Mandiant
Information security companywww.mandiant.com
49
MENTIONS
34
EPISODES
32
PODCASTS
Search complete. 49 mentions across 34 episodes found for "Mandiant".
Sep 20, 2026
An undercover Google analyst infiltrated a notorious supply-chain hacking gang — 2026-09-20
S
0:35speaker_0HOST
But what sets this story apart is Google's covert involvement.
S
0:39speaker_0HOST
During Team PCP's hacking spree, an analyst from Google's threat intelligence group, Mandiant, infiltrated the group.
S
0:46speaker_0HOST
This undercover analyst provided Google with real-time insights into the hacker's operations, allowing the company to warn potential targets and disrupt the group's activities from within.
S
0:57speaker_0HOST
At the Sentinel-1 LabsCon conference, Austin Larson from Google's Threat Intelligence Group revealed the details of this operation.
Cyber Daily News for September 19th, 2026
S
1:28speaker_0HOST
Organisations in these industries must update their defences to detect this specific malware family.
S
1:33speaker_0HOST
Mandiant has released its 2026 AI risk report, while a ransomware developer received a prison sentence for previous attacks.
S
1:41speaker_0HOST
Security teams are also dealing with the plug-in 4-shell AI attack vector and a critical flaw in SAP software.
S
1:48speaker_0HOST
These developments underscore the growing complexity of threats involving AI and legacy enterprise systems.
A hijacked AI coding session reportedly spread a worm across about 100 repositories
S
0:09speaker_0NARRATOR
A hijacked AI coding assistant session reportedly helped an attacker spread malicious code across about 100 internal repositories at an unnamed software-as-a-service provider.
S
0:19speaker_0NARRATOR
According to Mandiant, the assistant first recommended software that the attacker had poisoned, and someone accepted that recommendation.
S
0:26speaker_0NARRATOR
the resulting shai-halud activity then spread through the internal repositories and stole repository secrets and source code.
S
0:32speaker_0NARRATOR
This incident shows how a connected coding agent can turn one compromised session into a much wider software supply chain problem.
17-Sep-2026 Cisco Zero-Day, Mandiant AI Worm and Maritime Cyber Threats
S
1:36speaker_0HOST
Top story number three.
S
1:38speaker_0HOST
Mandiant says an attacker hijacked an active AI coding assistant session at an unnamed software-as-a-service provider and used it to spread the Shai-Hulud worm across about 100 internal repositories.
S
1:52speaker_0HOST
The campaign began after a poisoned software recommendation was accepted, then escalated through a malicious PyPI package, stolen GitHub OAuth tokens and an infected package in the company's own namespace, ultimately stealing source code and secrets.
S
2:10speaker_0HOST
The case underscores how AI-assisted development can become an entry point for supply chain compromise, prompting calls for checksum verification, stricter secret handling, and controlled dependency routing.
P
Unknown podcast
2026-09-17: Cisco ISE has a CVSS 10 authentication bypass zero-day (CVE-2026-76460) under active exploitation
Sep 17 · 1 Mention
C
5:43CarolinaHOST
AI coding assistant hijacked.
C
5:45CarolinaHOST
Shyhoolid worm spreads across Tilda 100 repositories Mandiant reports an attacker hijacked an active AI coding assistant session at an unnamed SAW-S provider.
C
5:54CarolinaHOST
The assistant recommended a poisoned PyPI package, which was accepted.
C
5:58CarolinaHOST
The attacker stole GitHub OAuth tokens and deployed the Shyhoolid worm across approximately 100 internal code repositories, exfiltrating repository secrets and product source code.
Hijacked AI coding session spreads compromise across about 100 repositories
S
0:09speaker_0NARRATOR
A compromised software development workflow allowed malicious activity to spread across about 100 internal code repositories.
S
0:17speaker_0NARRATOR
Mandiant says, an attacker hijacked an active AI coding assistant session at an unnamed software-as-a-service provider.
S
0:25speaker_0NARRATOR
Before that repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted.
S
0:32speaker_0NARRATOR
The resulting shai-hulud activity stole repository secrets and source code.
These researchers got drunk to hack an LG TV
A
40:56Andy HorngoldGUEST
Been at Intruder for five years, and my background is pretty heavily in the offensive security space.
A
41:00Andy HorngoldGUEST
So previously, I was at Mandiant, where I was the EU red team lead.
A
41:04Andy HorngoldGUEST
Intruder's mission is to essentially prevent breaches before they start.
A
41:09Andy HorngoldGUEST
We focus very heavily on that initial access side of things where we're trying to find weaknesses and exposures that may result in a breach.
EP29 Binary Similarity in the LLM Era with Jonas Wagner and Endre Bangerter of ThreatRay
E
39:09Endre BangerterGUEST
Or maybe you can find some contextual information about it, so that's what we're doing in TreadTray.
E
39:16Endre BangerterGUEST
We started a couple of years ago to index samples which are referenced in open source intelligence, let's say in blogs by Mandiant or whoever, right? We crawl these blogs, we get the hashes, then we get the binaries, we index the code of the binaries.
E
39:36Endre BangerterGUEST
We have a big number of binaries which are associated with the blog post basically, right? And how you could help an instant responder is basically, okay, that's a piece of unknown code.
E
39:48Endre BangerterGUEST
We don't know the family.
Directing in the Age of AI | Yvonne Wassenaar & Alla Whitston
Y
7:42Yvonne WassenaarGUEST
So every single board should be doing cyber tabletops with management.
Y
7:46Yvonne WassenaarGUEST
You should know, do you have the relationship with Mandiant, with what three-letter agencies? It is coming for all of us.
Y
7:53Yvonne WassenaarGUEST
And I will tell you on the two incidents that I can specifically reference, you know, basically Mandiant, Booz Allen, the three-letter agencies have all confirmed, oh, it is AI.
Y
8:04Yvonne WassenaarGUEST
AI was able to go through this other company, get a legitimate credential, go in, the pace of what they're working is not human possible.
Y
8:14Yvonne WassenaarGUEST
And so I do a lot with CISOs, and they have said the next 12 to 18 months, while all these vulnerabilities are uncovered, are going to be the most hellacious of their life, and therefore by default for all of us as board directors.
Can the Private Sector Go on Cyber Offense? with Armadin's Stacy O'Mara
F
1:00Frank CilluffoHOST
Stacey is at Armiden, and she's leading their government affairs efforts and much more.
F
1:06Frank CilluffoHOST
She had previously done so with Mandiant, Google, and just a... truly informed guest and a longtime friend and someone I always turn to when I'm looking for concise answers.
F
1:19Frank CilluffoHOST
Stacey, thanks so much for joining
S
1:20Stacy O'MaraGUEST
us.
20 MINS LATER
S
21:30Stacy O'MaraGUEST
Yeah, no, you want all of those relationships in place way before an event pops off.
S
21:37Stacy O'MaraGUEST
And that is within the industry community with and between the interagency and government agencies.
S
21:48Stacy O'MaraGUEST
And then also with foreign partners, you know talking about Ukraine again, which is another great case study for a lot of these topics On one of our visits there we were sitting with a couple liaisons in the room and in in Brussels and we were I don't know four or five months into the war and it was very quiet and somber and you know these men had families in Ukraine and finally and I was with the head of intelligence and my boss and he finally he says well if it weren't for Mandiant, we would have fallen to the Russians.
S
22:17Stacy O'MaraGUEST
And it was a very sobering moment.
24 more episodes mention Mandiant.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.