FireSideChats: AI News (Fable) and AI Security Musings

Hey All!

This week will be a bit different. Ryan and I conducted a fireside chat discussing the recent export control ban on Anthropic's Fable and Mythos AI models. We explained how Anthropic had been quietly releasing Mythos to enterprises before adding guardrails to create Fable, which showed significant performance gains on cybersecurity tasks such as code auditing. However, after just 4 days of public access, Amazon researchers discovered a “jailbreak” and reported it to the government, leading to export controls that prevented non-US citizens from accessing the models. The conversation covered the technical limitations of current AI safety measures, including the impossibility of completely preventing model jailbreaking, and discussed the growing competition in open-source AI models like GLM 5.2 that are approaching the performance of paid models like Claude.

We also addressed hardware considerations for running AI models locally, compared Mac Studio performance with PC-based solutions using multiple graphics cards, and shared their upcoming speaking engagements at DEFCON and Black Hat.

(Sorry for the low quality video, we will do 4k next time)

Legacy SASE Was Built for Yesterday’s Work. AI Changed the Rules.

Legacy SASE helped secure the modern enterprise when work still moved through predictable networks and apps. But AI has changed the shape, speed, and location of risk.

Employees paste sensitive data into prompts. Agents act with employee-level access. Enforcement often happens after intent has already passed. "The Perfect Packet:
A Guide to Modern SASE Architecture” from Island helps security practitioners understand where SASE architectures break down, why the gaps are structural, and what a stronger enforcement model looks like for the AI era.

NTLM Called. Your AI Agent Has the Same Problem.

In the 1970s, Unix managed many users on one machine by storing hashed passwords in a world-readable file. Readable to the system, readable to attackers too.

Today, AI agents need standing credentials to be ‘agentic’. Too bad a single point of compromise hands an attacker everything the agent touches.

From password hashes to AI agent tokens, every fix opens the next door. Knowing that history is how you shut the door on attackers. Read about “The Evolution of Identity Security” today!