The Cyberattack We’re Not Ready For

16 Jul 2026 · 58 min · 27 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Nicole Perlroth warns that AI-enabled cyber exploitation will accelerate “everything, everywhere, all at once” attacks on critical infrastructure and that the U.S. is unprepared. She also details North Korea’s cybercrime and remote-IT infiltration pipeline, plus broader U.S.-China cyber competition and election cybersecurity agency weakening.

Guest backgrounds

Nicole Perlroth is a former New York Times reporter (a decade covering cybersecurity, digital espionage, and sabotage). She is now founder/managing partner at Silver Buckshot Ventures (cybersecurity “moonshot” fund) and author of This Is How They Tell Me the World Ends.

Key claims

“Mythos” (an Anthropic model) can find and chain zero-day vulnerabilities across major OSes/browsers, enabling nation-state-grade attacks by tier-2/3 states. North Korea’s crypto theft and remote laptop farms fund its regime and nuclear program. The infiltration playbook is spreading (including to Iranians). Cybersecurity is increasingly an HR problem.

Notable examples

Sony (North Korea-backed hackers destroyed ~70% of server capacity); Bangladesh Bank/SWIFT theft (~$81M); crypto heists funneling $600M+; Bybit UI trick approving $1B+ transfers; a case where a “North Korean” candidate’s interview referenced a fake hurricane to catch them; 22-person cell applying to 160,000 U.S. jobs in three months.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Introduction to Cybersecurity Concerns

0:00 to 0:41

Learn about the increasing threats from AI in cybersecurity.

“I wrote a book about the humans and what it takes to find these zero-day exploit capabilities.”

Discussion on Cybersecurity Threats

1:15 to 2:00

Explore Nicole's insights on misinformation and cybersecurity threats.

“And she's just always a straight shooter, and I really appreciate it.”

Upcoming Live Taping Announcement

2:00 to 2:41

Kara announces a live taping event in Washington, D.C.

“And one more thing before we get started, if you're going to be in Washington, D.C.”

Upcoming Live Taping Announcement

2:44 to 3:09

Kara announces a live taping event in Washington, D.C.

“Now there's Odoo, the all-in-one, fully integrated platform that actually might help you get it all done.”

Interview with Nicole Perlroth

3:09 to 3:40

Nicole discusses the escalation of cyber threats over the past year.

“When you were on the show just over a year ago, you said you were most concerned about, quote, everything, everywhere, all at once, cyber scenario or multiple simultaneous cyber attacks on critical infrastructure.”

The Mythos Era in Cybersecurity

3:40 to 4:50

Discover what the 'mythos era' means for cybersecurity capabilities.

“Talk a little bit about what's changed in a year.”

Capabilities of New AI Models

4:50 to 6:36

Learn how modern AI can exploit vulnerabilities in major systems.

“The problem is now we're in the mythos era.”

North Korea's Cybercriminal Operations

6:36 to 7:43

Nicole explains advancements in North Korea's cyber operations post-Sony attack.

“And when I asked this red teamer at Anthropic, Nicholas Carlini, who do you worry about the most?”

North Korea's Use of Cryptocurrencies

7:43 to 11:41

Understand how North Korea exploits cryptocurrencies to fund its regime.

“So, you know, they came on the scene with Sony.”

Remote IT Worker Fraud Investigation

11:41 to 13:39

Nicole shares insights on North Korean IT workers infiltrating U.S. companies.

“It's responsible for about half of their total funding.”
Show all 27 chapters

Uncovering 'Laptop Farms' Operated by North Koreans

13:39 to 14:00

Explore the bizarre tactics used by North Koreans to obtain jobs in the U.S.

“So this is American to operate what are known as laptop farms and working for the DPRK, but it's the DPRK that's working their laptops that they set up.”

Uncovering North Korean Cyber Operations

14:00 to 18:06

Learn how North Korean hackers are infiltrating U.S. job markets through deceptive tactics.

“So they confirmed it was a North Korean.”

American Hosts for North Korean Operations

18:06 to 20:38

Discover who the American laptop hosts are and the risks involved with their backgrounds.

“And as they find them, they're firing these people.”

The Consequences of Remote Work Policies

20:38 to 22:46

Understand the implications of remote work on cybersecurity and corporate policies.

“I think one of them is we just take our eye off of North Korea.”

China's Cyber Dominance and AI Threats

23:54 to 28:00

Explore China's advancements in cyber attacks and the implications for global security.

“Let's talk about China and its rise in cyber dominance.”

Disinformation and Data Centers

28:00 to 29:05

Discussion on the use of data centers in disinformation campaigns by Russia and China.

“they really want to be the backbone of AI and AI infrastructure.”

The Impact of Naming and Shaming Cybercriminals

29:05 to 30:29

Exploration of whether the public attribution of cyber intrusions still holds value.

“And I think hopefully we will once the attacks start coming.”

China's Cyber Intrusions and Critical Infrastructure

30:29 to 31:03

Discussion on China's hacking of critical infrastructure and its lack of media coverage.

“So there is, you know, a legitimate question to say, what is the long term benefit really of calling out these operations?”

AI's Role in Cybersecurity Transformation

31:03 to 34:24

How AI is changing both offensive and defensive strategies in cybersecurity.

“I've just decided, okay, I'm going to focus on these issues that I think are super important, but are not getting that kind of mainstream coverage.”

Anthropic's AI Models and Cybersecurity Implications

34:24 to 38:08

Discussion about Anthropic's AI models and their implications for cybersecurity.

“But Anthropic initially released its mythos modeled in April to a limited group of companies for cybersecurity testing last month.”

Balancing Offensive and Defensive Cyber Capabilities

38:08 to 39:34

The necessity of balancing offensive and defensive capabilities in cybersecurity with AI.

“All of these models now have these capabilities, and soon again, the open weight models will too.”

Project Glasswing and AI Policy

39:34 to 42:01

Discussion on Anthropic's Project Glasswing and its approach to AI policy in cybersecurity.

“But I think the big issue here is that, again, we're entering a new era.”

AI's Role in Cybersecurity

42:01 to 44:06

Explore how AI can enhance cybersecurity defenses and policies.

“when we put these models out for the first time, we bias them towards defensive capabilities.”

AI's Role in Cybersecurity

44:23 to 45:24

Explore how AI can enhance cybersecurity defenses and policies.

“Odoo says they're the answer you're looking for.”

The State of U.S. Cybersecurity

45:24 to 54:49

Discuss the impact of governmental changes on cybersecurity leading to elections.

