The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes

Cybersecurity Headlines38mApril 17, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes” inside PodZeus.

AI-Generated Summary

In this episode of Cybersecurity Headlines, Rich Trafalino and guests Andrew Storms of KiloCode and Eduardo Ortiz of Tektronic Industries dive into a high-stakes week of cybersecurity news. The discussion kicks off with the controversial decision by open-source scheduling platform cal.com to abandon its open-source model due to AI-driven vulnerability discovery, sparking debate over transparency versus security. Minnesota’s deployment of the National Guard after a cyberattack on Winona County underscores the growing blurring of lines between civilian and military cyber response, highlighting the need for robust incident escalation paths. The episode then turns to emerging AI threats, including new attack vectors like hidden prompt injections and Git forgery, which exploit AI-assisted development workflows. NIST’s changes to the National Vulnerability Database (NVD)—prioritizing risk-based processing and dropping enrichment for pre-2026 vulnerabilities—raise alarms about the impact on smaller organizations reliant on public data. The central theme of the episode is the rise of AI-powered threats, particularly Anthropic’s Mythos and OpenAI’s GPT 5.4 Cyber, which demonstrate unprecedented capabilities in autonomous attack simulation. Guests emphasize that while these tools pose existential risks, they also offer transformative opportunities for defense, urging organizations to shift from indicator-based to behavior-based detection and to treat AI as a new baseline. The episode closes with alarming reports of critical infrastructure breaches in Venice and U.S.-linked industrial control systems, underscoring the urgent need for better OT security, network segmentation, and long-term strategic investment in resilient systems. Key takeaways include: (1) AI is no longer a future threat—it’s actively reshaping attack surfaces and must be integrated into security strategy now; (2) the shift from IOCs to behavioral detection is essential for surviving AI-driven attacks; (3) supply chain risks are no longer just about code—runtime trust and continuous monitoring are critical; (4) smaller organizations are disproportionately impacted by NVD changes and must build custom resilience; (5) critical infrastructure remains dangerously exposed due to legacy systems and slow modernization cycles; (6) organizations must treat AI as a new baseline, not an emerging trend; (7) board-level communication about AI risk should focus on business impact and preparedness; and (8) proactive testing of AI agents in safe environments is now a necessity for security teams.

Key Takeaways
1

Treat AI as a new baseline, not an emerging trend—proactive integration is no longer optional.

2

Shift from IOCs to behavior-based detection to counter AI-driven, automated attacks.

3

Supply chain security must extend beyond inventory to include runtime monitoring and trust verification.

4

Smaller organizations are at high risk from NVD changes and must invest in private feeds or internal expertise.

5

Critical infrastructure remains underdefended due to legacy systems and slow modernization cycles.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

Opening: Priorities & Sponsor Intro

Rich Trafalino opens the show with a quick check-in on guest priorities—networking for Rich, travel planning for Eduardo—and introduces the sponsor, Conveyor, while setting the stage for a packed episode on cybersecurity news.

2:00
3 min

cal.com Abandons Open Source

They want to be a scheduling company, not a cybersecurity company.

Highlight
5:00
4 min

Minnesota National Guard Deployed After Cyberattack

Minnesota Governor Tim Walz deployed the National Guard to Winona County after a cyberattack disrupted municipal services. The discussion explores the significance of military cyber response and draws parallels to private-sector incident response planning.

9:00
6 min

New AI Agent Attacks & Git Forgery

It's a new category of software supply chain risk that didn't exist two years ago.

Highlight
15:00
5 min

NVD Changes: Prioritizing Risk Over Volume

The KEB carve-out helps in this case. But it's, you know, it's kind of like a narrow, very narrow safety net for these teams.

Highlight
High-Impact Quotes
There's the potential here for enormous short-term pain, but long-term this makes him incredibly optimistic.
Phil Venerables21:13
Viral: 92.0
It's a new category of software supply chain risk that didn't exist two years ago.
Eduardo Ortiz9:12
Viral: 90.0
The attack chain complexity that previously required a lot of skilled human operators is now pretty much automated.
Eduardo Ortiz18:49
Viral: 88.0
Speakers

Host

Rich Trafalino

Guests

Andrew StormsEduardo Ortiz
Topics Discussed
AI-Powered Cyber Threats95%Critical Infrastructure Protection92%Open Source Security90%Software Supply Chain Risk88%Behavior-Based Detection87%Vulnerability Management85%AI Ethics and Dual Use80%National Guard Cyber Response75%
People & Brands

Eduardo Ortiz

person

25xPositive

Andrew Storms

person

20xPositive

Rich Trafalino

person

15xPositive

CISO Series

organization

10xPositive

Mythos

other

10xMixed

National Vulnerability Database

other

8xNeutral

Minnesota National Guard

organization

6xNeutral

Anthropic

organization

6xPositive

Conveyor

organization

5xPositive

NIST

organization

5xNeutral

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime