w/ Vaisha Bernard, Chief Hacker, Eye Security
In this episode of The Disclosure, we dive deep into three pressing topics shaping the cybersecurity landscape: The SharePoint Exploit with Vaisha Bernard (Chief Hacker, Eye Security) We sit down with Vaisha Bernard from Eye Security, the first team to discover the SharePoint exploit actively being weaponized in the wild. Vaisha breaks down how it was uncovered, what makes it dangerous, and what organizations need to do now to protect themselves. Links: Original Post https://research.eye.security/sharepoint-under-siege BlackHat Talk: https://www.blackhat.com/us-25/briefings/schedule/speakers.html#vaisha-bernard-47804 Supply Chain Attacks on NPM with Charlie Eriksen Charlie Eriksen joins us to discuss a surge in supply chain attacks targeting NPM. We unpack a clever phishing campaign that’s luring popular maintainers using the deceptive domain NPNjs.com. Charlie shares insights on how this tactic is tricking developers and the wider implications for open-source security. Cyber and Sake: AI’s Impact on Application Security with Berg Severens In our Cyber and Sake segment, Berg Severens and I explore how artificial intelligence is transforming security scanning for applications. From enhanced detection to automated fixes, we discuss how AI is reshaping the future of app security—and what risks it introduces. Whether you're a security pro or just curious about the evolving threat landscape, this episode is packed with critical insights and expert perspectives. Chapters: 00:00 - Introduction and Episode Overview 01:12 - Microsoft SharePoint Exploit Deep Dive with Vaisha Bernard 16:13 - Supply Chain Attacks and npm Malware Surge with Charlie Eriksen 24:10 - Sponsor Segment: Aikido Security and Safechain 25:08 - AI in Security Scanning: Sake and Cyber with Berg Severens 30:41 - Auto Triage and False Positives Reduction Using AI 38:43 - AI Economics and Moore's Law in Cybersecurity 47:17 - Challenges in AI Learning and Future Prospects 48:29 - Would You Rather Gam
Tell us who, why, and how to reach them. We read every submission.