“The Trump administration has weakened CISA, Cybersecurity and Infrastructure Security Agency, CISA, which Trump established actually in 2018 as responsible for election cybersecurity, among other things.”

Bipartisanship in Cybersecurity

54:49 to 56:00

Analyze the challenges and possibilities for bipartisan efforts in cybersecurity.

“Unfortunately, some of these things have become politicized, particularly around the misinformation, disinformation tracking.”

Reflections on Bipartisanship and Cybersecurity

56:00 to 56:45

A discussion about the current state of bipartisanship in relation to cybersecurity threats.

“And when he retired from Congress, he said, I signed up for this, but my family didn't sign up for death threats and swatting.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00I wrote a book about the humans and what it takes to find these zero-day exploit capabilities. If you had asked me, hey, write a sequel and you can make it fiction, make it science fiction, what is the nightmare next chapter of this thing? I would have written a book that didn't look that different from the era we are entering right now, where AI can essentially find these vulnerabilities and turn them on anyone they choose.

0:41Kara Swisher:Hi, everyone from New York Magazine and the Vox Media Podcast Network. This is On with Kara Swisher, and I'm Kara Swisher. My guest today is Nicole Perlroth, a leading expert on cybersecurity and cyber conflict. Nicole spent a decade covering cybersecurity, digital espionage, and sabotage as a reporter at the New York Times for stepping out to become a founder and managing partner at Silver Buckshot Ventures, a cyber moonshot fund investing in cybersecurity companies. She's also the author of one of my favorite books, This Is How They Tell Me the World Ends, about the global cyber arms race. It's a must read.

1:15Kara Swisher:The latest season of our award-winning investigative podcast, To Catch a Thief, exposes North Korea's infiltration of American companies via a pipeline of remote IT labor that's sending hundreds of millions of dollars back to the regime and its nuclear weapons program. The season finale is out this week. I just love Nicole. I think she talks in plain English about some very serious and complicated threats to the United States and most democracies around misinformation, around cybersecurity, around the efforts of this administration to undercut our cybersecurity and more. And she's just always a straight shooter, and I really appreciate it.

1:50Kara Swisher:Our expert question today comes from Dmitry Alperovitch, co-founder of CrowdStrike and the chairman of the Silverado Policy Accelerator, a Washington, D.C.-based geopolitical think tank. So stick around. And one more thing before we get started, if you're going to be in Washington, D.C. today, July 16th, please join us live at the Johns Hopkins University Bloomberg Center for a taping of On. I'll be talking to Gina Raimondo, Kamish Secretary under President Biden and former Rhode Island governor about what AI means for the workforce. And as a special bonus before that conversation, I'll be speaking with Johns Hopkins University President Ron Daniels and the University of Notre Dame President Father Robert Dowd to talk about how universities are approaching AI and workforce issues.

2:32Kara Swisher:You can get tickets and learn more at voxmedia.com slash Kara Swisher Live.

2:41Kara Swisher:Support for this show comes from Odoo. Running a business takes everything you've got, and a lot of the tools out there that are supposed to make your life easier just aren't great at talking to each other, and that means you end up having to toggle between a dozen different apps and services just to keep the lights on. Enough of that. Now there's Odoo, the all-in-one, fully integrated platform that actually might help you get it all done. Thousands of businesses have made the switch, so why not you? Try Odoo for free at odoo.com. That's O-D-O-O dot com.

3:19Kara Swisher:Nicole, thanks for coming on On. Thanks so much for having me. It's so good to be back. When you were on the show just over a year ago, you said you were most concerned about, quote, everything, everywhere, all at once, cyber scenario or multiple simultaneous cyber attacks on critical infrastructure. In a short period of time, we've experienced more geopolitical instability and rapid advances in AI. But so far, we've avoided this worst case scenario. Is that still your number one worry? Talk a little bit about what's changed in a year. Everything's changed. Last year I was saying we were worried about this quote, everything, everywhere, all at once, cyber scenario, based on what we were actually seeing Chinese hackers pre-position in, which to jog everyone's memory, and it's still happening, is water, power, pipeline infrastructure, high-speed rail, aviation, ports, logistics.

4:10That's all still happening. So we had to contemplate this nightmare scenario of what would happen if all of these hackers sort of detonated on the access they have all at once. So it wouldn't just be one colonial pipeline, but hacks on critical infrastructure across the country. I always thought that it was unlikely that they would detonate on all these things at once unless they were making a move on Taiwan and they wanted us to think twice about whether we wanted to support this island 7 ,000 miles away. And that even in that case, they would maybe go for, you know, one water treatment facility and a power grid hack here or there, just flicker the lights on and off.

4:50Okay. The problem is now we're in the mythos era. Explain what that is for people who don't know. So mythos is, you know, this new anthropic model, new-ish at this point, anthropic model that wasn't designed to exploit code. It was actually designed to write code, but as a byproduct, it can exploit code, which means it can find vulnerabilities in every major operating system, every browser, and chain them together into an exploit so it can do things like, and by the way, I interviewed the head red teamer at Anthropic, so I'm a little bit close to the capability, and I said, describe the capabilities that this model has in plain English.

5:37He said, it's the type of thing where I can direct you to a website and gather all your banking activity. I can pull the photos off your phone without you unlocking it. We have found exploits using this model in most major operating systems, most browsers, etc., etc., etc. And these are capabilities that I, you know, the expert as a human would never have found otherwise. The model is finding these. And so the problem is now these models can do what only previously the tier one elite nation state intelligence or their contractors could do.

6:22Kara Swisher:Therefore, and may not have done, they're just using it as a strategic advantage versus they would do it. And the people that can now do it are kind of crazy people, possibly, or just chaos monkeys or whatever. Exactly. And when I asked this red teamer at Anthropic, Nicholas Carlini, who do you worry about the most? He said, well, on some level, the tier ones already have had this capability. You know, obviously, the models will increase their productivity. But you have to worry about these sort of tier two, tier three nation states like Iran, like North Korea, that have never had this capability before, but have done pretty well with just social engineering, are now going to have the ability to break in essentially anywhere they want.

7:10Kara Swisher:So let's talk about your new season of your investigative podcast, To Catch a Thief, which focuses, speaking of chaos monkeys, on how North Korean IT workers have successfully infiltrated major U.S. companies. We're going to talk about mythos more later. But cybercrime is now a key part of the North Korean economy. People may remember the 2014 cyber attack on Sony Pictures carried out by a North Korean government-backed group. Talk about the advancements in North Korea's cybercriminal operations in those years. And in what way does the DPRK influence other adversaries? Because they're sort of the out-front group here.

