeah, production changes to your database. Any time you've got agentic AI happening. I think I really love that, Chris.
I'm taking that back to my office, and believe me, my team's going to be doing some stress testing this week. There we go. Well, hey, I think we need to wrap it up, but I want to thank everybody.
This was a really fun show. It made me paranoid as hell, but I'm all ready to be- You're already halfway there anyway, right? Already there, yeah.
So what difference does it make? So thank you. You're right, Terry.
Thank you, Terry. Thank you, Chris. Thank you, Andy.
Tomorrow, Mike is out today. He was in New York at a Salesforce event, so you might hear about that tomorrow. I'm going to be traveling back to the Bay Area, and hopefully I will avoid another thunderstorm and tornado warnings.
There's planes flying over here. You can probably hear them in the background. But I want to thank you for watching today.
There's Techstrong TV, of course, has a continuous lineup of content that I think you'll really enjoy. And, for all of our guests and the audience and everyone, I want to thank you for joining again, and we'll see you next time.