State of the AI SOC, regulating AI, and can AI agents feel pain?
Interview with Aqsa Taylor
Exaforce's Chief Security Evangelist, Aqsa, joins us to discuss the current state of the AI SOC and why it covers so much more than it did over 2 years ago, when our podcast first started covering this market. Exaforce also recently released AI Security and its ExaGo mobile app - we're very excited about the possibility of analyzing incidents at the grocery store!
This segment is sponsored by Exaforce. Visit https://securityweekly.com/exaforce to learn more about them!
Topic Segment - Regulating AI
The AI industry's sandbox escapes have had a big impact on everyone and unsurprisingly, there's a bill proposing to ban some AI products and pause the development of others.
It seems that, increasingly, as pro-AI and anti-AI groups become more polarized and divided, you could start an entire podcast that does nothing but fact-check both sides. We're an emotional species and it seems the more heated debate gets, the more folks on both sides are willing to straight-up fabricate things to help argue their points.
Today's focus is this YouTube video: https://www.youtube.com/watch?v=WXsTCJl7sU4
It's the most on-the-nose type of propaganda - straight up claiming the government is going to break into your house and take your GPUs and LLMs. Could the bill proposed by Bernie Sanders and Greg Casar be characterized as extreme? Sure, but it's nowhere near as extreme as the title of the video, "They're Banning AI Servers at Home" suggests.
The hardest things to swallow about the video:
- it characterizes Bernie Sanders as "the government", as if he's representative of most of the US government rather than an outlier that has little to no chance to get a bill like this passed
- it never mentions the fact that the bill establishes a model cutoff, measured in training effort (10^25 flops, which doesn't include the open weight models you're using at home, unless you have an 8x cluster of DGX Sparks - $40k+ worth of AI compute)
Enterprise News
Finally, in the enterprise security news,
- we check the vibes
- massive, connected funding
- NVIDIA OpenShell
- cars are still hackable
- a ransomware arrest turned into a murder investigation
- AI welfare
All that and more, on this episode of Enterprise Security Weekly.
Aqsa Taylor is a cybersecurity leader, author, and technology evangelist recognized among the Top 20 Women in Cybersecurity in the World in 2026. She brings a rare perspective that spans building security products, advising CISOs, researching emerging technologies, and explaining where the industry is heading.
Aqsa started her career at Twistlock as its first Solutions Engineer and went on to Palo Alto Networks, where she helped integrate Twistlock following its $410M acquisition and led the launch of agentless workload security across AWS, Azure, and GCP. She has since held product and marketing leadership roles at Gutsy and Abstract Security.
As Chief Research Officer at SACR, Aqsa authored research and market analysis read by 16,000+ security professionals on average, advised CISOs, helped build the firm’s CISO advisory board, and contributed to more than $440K in revenue. She has also worked directly with organizations representing 44%+ of the Fortune 100.
Today, as Chief Security Evangelist at Exaforce, Aqsa focuses on making complex security and AI topics understandable, practical, and actionable. She is the author of Process Mining: The Security Angle and co-author of Applied Security Data Strategy, bringing a practitioner-first perspective to conversations about AI, cloud security, SecOps, and the future of cybersecurity.
Quick reality check. Your environment isn't getting simpler. It's getting noisier.
More identities. More cloud services. More third parties. More AI. But your team? Probably not getting more headcount.
The challenge isn't collecting more telemetry or buying another tool. It's figuring out where your organization is actually exposed and what deserves your attention first.
If you're defending financial systems, join us October 14 for the FinSec Virtual Summit. You'll hear how enterprise security teams are prioritizing risk, strengthening resilience, and making smarter security decisions without adding unnecessary complexity.
Register for free at https://securityweekly.com/finsec using the discount code CSS26-SW!
InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Adrian Sanabria
- FUNDING/M&A courtesy of the Security, Funded newsletter, #263 – Ctrl+C, Ctrl+VC
VIBE CHECK
Why do security categories converge on the same roadmap within 18 months of inception?
- 46% - Customers all ask for the same thing
- 31% - Teams copy what works
- 8% - Analysts define the category
- 8% - Investors fund the same pitch
- 8% - Other (tell me)
Adrian's variation on the winning answer: "Gartner tells customers to all ask for the same thing"
FUNDING
- Cyera, a United States-based data security posture management platform, raised a $400.0M Series G from Evolution Equity Partners.
- Island, a United States-based remote enterprise browser isolation platform, raised a $400.0M Series F from Evolution Equity Partners.
Note from Adrian: "Well, that's weird. Is that a typo?"
- NEW PRODUCTS: Say Hello to Agent Insta: Scanless Detection at AI Speed
I'm surprised it took this long, but we've got a mainstream vuln mgmt tool enabling an intel-driven flow. I'm glad to see it!
- NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
Basically just a simple (hopefully) effective sandbox for AI agents. Great intro video on it here: https://youtu.be/GYYP-eW58ug?is=F4wMD0sFCjJRw3r_
- CYBERINSURANCE: Cyberattacks to be insured like accidents: Ministry of Finance discusses new rules for critical infrastructure – DataBreaches.Net
- VULNERABILITIES: Anthropic-linked CVEs pile up, attackers mostly shrug
“There's a big difference between finding vulnerabilities and whether they're actually useful to and will be used by threat actors,” Garrity told The Register.
- ESSAYS: I don’t like passkeys
- RESEARCH: We got a cybersecurity expert to hack this BYD. It was too easy
- REPORTS: Account Takeovers Rise – Travelers Insurance
- REPORTS: State of Security Champions Report 2026
- ARRESTS: Shocker: suspected ShinyHunters member charged with attempted incitement to commit two murders – DataBreaches.Net
This story is getting wild. Brian Krebs was talking to Pepijn regularly and then he went silent. A few weeks later, the FBI got hacked and terabytes of data was stolen. Pepijn was brought in under suspicion of doing the attack. When they searched his laptop, they found that he had potentially ordered a hit on two people.
Attacking the FBI and attempted murder? For someone that just got out of jail a few months ago?
- ATTACKS: Early rogue AI agent activity and attempts to hack found on urlquery.net
- LAWSUITS: Factor Cybersecurity Files Federal Lawsuit Against SecurityScorecard and CEO Aleksandr Yampolskiy
- SQUIRREL: Would an AI in pain pay a price to make it stop?
A World Appears by Michael Pollan
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.