7:42Yeah. So, you know, they came on the scene with Sony. And I think if I remember, I think it was All Things D that broke that it was a North Korean cyber attack. Yes, that was me. That was me. Yeah. That was Kara Swisher.

7:56Kara Swisher:Yeah, Kara Swisher broke that one. When I was a reporter, back in the day when I was a reporter. Most people remember that attack. But as I kind of say in the podcast, few people remember it for what it actually was. Because most people remember the leaks and sort of the absurdity of all. The dumb arguments between the studio heads over stupid things. Yes, right? Exactly. Yeah. But what they don't really remember is that these North Korean hackers decimated 70 % of Sony's server capacity. You know, no one could get on email. No one could get on their devices. People were using fax machines, pen and paper.

8:31It was hugely destructive. And what the North Koreans learned from that attack is, okay, we can do this. You know, we can get into an organization with social engineering. we can basically map their network, find the crown jewels, and then we can decide what to do with those crown jewels for maximum impact. In this case, it was to embarrass Sony and keep them from releasing this ridiculous movie. The interview with Seth Rogen, which depicted the assassination of Kim Jong-un. So right after Sony, we saw them basically take those same capabilities and deploy them against banks. And we saw them go after one bank in particular, the Bank of Bangladesh, and they were able to, using social engineering for the most part, get into the bank's connection to something called SWIFT, which is essentially like a messaging protocol.

9:24So if you, Kara, want to send me$10 ,000, the bank says, okay, send$10 ,000 from Kara's account here over to Nicole's account here. They were able to manipulate it to essentially get $81 million out of the New York Fed. They were looking for a billion, but they had a few typos, and basically through good luck, they were only able to get$81 million out of the billion. So they learned a lot from that attack. They learned that they could basically use hacking to evade sanctions, to generate the cash that they needed for their nukes program. and they also learned that there were a lot of choke points in the system.

10:06You know, one typo can basically throw off the whole operation. Then, almost like a gift from above, the world handed them crypto. And we have really not paid close attention. I think I, even someone who studies cyber for a living, had not paid very close attention to what North Koreans were doing with crypto. but they have essentially become the masters of the blockchain. We just don't know it yet. What do you mean by that? They started off basically hacking people's private wallets just by social engineering and phishing. But then they really started to study the infrastructure of the blockchain.

10:46And they started pulling off some heists that, to quote Rob Joyce, who used to run the NSA's hacking divisions, are some of the most sophisticated he's seen in his career. They found their way into these bridges that convert, you know, Ethereum into some other kind of cryptocurrency. And they were able to funnel more than$600 million back to their own wallets in one case. In the case of Bybit, you know, the second biggest cryptocurrency exchange, they pulled off a heist that was like David Copperfield-esque. They got the CEO of Bybit to approve what looked like a routine transfer when underneath the user interface, he was actually approving more than a billion dollars in transfers to North Korean wallets.

11:35So this is now funding about half of North Korea's regime. It's responsible for about half of their total funding. They need the money. And if you read the coverage around Xi Jinping's visit to North Korea this year, The Wall Street Journal, the New York Times, they all wrote about, hey, like, we don't know why, but North Korea seems to be doing just fine despite being the most sanctioned nation on earth.

12:03Kara Swisher:So they're getting better and they're using crypto to do so. They had their usual schemes, the phishing, the hacking. But this is a quantum level up. So talk about how did the investigation to the North Korean remote IT worker fraud begin? And just for people who know, last year, Amazon said one of its contractors hired a North Korean as its IT systems administrator. Talk about that. Yeah. So this is super weird. And I started hearing about this about two years ago. You know, some CISOs, some chief information security officers started telling me, you won't believe what happened. We actually accidentally hired a North Korean who had applied as a full stack developer under someone else's identity.

12:46I was like, that's kind of weird. You know, what did they do? The weird thing was, Nicole, they didn't do anything. They were actually just there for the paycheck. So it kind of was just kind of this bizarre, absurd thing. And then I started hearing about major defense contractors having this issue, major ag companies. So it was North Koreans pretending to be someone else in order to get a job. Yes. And in some cases, they are stealing identities to get these jobs. In other cases, they are paying Americans to loan out their identities. Their identity. Yeah, and pass background checks. And they are finding Americans to host their corporate laptop.

13:25So the employer will ship a laptop to this American who gets$100 a month per laptop. And then that American will download some remote app that lets the North Korean remote in. And the North Korea pays them some nominal fee and then is basically able to do what they need to do to do their job.

13:44Kara Swisher:So this is American to operate what are known as laptop farms and working for the DPRK, but it's the DPRK that's working their laptops that they set up. Exactly. And so I started digging into this. And at one point, I partnered with a security firm called Nisos that had been triaging some of these cases for Fortune 100 companies, and then posted a job for an AI developer and ended up getting a response from what they believed was a North Korean. So they confirmed it was a North Korean. Why did they believe that? Oh, it was, you know, all the red flags. It was someone who comes on, and there's a slight delay in their answer.

14:27And there's clearly a language barrier, but then their answer is spoken in perfect English. And it's clear they're using some kind of AI chatbot to answer these questions. And in this case, they actually, because they sort of suspected as much, they brought him back for a second interview. And they asked him questions like, oh, I see you're in Florida. You know, how'd you weather Hurricane George? And there's this kind of delay. And then they say, oh, you know, we did fine. A few branches came down here and there, but we were just fine. And there was no Hurricane George, that kind of thing. Yeah, that's how you catch a thief.

15:04That's how you catch a thief. So they ended up sending him a laptop.

15:07Kara Swisher:Patton Dodgers, but go ahead. No, it's a lot of that. It's like, that's how you catch these guys. It's like, what was your university mascot was one that was tripping him up. My favorite was Say Something Bad About Kim Jong-un, and that usually weeds him out quite quickly. But, you know, in this case, they hired him deliberately, and they sent him a laptop that had spyware on it. And this guy that they hired basically logged into his Discord account. And so they were able to get into his Discord account. And it turns out that's where they were managing their whole backend operation. And it was this entire cell.

15:44Kara Swisher:So the guy was a North Korean, this American laptop farm that did it, or this was a corporation that they were trying to get into? So the security farm hired a North Korean that was using an American to host his laptop in Florida. So they could see through the camera that they were sitting in a basically like container store type closet somewhere in Florida. And then they could they send him something that could cut through his VPN and show that actually he was logging in from China, which is where a lot of these North Korean IT workers are based. And then through this guy's own credentials that he stored in his Gmail account, they were able to get into this Discord channel where they organize their whole cell operations.

