
RSA recap, the LiteLLM breach, and the quest to fix AI agent security
Source: YouTube · IBM Technology · published Apr 1, 2026 · 48:36
IBM security leaders and HashiCorp's Field CTO explain why organizations need mature identity management as a prerequisite for agentic AI adoption, comparing it to a roller coaster height requirement.
Key Takeaways:
• Organizations must first discover and manage all existing identities before securing AI agents—the baseline maturity required for AI adoption 0:00
• Agentic AI security requires workflow isolation, not just identity controls—agents shouldn't directly call other agents to prevent self-escalating privilege chains 1:30
• IBM and HashiCorp's Security Lifecycle Management uses Verify for human identity and Vault for just-in-time non-human credentials with session-based lifecycle 5:00
• RSAC 2026 showcased agentic AI moving from concepts to working demos, but mostly as narrow point solutions lacking orchestration 12:00
• SANS ranked AI-generated zero days as the top 2026 threat—natural language has become the most dangerous programming language, lowering the barrier to entry for attackers 18:00
• The LightLLM breach demonstrated cascading supply chain risk when attackers compromised the Trivy scanner to poison the library 25:00
Organizations rushing into AI without proper identity hygiene risk catastrophic breaches—security lifecycle management is a prerequisite, not an afterthought.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
You think of it as like getting onto a roller coaster. Like, you have to be this tall to get, you know, I've got to be 4ft tall in order to get onto the roller coaster. You have to be this tall to AI. All that and more on security Intelligence. Hello and welcome to Security Intelligence, IBM's weekly cybersecurity podcast where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your host, Matt Kaczynski. And even though this episode is coming out on Fool's Day, we're all deathly serious here about cyber security. Joining me today, Suja Vison, Vice President, security products Dave McGinnis, VP, Senior Partner, Global Cyber Threat Management. Jeff Croom, distinguished engineer, master inventor, data and AI security, and our special guest st…