Episodes

  • Neuroscience, AI Research & Hiring Swifties with Alon Schindel
    Feb 12 2026

    Agentic AI is coming. Are defenders ready?

    Alon Schindel, Director of Data & Threat Research at Wiz, joins Eden and Amitai for the Season 3 Finale. This isn't just a recap. It is a look at how top-tier research teams operate at speed. Alon explains why Wiz treats research as a "product" rather than a support function. He details the "DeepLeak" discovery where his team found thousands of exposed API keys mere hours after a platform's popularity spiked.

    What's Inside:

    • Agentic AI: Why 2026 will be the year AI starts taking action, not just chatting.

    • Speed as a Weapon: How to shorten the time between a zero-day and a detection.

    • Culture: The power of the "Table" and collaborative chaos.

    • Retrospective: Lessons from IngressNightmare and the year in vulnerabilities.

    Resources:

    • Read the DeepLeak Research: https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak

    • Wiz Threat Research Hub: https://www.wiz.io/research

    Show More Show Less
    24 mins
  • Hacking Moltbook with Gal Nagli
    Feb 3 2026

    🚨 Vibe coding meets critical data exposure: The Moltbook Hack.


    On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Wiz researcher Gal Nagli to unpack how he compromised the "Facebook for AI Agents" in under an hour ↓


    1. How a simple boolean manipulation (valid: false to true) bypassed authentication

    2. Cloud Database misconfigurations and the failure of Row Level Security (RLS)

    3. How Claude Code was used to identify and exploit the vulnerability

    4. The security reality of "Vibe Coding" and zero-manual-code applications

    Show More Show Less
    13 mins
  • CodeBreach: Hijacking the AWS Console with Yuval Avrahami
    Jan 15 2026

    🚨 Everything you need to know about CodeBreach with Yuval Avrahami


    On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with Wiz researcher Yuval Avrahami to unpack a major supply-chain flaw that put cloud environments at risk ↓


    Misconfigured CodeBuild instances used by AWS themselves

    One small regex mistake, huge consequences

    How an SDK used by the AWS Console could have been hijacked (!)

    The CI/CD controls that can mitigate this risk

    Show More Show Less
    17 mins
  • React2Shell, Shai-Hulud 2.0, Gogs Zero-Day & Tika RCE
    Jan 1 2026

    🎙️ Shai-Hulud, Shai-Hulud 2.0, are you keeping up?

    In this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen go deep into real-world cloud security incidents ↓

    1. How Shai-Hulud evolved into Shai-Hulud 2.0

    2. A vulnerability affecting Apache Tika

    3. React2Shell and its implications

    4. Gogs zero-day explained

    You DONT want to miss this!
    This is a technical, concrete conversation focused on how attacks actually happen, how they evolve, and what defenders need to understand to keep up.

    Show More Show Less
    20 mins
  • Live Talk: Security Minds from Google Cloud, AWS & Wiz
    Dec 8 2025

    🎙️ AI is changing the rules of cyber, are you keeping up?Eden Naftali goes live with leading voices in cloud security:Ryan Nolette (AWS), @John Miller (Google Cloud), and Alon Schindel (Wiz). This episode is essential listening for anyone defending at cloud scale. 👇🔍 Inside ↓1) How AI is supercharging attacker tactics — from hyper-variable phishing to rapid exploit generation2) The rise of "AI slop" and why it's burning analysts' time3) Emerging AI bug-hunters — what they can (and can't) do

    Show More Show Less
    22 mins
  • Cloud Detection Engineering, AI in the SOC and Parallel Parking with Alex Hurtado
    Nov 14 2025

    Detection engineering just got real!
    Eden Naftali and Amitai sit down with detection engineering powerhouse Alex Hurtado - and it's a must-listen for anyone in cloud security. 👇

    🔍 What's inside:

    1. The evolution of detection engineering in the cloud — and why traditional rules no longer apply

    2. Why DIY detections > vendor defaults

    3. How AI is reshaping detection and threat hunting (and why the human in the loop still wins)

    Show More Show Less
    26 mins
  • VSCode Extension Secrets, RediShell, & Living-off-the-LLM
    Nov 7 2025

    🔍 From discovering VS Code supply chain risks → to uncovering Redis Shell vulnerabilities.

    Eden Naftali and Amitai sat down to unpack: 👇

    • How VS Code extensions became a critical supply chain risk (w/ Rami McCarthy)

    • What RediShell reveals about attacker innovation

    • Where AI is being weaponized in modern malware

    🎙️ Listen now to our NEW Crying Out Cloud episode

    Show More Show Less
    30 mins
  • eBPF, Fishy Book Covers, and Open Source Security with Liz Rice
    Sep 16 2025

    🚨 The kernel-level security revolution you can't ignore — a must-listen with Liz Rice

    Eden Naftali and Amitai sit down with Liz Rice, Chief Open Source Officer at Isovalent (Cisco), and a global expert in eBPF, containers, and Kubernetes security.

    🎙️ In this episode:

    • How eBPF is reshaping cloud security from the ground up

    • Practical strategies to tackle open source supply chain attacks (a hot topic given today’s events)

    A must-listen for anyone building or securing cloud infrastructure in an era of AI coding and supply chain attacks.

    Show More Show Less
    33 mins