16:28And it was one cell of 22 people. But the pertinent thing is they were only able to keep this guy for three months because they couldn't actually pay him because that would be against sanctions. And just in those three months that they had access to this Discord channel, this one cell of 22 North Korean fake IT workers applied to 160 ,000 jobs just in the United States. So they're trying to get infiltrate. And that's when I realized the scale of this. Yeah. The scale of this is insane. And the goal is to steal. Fuck up or steal? The goal is to make a paycheck. So the goal is, initially, when the Mandians of the world would come in and triage these cases, they would look, you know, did they plant malware?

17:12Did they steal IP? Did they steal data? And for the most part, and it was really weird, they're just there for the paycheck. And my understanding was this is basically a way to get a steady form of funding, like almost like their ARR to fund sort of these larger hacking crypto heists that can take a year in some cases of careful planning.

17:36Kara Swisher:Right. So they may not be stealing. They want jobs. And they want to hide themselves. They want jobs. And they're taking like 12 jobs. They could. And that's the thing is now that companies like Amazon is talking about this, Palo Alto Networks is talking about this, CISOs are talking to each other about this because it's really gotten to the point where, as one person at Mandiant told me, I have yet to find a company in the Fortune 500 that hasn't hired a North Korean IT worker. As they're talking to each other, they're looking for these red flags. And as they find them, they're firing these people.

18:11And so these people still have to monetize their access. And we're starting to see some more extortion cases and data theft and that kind of thing.

18:21Kara Swisher:Right. And because eventually that's where it goes. So who are the Americans hosting the laptop farms? Okay. So this was fascinating. I was like, who are these people that are just taking corporate laptops, hosting them in their house? So I wanted to go meet with one of these people. And the only case that we've really heard about publicly is a woman in Arizona named Christina Chapman, who is hosting something like 60 laptops for the North Koreans. And so I was trying to find others. And it turns out a lot of these people have serious criminal records. They're Americans who, for whatever reason, can't get work.

18:58They're posting on a Reddit channel, hey, I'm looking for quick cash. And that's where the North Koreans are finding them. Sometimes they post that they're looking for work on LinkedIn, and that's how the North Koreans find them. But a lot of them have criminal backgrounds, which is why they can't get work, and maybe why they're willing to accept laptops from a total stranger. Yeah, please just put this up and pretend it's you. Yeah. And so for the podcast investigation, I wanted to go meet with one of these people, but their background checks were a little terrifying. But we found one woman in Cincinnati, and I did fly out to Cincinnati and knock on her door, and they let me in.

19:33And it's not like they ever tell these people, hey, we're North Koreans. They make up an identity. In some ways, these people are being scammed themselves. But they come up with some reason why they can't be in the US and they need this person to host their laptop. And some of these Americans that are hosting laptops are vets. Some of them are just people who think they're running a legitimate business. One of them had essentially the words laptop farm on their resumes. But they're just not asking questions about these people who are willing to send them, you know, quick cash, quick crypto to host these laptops.

20:09Yeah. And what I think is really hard to think about is like the pool of those willing Americans is only going to get bigger and bigger as we start seeing more job losses from AI.

20:20Kara Swisher:Yeah, because it's easy money. It's easy money. So just be us. Just let's buy your identity, essentially. We're going to talk a little bit about China and the AI rights and cyber threats in a second. But what was your conclusion from catching these essentially thieves, but really catching these employees, right? Because they're not thieves yet. They're employees. I think it was a few things. I think one of them is we just take our eye off of North Korea. We caricature them, but we should use them as a case study right now because this is the actor that is an early adopter as they were with crypto and the blockchain that is quite persistent, you know, really good at social engineering.

21:01And I have no doubt they're going to be one of the first nation states that pop up in an AI-powered attack. And we can't take our eye off the ball. This is actually the kind of adversary that we should be paying very close attention to. The other thing is this really isn't a cybersecurity problem in many ways. It's becoming one now that they're kind of moving towards extortion, et cetera. It's really an HR problem. and it tells you how little we're actually screening some of these remote workers. Like, I want remote work to stay. I love remote work. I think it's wonderful. I love the flexibility it brings.

21:42It's probably going to be one of the costs of this North Korean operation. I'm already hearing about companies saying, you have to come in. You know, at Amazon, they're like basically ending remote work. There's a lot of companies that said, we have to see you and we have to see for a prolonged amount of time. We have to make sure you're the person we interviewed, that you have the skills that you said you had, and we need to see that in person. Because by the way, this playbook was North Korea's, but it's spreading. And this week, we released the episode where we disclosed that we're starting to find Iranians are now using this playbook and getting jobs.

22:20And they have very different motivations in some cases than the North Koreans. They're more destructive. They're more retaliatory. So this playbook spreading and we kind of just we have to talk about this because we have to talk about how to filter for it. We'll be back in a minute.

22:45it.

Read the full transcript

23:08Kara Swisher:you'll ever need. It's an all-in-one, fully integrated platform that handles everything, CRM, accounting, inventory, e-commerce, HR, and more. No more app overload, no more juggling logins, just one seamless system that makes work easier. And the best part, Odoo replaces multiple expensive platforms for a fraction of the cost. It's built to grow with your business, whether you're just starting out or already scaling up. Plus, it's easy to use, customizable, and designed to streamline every process so you can focus on what really matters, running your business. Thousands of businesses have made the switch, so why not you?

23:43Kara Swisher:Try Odoo for free at odoo.com. That's O-D-O-O dot com.

23:54Kara Swisher:Let's talk about China and its rise in cyber dominance. You mentioned them earlier. For at least the last decade, China has targeted U.S. telecom companies, notably the expansive the salt typhoon attacks. China-backed hackers have also infiltrated critical infrastructure, including water transport and grid networks. You've talked about this being the era of, quote, mutually assured digital destruction. But it sounds like China's gaining advantage in cyber dominance. Talk a little bit about the case. This is the argument, of course, all of Silicon Valley is making. And others say, no, it's not as much.

24:25Kara Swisher:But give me your assessment of where we are and if they have the upper hand. And if so, what are the consequences? When I first started covering Chinese cyber attacks against the New York Times, for instance, a decade ago, it was brazen, but it was phishing. You know, it was loud, but it was successful. You know, some people called them the most polite hackers in cyber because they'd almost announced their presence. As we started outing some of these campaigns, they really went underground. And I think really the up-leveling moment was when they started using their authoritarianism to their advantage.

