Dark mode: ON

Infosec Decoded Season 6 #13: Secure Access Service Edge (SASE)

With sambowne@infosec.exchange and Doug Spindler

Recorded Thu, Feb 26, 2026

AI

Pentagon’s AI Ultimatum Is a Warning Shot—at America
Washington is no longer asking Silicon Valley whether it wants to be in the business of "warfare technology." It is asking how quickly it can stop acting like it has a choice.
What the Anthropic AI safety saga is really all about
Anthropic has reached a familiar crossroads for a growing tech company: how to scale without compromising the principles that set it apart.
Code Mode: give agents an entire API in 1,000 tokens
Instead of adding tools to every prompt, using up tokens, Code Mode runs search() and execute() operations in an external, non-AI service. This is the future of agentic AI, mixing AI operations with non-AO operations for increased cost efficiency.
Guide Labs debuts a new kind of interpretable LLM
Guide Labs, a San Francisco startup, open sourced an 8-billion-parameter LLM, Steerling-8B, trained with a new architecture designed to make its actions easily interpretable: Every token produced by the model can be traced back to its origins in the LLM’s training data.

Developers insert a concept layer in the model that buckets data into traceable categories. This requires more up-front data annotation, but by using other AI models to help, they were able to train this model as their largest proof of concept yet.

Hacker Used Anthropic’s Claude to Steal Mexican Data Trove
The unknown Claude user wrote Spanish-language prompts for the chatbot to act as an elite hacker, finding vulnerabilities in government networks, writing computer scripts to exploit them and determining ways to automate data theft. In a month, he stole 150 gigabytes of Mexican government data.
FBI Got Grok to Hand Over Prompts Used to Create Nonconsensual Porn
The FBI obtained prompts used to make more than 200 sexual videos of a woman in a harassment case.
Boston AI startup can predict risk of breast cancer before tumors appear
Using only a typical mammogram image, the system is able to pinpoint women at a high risk of developing breast cancer with much greater accuracy than traditional methods.
PwC and Anthropic Collaborate to Advance Enterprise Agent Deployment in AI Native Finance and Healthcare & Life Sciences
Enterprises are moving past AI pilots and into real workflows. In all industries, especially those that are highly regulated, that means getting governance, auditability, and risk controls right from day one. PwC understands that better than anyone, and they're building the industry-specific skills and plugins on Cowork to make it happen.
Microsoft deletes blog telling users to train AI on pirated Harry Potter books
A Kaggle dataset that included all seven Harry Potter books has been available online for years and incorrectly marked as “public domain.”

Politics

Trump Should Take the U.S. Military’s Warning on Iran Seriously
The US doesn't have enough munitions, and Iran could retaliate US bases, oil infrastructure of our allies, or close the Strait of Hormuz, thereby spiking global oil prices. These are all risks that the U.S. military is acutely aware of, and they are magnified because of the likely lack of support from any allies—aside from Israel—for U.S. operations against Iran.
Meta executive warned Facebook Messenger encryption plan was 'so irresponsible', shows court filing
Meta execs feared encryption would hinder child exploitation reporting.

End-to-end encryption poses a heightened risk when built into public social networks that readily connect children to people they do not otherwise know. Encrypting a mere messenger like WhatsApp is safer.

ICE whistleblower testifies to Congress about minimal training
ICE is “lying to Congress and the American people” about its training of new recruits.

Classes on firearms training intended “to teach them how to use their weapons correctly and safely” were eliminated, as well as other courses on the constitutional requirements and limits of their roles. That included a 2-hour course about the rights of protesters, which was reduced to 10 minutes.

“Many graduates go to their home office just long enough to get their gun, their badge and their body armor before deploying to places like Minneapolis and other ICE operations with minimal supervision,” Schwank said. “It’s shocking that anyone would think this is safe or responsible.”

The Carlson-Huckabee interview may be the wake-up call Americans needed
Huckabee, who is also a Baptist minister and former governor of Arkansas, was confirmed as US ambassador to Israel in April 2025. The news of his appointment was welcomed by the Israeli government and various pro-Israel groups, and he was hailed as a “true friend of Israel”.
Exclusive: US orders diplomats to fight data sovereignty initiatives
Trump's administration has ordered U.S. diplomats to lobby against attempts to regulate U.S. tech companies' handling of foreigners' data, saying such efforts could interfere with artificial intelligence-related services.
Kalshi reveals insider trading case against editor for MrBeast
He's been suspended from the prediction market and reported to federal regulators for insider trading. He had "near-perfect trading success" on bets about the YouTuber's videos with low odds, making the wagers appear suspicious,

Infosec

Cloudflare One is the first SASE offering modern post-quantum encryption across the full platform
Secure Access Service Edge (SASE) is a cloud-native architecture that converges software-defined wide area networking (SD-WAN) and cloud-native security functions—such as Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Firewall-as-a-Service (FWaaS), and Zero Trust Network Access (ZTNA)—into a single, unified service.

At the end of 2024, the National Institute of Standards and Technology (NIST) sent a clear signal: the era of classical public-key cryptography is coming to an end. NIST set a 2030 deadline for depreciating RSA and Elliptic Curve Cryptography (ECC) and transitioning to PQC that cannot be broken by powerful quantum computers.

This App Warns You if Someone Is Wearing Smart Glasses Nearby
The app scans for smart glasses’ distinctive Bluetooth signatures and sends a push alert if it detects a potential pair of glasses in the local area.
5 Home Security Cameras To Avoid At All Costs, According To Consumer Reports
#1 is SimpliSafe, because its response time to motion is too slow and the daytime image quality too poor.
Google’s new 1.9GW clean energy deal includes massive 100-hour battery
They'll build 1.4 gigawatts of wind power and 200 megawatts of solar power to power a data center. Both will feed Form’s battery, which will be capable of delivering its rated power for 100 hours. At 30 gigawatt-hours, it will be the largest battery in the world, helping the data center operate on clean energy for longer periods of time. Form’s batteries store energy by rusting and deoxidizing iron.
AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
By sending pings, an attacker can redirect traffic to gain AITM status, just like old-fashioned ARP poisoning. I don't see any big risk here.