Skip to main content
Mandiant

Mandiant

Information security companywww.mandiant.com

Search complete. 49 mentions across 34 episodes found for "Mandiant".

Sep 20, 2026

speaker_0HOST
0:35
But what sets this story apart is Google's covert involvement.
speaker_0HOST
0:39
During Team PCP's hacking spree, an analyst from Google's threat intelligence group, Mandiant, infiltrated the group.
speaker_0HOST
0:46
This undercover analyst provided Google with real-time insights into the hacker's operations, allowing the company to warn potential targets and disrupt the group's activities from within.
speaker_0HOST
0:57
At the Sentinel-1 LabsCon conference, Austin Larson from Google's Threat Intelligence Group revealed the details of this operation.
speaker_0HOST
1:28
Organisations in these industries must update their defences to detect this specific malware family.
speaker_0HOST
1:33
Mandiant has released its 2026 AI risk report, while a ransomware developer received a prison sentence for previous attacks.
speaker_0HOST
1:41
Security teams are also dealing with the plug-in 4-shell AI attack vector and a critical flaw in SAP software.
speaker_0HOST
1:48
These developments underscore the growing complexity of threats involving AI and legacy enterprise systems.
speaker_0NARRATOR
0:09
A hijacked AI coding assistant session reportedly helped an attacker spread malicious code across about 100 internal repositories at an unnamed software-as-a-service provider.
speaker_0NARRATOR
0:19
According to Mandiant, the assistant first recommended software that the attacker had poisoned, and someone accepted that recommendation.
speaker_0NARRATOR
0:26
the resulting shai-halud activity then spread through the internal repositories and stole repository secrets and source code.
speaker_0NARRATOR
0:32
This incident shows how a connected coding agent can turn one compromised session into a much wider software supply chain problem.
speaker_0HOST
1:36
Top story number three.
speaker_0HOST
1:38
Mandiant says an attacker hijacked an active AI coding assistant session at an unnamed software-as-a-service provider and used it to spread the Shai-Hulud worm across about 100 internal repositories.
speaker_0HOST
1:52
The campaign began after a poisoned software recommendation was accepted, then escalated through a malicious PyPI package, stolen GitHub OAuth tokens and an infected package in the company's own namespace, ultimately stealing source code and secrets.
speaker_0HOST
2:10
The case underscores how AI-assisted development can become an entry point for supply chain compromise, prompting calls for checksum verification, stricter secret handling, and controlled dependency routing.

Unknown podcast

2026-09-17: Cisco ISE has a CVSS 10 authentication bypass zero-day (CVE-2026-76460) under active exploitation

Sep 17 · 1 Mention

CarolinaHOST
5:43
AI coding assistant hijacked.
CarolinaHOST
5:45
Shyhoolid worm spreads across Tilda 100 repositories Mandiant reports an attacker hijacked an active AI coding assistant session at an unnamed SAW-S provider.
CarolinaHOST
5:54
The assistant recommended a poisoned PyPI package, which was accepted.
CarolinaHOST
5:58
The attacker stole GitHub OAuth tokens and deployed the Shyhoolid worm across approximately 100 internal code repositories, exfiltrating repository secrets and product source code.
speaker_0NARRATOR
0:09
A compromised software development workflow allowed malicious activity to spread across about 100 internal code repositories.
speaker_0NARRATOR
0:17
Mandiant says, an attacker hijacked an active AI coding assistant session at an unnamed software-as-a-service provider.
speaker_0NARRATOR
0:25
Before that repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted.
speaker_0NARRATOR
0:32
The resulting shai-hulud activity stole repository secrets and source code.
Andy HorngoldGUEST
40:56
Been at Intruder for five years, and my background is pretty heavily in the offensive security space.
Andy HorngoldGUEST
41:00
So previously, I was at Mandiant, where I was the EU red team lead.
Andy HorngoldGUEST
41:04
Intruder's mission is to essentially prevent breaches before they start.
Andy HorngoldGUEST
41:09
We focus very heavily on that initial access side of things where we're trying to find weaknesses and exposures that may result in a breach.
Endre BangerterGUEST
39:09
Or maybe you can find some contextual information about it, so that's what we're doing in TreadTray.
Endre BangerterGUEST
39:16
We started a couple of years ago to index samples which are referenced in open source intelligence, let's say in blogs by Mandiant or whoever, right? We crawl these blogs, we get the hashes, then we get the binaries, we index the code of the binaries.
Endre BangerterGUEST
39:36
We have a big number of binaries which are associated with the blog post basically, right? And how you could help an instant responder is basically, okay, that's a piece of unknown code.
Endre BangerterGUEST
39:48
We don't know the family.
Yvonne WassenaarGUEST
7:42
So every single board should be doing cyber tabletops with management.
Yvonne WassenaarGUEST
7:46
You should know, do you have the relationship with Mandiant, with what three-letter agencies? It is coming for all of us.
Yvonne WassenaarGUEST
7:53
And I will tell you on the two incidents that I can specifically reference, you know, basically Mandiant, Booz Allen, the three-letter agencies have all confirmed, oh, it is AI.
Yvonne WassenaarGUEST
8:04
AI was able to go through this other company, get a legitimate credential, go in, the pace of what they're working is not human possible.
Yvonne WassenaarGUEST
8:14
And so I do a lot with CISOs, and they have said the next 12 to 18 months, while all these vulnerabilities are uncovered, are going to be the most hellacious of their life, and therefore by default for all of us as board directors.
Frank CilluffoHOST
1:00
Stacey is at Armiden, and she's leading their government affairs efforts and much more.
Frank CilluffoHOST
1:06
She had previously done so with Mandiant, Google, and just a... truly informed guest and a longtime friend and someone I always turn to when I'm looking for concise answers.
Frank CilluffoHOST
1:19
Stacey, thanks so much for joining
Stacy O'MaraGUEST
1:20
us.

20 MINS LATER

Stacy O'MaraGUEST
21:30
Yeah, no, you want all of those relationships in place way before an event pops off.
Stacy O'MaraGUEST
21:37
And that is within the industry community with and between the interagency and government agencies.
Stacy O'MaraGUEST
21:48
And then also with foreign partners, you know talking about Ukraine again, which is another great case study for a lot of these topics On one of our visits there we were sitting with a couple liaisons in the room and in in Brussels and we were I don't know four or five months into the war and it was very quiet and somber and you know these men had families in Ukraine and finally and I was with the head of intelligence and my boss and he finally he says well if it weren't for Mandiant, we would have fallen to the Russians.
Stacy O'MaraGUEST
22:17
And it was a very sobering moment.

24 more episodes mention Mandiant.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.