25:00They basically created a series of new laws that said, hey, if you find a vulnerability, you have to give the state right of first refusal. And all these Chinese hackers that I used to see at the big hacking competitions that would show how to hack into a Tesla or an iPhone or Android stopped showing up on state's orders pretty much. All that knowledge, all that skill started funneling directly to the state. And we started seeing some really significant up-leveling and sophistication in some of these Chinese operations, like Salt Typhoon. Chinese state operations. Exactly. And these are much harder to defend against.

25:43We started seeing them come for security devices. We started seeing them find zero days, vulnerabilities no one knew about, using those in the course of their operations. And we're catching them in not only our back-end telecom infrastructure, but in these critical entities like water and power.

26:03Kara Swisher:But their capabilities, you know, U.S. and China are locked in this global AI arms race that has experts on both sides concerned if the two nations fail to cooperate, right? Obviously, Anthropoc and OpenA are accusing China of copying their AI systems through distillation. And the Trump-Xi summit in May ended without any meaningful agreements on AI. I mean, the biggest argument from Silicon Valley is we must do all these things without any regulations in order to fight the Chinese. Most people that I think are intelligent say we've got to cooperate with them in some way. But is there a realistic chance of cooperation between the U.S.

26:38Kara Swisher:and China on AI? Should it happen? And what do you make of the arguments of people, you know, in Silicon Valley are like, you know, it's the Xi or me argument kind of thing that they try to pull? You know, we are locked in this very dangerous game of chicken. And I wish that we had an entirely new generation of technological diplomats that could sit down with Xi and say, hey, you know, none of us want the world that we're crashing towards. But I am close to people who've had similar conversations with China on hacking for years, on fentanyl, more recently on Volt Typhoon, these hacks of our critical infrastructure.

27:26At one point, one of the people I interviewed last season when we were focused on China said they were tasked by the Biden administration to go to China and propose that we set up red lines just around hacking water treatment facilities, water systems, civilian water systems. And their counterparts in China said no. So I don't know if it has changed now that we are slightly ahead on AI, but for how long are we ahead? I think that the decision to release DeepSeek as an open-weight model was intentional. they really want to be the backbone of AI and AI infrastructure. And there's a really interesting report that came out last week that the New York Times covered from a startup called Aletheia, where they looked at some of the disinformation campaigns coming out of Russia and China right now.

28:22And they are latching onto data centers as an American culture war. I think in part in China's case, China wants to basically play up some of the fights around nimbyism and environmental concerns and all of the legitimate concerns we have around data centers in terms of water use, energy use, contamination. They want to use that as a wedge issue so that we don't have the data center infrastructure in the United States that they own that.

28:49Kara Swisher:Well, it's going into space, Nicole. That's right. That's right. Yeah. I can't wait for that one. I got to say, I'm with Sam Altman on this one. But anyway, at this moment in time, All I'm saying is I wish we were living in a different world where we could actually sit down with them and have these conversations. And I think hopefully we will once the attacks start coming. But right now I am sort of the, you know, ye of little faith on this issue. Every episode we get a question from an outside expert here is yours. Hi, Nicole. Your friend Dimitri Alperovic here, co-founder of CrowdStrike and now chairman of Silverado Policy Accelerator.

29:26Kara Swisher:As you know, I spent a good chunk of my career putting names and faces on the hackers behind cyber attacks, because I believe that naming and shaming them would deter them and mobilize collective government actions against them. From where you sit, do you think that public attribution of cyber intrusions is still important, or have we become so accustomed and numb to it that it no longer serves any purpose? Thank you. Love, Dimitri. You know, the naming and shaming, I thought, had a big effect. And in some ways it did. We actually saw China go quiet. The Obama administration reached an unprecedented deal with China for a while that we would cease, well, really, they would cease hacking for intellectual property and trade secrets.

30:11And we saw those drop off for about a period of 18 months. But that was during the Obama administration. In came Trump, kind of tossed the tables over, and we saw that resume. And when it resumed, it resumed in a much more sophisticated, well-organized, stealthy way. And so in retrospect, all of that naming and shaming that made them stop actually, I think, just sent them further underground. So there is, you know, a legitimate question to say, what is the long term benefit really of calling out these operations? I think we have to, you know, I think the fact that China is pre positioning itself in some of our most critical infrastructure is worthy of almost daily national press coverage, and it hasn't gotten that, which is why I'm doing this podcast.

31:01in the first place. I've just decided, okay, I'm going to focus on these issues that I think are super important, but are not getting that kind of mainstream coverage. China's hacking of critical infrastructure being one of them. I mean, I think it would be a bizarre world if we were catching these Chinese nation state hackers inside our civilian water systems. And for whatever reason, saying, oh, it's just not worth attributing it to China. But Dimitri has a great point, which is we are sort of becoming numb to this. And there's been so little action and there is really no deterrence.

31:38Kara Swisher:You mentioned mythos at the beginning. Let's talk about Anthropic and its ongoing tensions with the US government. Talk about how AI has transformed cybersecurity. This is something you had written about. It's for Stuxnet and everything else. So talk about how it's transformed for both offensive and defensive purposes. AI in the beginning, you know, it's a really useful social engineering tool. Find me a useful target, craft a message in perfect English. In some cases, create an audio deepfake of someone's voice that this person legitimately knows, like a CFO of a major enterprise, and ask them to basically ask someone in their accounting department to make a wire transfer.

32:17All of those things are things that we are seeing. And we are seeing video deepfakes too. We're seeing North Koreans use deepfakes in some of these interviews. Now we're entering a new phase, which is AI is giving hackers this tremendous advantage to pull off everything I just mentioned at scale. It's also giving them the skills that they previously didn't have, that previously were just the purview of these tier one nation states like NSA, you know, U.S. is NSA and GCHQ, Israel, China, perhaps, Russia, perhaps. It's throwing those skills in the laps of cyber criminals, of these tier three nation states like North Korea, like Iran.

33:04And I think we are about to enter what is truly the everything, everywhere, all at once cyber scenario, which is anyone who has any interest in hacking you will now have the tools to do so, whether that is me pissing off North Korea because of a podcast or Sony putting out a movie or anyone that just has some dark interest in watching the world burn will now have these capabilities. And all of them will come at us at machine speed. So on offense, I think it's very clear that AI will give the bad guys the advantage, the offensive advantage. The hope is, though, that AI will also help us defensively to do the things that we with our puny human minds were never able to do before, like write secure code, handle configuration, ensure that we have multi-factor authentication turned on at scale, make sure that our vendors at least interrogate our vendors to make sure that they're not our biggest weak points.

34:09These are things where AI could create tremendous up-leveling on defense. I think it's just a question of what is the delta between where we are now.

34:19Kara Swisher:And of course, there's this infighting. To me, a lot of what has been happening with the Trump administration is an inside Silicon Valley beef. But Anthropic initially released its mythos modeled in April to a limited group of companies for cybersecurity testing last month. The Trump administration abruptly banned the foreign use of Anthropic's two most powerful models, mythos and fable five. Just over two weeks ago, the Trump administration and Anthropic reached agreements to restore access. Talk a little bit of what's happening here, what's happening internally, because a little bit is, again, this beefing among Silicon Valley rivals, really.

34:53Kara Swisher:And an example of that is Anthropic suing the Trump administration after the Pentagon declared it a supply chain risk. I think that was Emile Michaels doing. He's the undersecretary for research and engineering. Anthropic CEO Dario Amodi went back and forth for months with Emile over safety guardrails and the Pentagon's use of AI. Emil famously was fired from Uber for a bunch of nefarious actions that he has denied. Talk about what's happening here overall and how does it end with the Pentagon, with the White House and everybody else? Well, I think it's fair to call this a giant shit show. I don't dispute anything you just said that I think it comes down to beefing and who's kissed the ring and who hasn't adequately kissed the ring.

35:36but man, we have real supply chain risks in the United States, many of which I've called out in my reporting. TPLink routers were one, DeepSeek is one. These are the real supply chain risks. So I think it says a lot that this administration went for Anthropic, I think because of these conversations between Pete Hegseth, who I went to college with, and Dario. Oh, wow, how was that? over. I think they both actually spent some time at my alma mater. Anyway, no, Pete Hexeth, he was famous when we were in college for being part of this right wing organization that put out this magazine with an owl on the cover in crosshairs and owl stood for organization of women leaders.

36:26So he's always sort of been like this. He's been a charmer for a long time. Yeah. Yeah. Anywho, I think this is why, and you've covered this brilliantly, this is why we saw Tim Cook show up with the golden statue. We saw everyone and their wives and mothers show up to the White House for the inauguration. This is what they're hoping to avoid. and in this case apparently Dario didn't play the game and they are where they are now you know it's amazing to me to have watched Anthropic do what I think was the responsible action to withhold this model once it saw what its cyber exploitation capabilities were and then to watch David Sachs sort of disparage it on Twitter and I think either in an interview with Politico where he said this is all marketing, essentially.

37:23He was our AI czar. He's no longer our AI czar. But I had the same questions. How much of this is real? How much this is marketing, which is why I went and interviewed Nicholas Carlini, the red teamer at Anthropic. If you listen to that interview, it's clear this guy doesn't have a marketing bone in his body. He's truly just a hacker's hacker who was testing the models to see what they're capable of and came away wide-eyed at what these models can do. And I think Anthropic did the right thing. Now, coming back to the previous question on offense and defense, the best thing we can do defensively in this moment is take Mythos, take Fable, take every model from every major frontier lab, test its exploitation capabilities.

38:07Including the new chat GPT, correct?

38:09Kara Swisher:There's a new one. Exactly. And Gemini. All of these models now have these capabilities, and soon again, the open weight models will too. And our best defense is to take them, aim them at ourselves, and see where we are vulnerable and move very quickly to eliminate those inroads and kill paths. And so when you pull Mythos or when you prevent our closest allies from having access to those models, from being able to essentially pen test themselves with these models, test where they're weakest, it's a big deal because this is our greatest hope right now in terms of cyber defense, that we can use these models to test ourselves.

38:51And my understanding is that, you know, Mythos may still have the best cyber exploitation capabilities, but these other models are not far behind. And I don't know what the long-term play here is.

39:04Kara Swisher:They're not far behind. They're not far behind. Now, just for people to know, David Sachs, when he was repeatedly warned that any sort of AI regulation could cost the U.S. in its lead race against China, he's accused Anthropik of, quote, running a sophisticated regulatory capture strategy based on fear mongering. And this is what's influencing the Trump administration, this frenzied approach to lack of AI regulation in any way, or cooperation, which is more what you're saying here. Yeah, that's right. And I think Anthropic has sort of done a good job doing some quiet education around some of these issues with the administration.

39:40Maybe that's why they backed off. But I think the big issue here is that, again, we're entering a new era. You know, I wrote a book, it took me seven years, about the humans and what it takes to find these zero-day exploit capabilities, these vulnerabilities that only they could find. And the market that existed from governments to buy these from these hackers and use them in their offensive operations. And these were the best of the best.

40:08Kara Swisher:This book was This Is How They Tell Me The World Ends, correct? Yes, This Is How They Tell Me The World Ends. And in retrospect, what that book was about was about scarcity. It was about the few people who could find these vulnerabilities and then create the code to exploit them in systems like our iOS, iPhone operating system so that they could basically turn these things into ankle bracelets. If you had asked me, hey, write a sequel and you can make it fiction, make it science fiction. What is the nightmare next chapter of this thing? I would have written a book that didn't look that different from the era we are entering right now, where AI can essentially find these vulnerabilities that, again, were just the purview of these advanced hackers and nation states and turn them on anyone they choose.

40:56And that's the era we're walking into. And we can't do this, like, game. Yeah.

41:01Kara Swisher:China just said that it's ZAI already matched mythos and cybersecurity. And then, of course, all the others will match what Mithos can do relatively quickly. Right. These are all sort of like momentary delays towards the inevitable. Yeah, they just were the first to get there to say, oh, dear, where you're all headed. But to your earlier point, like, we don't have time for the beefing. No, we don't have time. But guess who likes to beef? People with self-interest. I'm not saying David Sachs is self-interest, but I think I just said that David Sachs is self-interest. I think it's all a Silicon Valley beef.

41:32Kara Swisher:And I don't think they're interested in national security at all, at all, at all. Like in so many ways, it's something else happening here. But speaking of which, with Carlini, this research scientist in Anthropic, let's listen to what he has to say about whether we're in for stability or chaos. Let's listen to him talk about it. I think the primary thing that determines how this plays out is how good the models get and whether or not they favor defenders or attackers more. And I feel like this is mostly a question of nature. and we can try and balance it one way or the other by making sure that, you know, when we put these models out for the first time, we bias them towards defensive capabilities.

42:11But I don't feel like there's any particular action that this week we can take that will determine what happens here.

42:18Kara Swisher:Are we past the point of policy or an ability to handle these risks that AI poses to cybersecurity? You know, I think that actually what Anthropic did with Mythos, essentially withholding it, they announced this project, Project Glasswing, where they were going to give the model to a certain subset of companies, mostly cybersecurity companies and banks, so that they could test their own systems and basically get ahead of the threat that was going to come. it's not perfect there will be jailbreaks etc but i think it's actually a taste of somewhat good policy that we essentially before we kind of throw these capabilities into everyone's lap we essentially test them against ourselves and that way at least have a chance of defending ourselves you know there are companies coming to market that deploy agents that mimic these adversaries that you can test against your systems.

43:16And not just the usual ways, but with social engineering and that kind of a thing. So there are, I think, ways to essentially uplevel ourselves here. And I think the best way is probably something that looks a lot like Glasswing. And I don't think that it's a bad idea to essentially force the frontier labs to red team these systems and give companies, particularly in critical infrastructure, advanced access to these models so that they can up-level themselves as well. But I have now been in cybersecurity for almost 20 years, and the state of our cybersecurity, particularly at critical infrastructure entities, is terrible.

44:05We'll be back in a minute.

44:20Kara Swisher:Support for this show comes from Odoo. There's an endless supply of software out there that promises to streamline your workflow. That may be true for a specific aspect of your business, but if you need one app for accounting, one for inventory management, another for sales, how streamlined can your workflow actually be if you have to be the middleman between them? Odoo says they're the answer you're looking for. The only business software you'll ever need. Odoo can be your one-stop shop for CRM, accounting, inventory, e-commerce, HR, and more. Plus, it's super customizable and easy to use out of the box.

44:52Kara Swisher:And the best part? They say not only can they replace multiple applications, but they say they'll do it for a fraction of the cost. Whether you're just starting out or already well on your way to scaling, Odoo wants to help you put the clutter aside so you can do what you set out to do when you started your company. Thousands of businesses have made the switch, so why not you? Try Odoo for free at odoo.com. That's O-D-O-O dot com.

45:23Kara Swisher:Let's go into cyber threats, the U.S. ahead of the midterms. The Trump administration has weakened CISA, Cybersecurity and Infrastructure Security Agency, CISA, which Trump established actually in 2018 as responsible for election cybersecurity, among other things. He also shut down an FBI task force intended to fight foreign influence in elections. The New York Times has reported these changes are part of a larger effort to affect the outcome of midterm elections. Talk about diminished cybersecurity agencies will impact election officials, voters and potentially the results. And that's that's not with the other stuff that they're doing.

45:56Kara Swisher:They're also getting these bipartisan commissions that help elections and give them good information. They're trying to break them down. Talk a little bit about that state when you're saying it's a shit show, essentially. So I should disclose here that when I left the New York Times, I left in part because I joined the essentially the advisory board at CISA, which is the cybersecurity and infrastructure security agency under Biden. They wanted a journalist on that committee. They asked me. I said yes, but of course that meant stepping out of journalism because you can't be sort of inside the tent and reporting outside the tent at the same time.

46:33And it was incredible because I joined just before Russia invaded Ukraine. And a lot of CISA's efforts during that timeframe went towards getting American companies to get their shields up and also working with Ukraine cyber defense entities and other allies to help Ukraine. And it was an incredible effort. And one day that should be my next book, because it really was a model for how public-private partnerships can come together in a meaningful way. And, you know, I walked into that advisory role with basically zero faith in the federal government doing anything on cybersecurity. And I left truly impressed at what they were able to build in such a short time.

47:14So imagine my dismay when, you know, by the way, I got a letter saying, due to the misuse of resources, you are no longer on this committee. Like, I don't think I ever got paid a single dollar. In fact, I think I like forgot to expense my, you know, economy back at the plane.

47:32Kara Swisher:So Elon's always trying to save us money. Elon's always trying to save us money, mostly so he can take it for himself. But go ahead. So, you know, they eliminated that committee fine, but then they started hollowing out the actual agency, I think, in large part because of Chris Krebs coming out in the 2020 election and calling it the most secure election in history. But yeah, they took out some of the best. Those are people who were recruited during that time that I served on that committee who were probationary, which is just like, that's what happens when you take these jobs. No matter who you are or how good you are, you're just probationary until one day.

48:10Kara Swisher:As long as you're not North Korean, but go ahead. Yes, exactly. Way to bring us full circle. So anyway, they basically fired all those people. And now we have a hollowed out cyber defense agency, and it's kind of free reign. Now, I should give credit to the FBI that I think has really stepped up and the FBI cyber division is incredible. And they are, you know, still doing what needs to be done to sort of out some of these Chinese operations on our critical infrastructure. And they're, you know, getting on top of this North Korean issue as well. And those are really good people. I will say that the people I have met in the FBI cyber division are fantastic.

48:46But they are shouldering a lot. Patel doesn't know about them yet. Yeah, and hopefully he doesn't listen to this because I'd like to keep it that way. But yeah, it doesn't make any sense. You know, if you truly care about national security, well, cybersecurity is national security. This is where our adversaries, especially adversaries that know they can never match us militarily, are investing. and you know it might be the case that you don't care if russia tries to interfere with our elections because maybe you think that they're on your side but they're not the only game in town you know there is china there is iran there are other adversaries there are a lot of good reasons why we should all care about cybersecurity of our critical infrastructure.

49:41And it's getting to the point where we're just sort of waiting for that everything everywhere, all at once attack era to start, but it's coming. I mean, it's coming without human fatigue from machines across all time zones. And it hasn't happened yet, but hopefully once it does, we'll see just how short-sighted these decisions were.

50:02Kara Swisher:The other side of that, of course, is there are real threats from China and Russia. And you talked about exploiting the public debate around data centers is so division through AI-generated images on social media. I do think it's a real grassroots situation and it's not being organized by Russia and China. People on the ground are really upset about these data centers. But there is an element of foreign influence campaigns everywhere in every aspect of America now. How prepared are U.S. cyber officials to combat this level of misinformation ahead of midterms? the stuff that's there already. Although some of the misinformation is from the government itself, by the way.

50:38Kara Swisher:So it's kind of a weird situation we find ourselves in. Yeah, I would say it's the weirdest situation that we've been in since I started studying this stuff. We are in no way prepared, is my understanding, for some of the coordinated misinformation campaigns that will come at us full throttle in this election. You know, it wasn't just CISA, it was the State Department. Their bureau that basically monitored these threats was completely dismantled. And we saw what happened, I think it was last week, where they essentially fired everyone on this election commission that their whole job is ensuring free and fair elections at the state level or helping states offer free and fair elections.

51:19So I'm pretty concerned. This is coming at us, though. It's not just Russia. What could they do?

51:25Kara Swisher:Give me an example. What could any of these sort of nefarious entities do? So my nightmare scenario has always been that we saw in 2016 that Russia got access to the voter rolls. And they didn't do anything, right, was our understanding. But they got access to them. And it was clear that they were sort of mapping our election infrastructure. And the sort of consolation that I would hear at the time was, well, you know, thank God our elections are so decentralized. They could never hack this thing at scale. But I think what we have all learned over the last 12 years is our elections come down to a few purple states and a few counties in those purple states.

52:15And my nightmare scenario is you would pull off a hack where you'd essentially go to those voter rolls and mark the people that might vote for the candidate that you don't want to win as not registered. You would change their registration status. So they would show up to vote on election day and they'd be told, oh, you're not registered. You could think of it like a denial of service attack against sort of key people in these key counties in a US election. And when we're not paying attention to some of these operations, that's really hacking. That's not disinformation. It's more that we've dismantled disinformation, I'm assuming, hoping.

52:57But you could use AI to figure out the 300 key people here. Well, it's, you know, what I just described as a hacking campaign, but you could also imagine a disinformation campaign aimed at those people where you wouldn't have to change their registration status or leave those fingerprints, but would just send them some kind of notice to say, hey, you're not registered. And maybe they wouldn't show up on their own volition. And then how do you go back and track that? And there are all sorts of tools that are being thrown in people and nation states lapsed to do that. So when you don't have people whose specific job is to track these campaigns at the State Department, at CISA, et cetera, et cetera, et cetera, that's very troubling.

53:39Kara Swisher:Yeah, it's almost like they want to change elections. It's interesting. Anyway, last question. Last year on this podcast, you said that cybersecurity remains a bipartisan issue, despite all this nonsense from Trump especially. You said it remains a bipartisan issue. Is that still true? Do you feel that or not at this point? Because the Trump administration is trying to put his finger on the scale. It's very obvious through these firings and demotions or, you know, just disintegration of these units that matter. So, you know, clearly at the White House, it's been politicized. It's no longer a bipartisan issue.

54:15every level below that though. I've met with staffers for senators from both sides, same with Congress. There's a lot of collaboration that happens in cybersecurity, thank God, not just among political parties, but among competitive companies. This is one space where the chief information security officers are constantly talking to each other about the threats that they're seeing. And they're even organized by industry where they get together and talk about the threats that they're seeing. And that level of threat intelligence is only increasing now with AI and hopefully will continue to scale.

54:49Unfortunately, some of these things have become politicized, particularly around the misinformation, disinformation tracking. And Elon made it a huge issue. The Twitter files were basically used to validate this conspiracy theory and validate what happened next, which was sort of the destruction of the teams that track these issues. And even worse, we saw the people who worked on these issues at Twitter, et cetera, become targets for death threats, et cetera. So it's like, who wants to raise their hand to take these jobs anymore? You know, we saw what happened with Chris Krebs. So who does? Well, you know, it's depressing.

55:32It's not just cybersecurity. You know, I was calling my friend who I think is infinitely qualified to run for Senate in Maine right now. And if he was to stand up and raise his hand and say, I'm running, I think he could win. But he won't because he's looking at past data that says there's a narrow path. But more than that, it's just like, if you have a nice life, why put yourself through that right now? And it is happening on both sides of the aisle. I also went to college with Mike Gallagher. And when he retired from Congress, he said, I signed up for this, but my family didn't sign up for death threats and swatting.

56:06To me, that's almost like... Very smart guy.

56:08Kara Swisher:Very, too bad he left, right? Another person who was very sharp and bipartisan. But do you have any hopes for bipartisanship, I guess, at this moment? I think someone has to go. And I think until then, it's just going to get worse and worse and worse. Well, we get an attack. Or we get an attack that's devastating. Yeah. Well, on that note, Nicole, I appreciate it. This is a great conversation. I really appreciate it. You bring all this sunshine to our world. Right. Just a ray of sunshine. Ray of cyber sunshine. Thank you so much, Nicole. Oh my gosh. Thank you so much, Cara. Good to see you.

56:53Kara Swisher:Today's show was produced by Michelle Alloy, Catherine Millsop, Madeline LaPlante-Duby, and Kaylin Lynch. Nishat Kerwa is Vox Media's executive producer of podcasts. special thanks to Julia Sharp Levine Bradley Sylvester and Dave Shaw our engineers are Fernando Arruda and Rick Kwan and our theme music is by Trackademics if you're already following the show you won't be recruited to join a global hacking crime syndicate if not your linen closet would make a great laptop farm go wherever you listen to podcasts search for On With Kara Swisher and hit follow thanks for listening to On With Kara Swisher from Podium Media New York Magazine the Vox Media Podcast Network and us we'll be back on Monday with more

57:37Kara Swisher:Thanks again to Odoo for supporting this show. Odoo wants to be your ultimate all-in-one, fully integrated platform to handle everything. Seriously, everything. Inventory, CRM, accounting, HR, and much more. No more shopping around or settling for expensive services that can only handle a fraction of your business. Thousands of businesses have made the switch, so why not you? Try Odoo for free at odoo.com. That's O-D-O-O dot com.

From the publisher

AI is giving cybercriminals capabilities once reserved for elite hackers and powerful nation-states. Cybersecurity expert Nicole Perlroth joins Kara to explain why she fears we’re inching closer to an “everything, everywhere, all at once” wave of cyberattacks.

Perlroth reveals what she learned in reporting the latest season of her podcast, "To Catch a Thief: North Korea on Our Payroll," a deep dive into North Korean operatives who use stolen identities and American “laptop farms” to land remote jobs at major U.S. companies and funnel money back to the regime and its nuclear weapons program.

She also examines China’s growing cyber capabilities, threats to critical infrastructure and what Anthropic’s Mythos model means for cybersecurity. Plus: how the Trump administration’s dismantling of cybersecurity and election-security programs could leave the U.S. vulnerable ahead of the midterms.

Questions? Comments? Email us at on@voxmedia.com or find us on YouTube, Instagram, TikTok, Threads, and Bluesky @onwithkaraswisher.
Learn more about your ad choices. Visit podcastchoices.com/adchoices

More from On with Kara Swisher

All 139 episodes
The Cyberattack We’re Not Ready ForOn with Kara Swisher · 58 min
Listen in VO