AI, Vulnerability Management & The Future of GRC Engineering

In this episode of the Distilled Security Podcast, we dive into AI-driven vulnerability management, a massive breach hitting 9,000 educational institutions, and the future of GRC engineering, including a live preview of what autonomous compliance agents actually look like in practice. 🔹 AI & Vulnerability Management — Why the next 6–18 months will be a patching crisis, how AI models are accelerating zero-day discovery, the operational reality of back-to-back criticals, surge scenario planning, burnout risk, and Microsoft's M-Dash orchestrated agent approach 🔹 The Canvas/Instructure Breach — 275 million records exposed, finals week disrupted across 9,000 universities, a rumored $10M ransom negotiated by the SaaS provider, the Shiny Hunters connection, and what this means for critical infrastructure concentration risk 🔹 GRC Engineering Meets AI—Deterministic vs. non-deterministic testing explained, why auditors can't rely on AI-generated evidence, autonomous agents with segregation of duties, the Episky 2.0 platform preview, and the emerging role of the "orchestration conductor" in security teams 🥃 Spirit Review: Heaven Hill Grain to Glass (DSP KY-1) ⏱️ Timestamps 00:00 – Intro & Topics Overview 01:27 – AI & The Coming Vulnerability Surge 07:00 – Patching Windows, Burnout & Operational Reality 16:40 – Surge Scenarios, Fix-It Weeks & Recommendations 21:20 – Microsoft M-Dash: Orchestrated Agent Scanning 25:56 – The Canvas/Instructure Breach Breakdown 33:18 – Critical Infrastructure & Third-Party Concentration Risk 47:00 – Black Kite 2026: Third-Party Breach Report 53:11 – Spirit Review: Heaven Hill Grain to Glass 57:07 – BSides Pittsburgh 2025 Update 1:04:01 – GRC Engineering Meets AI 1:19:00 – Deterministic vs. Non-Deterministic Testing Explained 1:25:00 – episki 2.0 Platform Preview 1:47:00 – AI Segregation of Duties & Three Lines of Defense 1:53:00 – The Orchestration Conductor: A New Security Role 2:02:31 – Outro & Wrap-Up 🎙️ Hosts Justin Leapline – @justinleapline Joe Wynn – @wynnjoe Rick Yocum – @rickyocum 📬 Send Us Your Questions! [email protected] 🌐 Connect with Us Website: distilledsecuritypodcast.com X: @DisSecPod Email: [email protected] 👍 Like, comment, and subscribe for monthly security and compliance insights.

2 Years, 24 Episodes & The State of Security in the Age of AI
▶︎

2 Years, 24 Episodes & The State of Security in the Age of AI

My worst video ever. Please hang in there! Unfortunately, this is our reality ✝️❤️
▶︎

My worst video ever. Please hang in there! Unfortunately, this is our reality ✝️❤️

Ankit Panda on extended deterrence and South Korea’s strategic future — Ep. 134
▶︎

Ankit Panda on extended deterrence and South Korea’s strategic future — Ep. 134

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

#AuditTuesday - Designing the Secure Data Center - ZeroTrust w/ EdgeRealm.ai and YouAttest
▶︎

#AuditTuesday - Designing the Secure Data Center - ZeroTrust w/ EdgeRealm.ai and YouAttest

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source
▶︎

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

Historian Timothy Snyder on ENDING Trump Nightmare FOR GOOD | PoliticsGirl
▶︎

Historian Timothy Snyder on ENDING Trump Nightmare FOR GOOD | PoliticsGirl

Hold the Line Update
▶︎

Hold the Line Update

🔴 Jun 22's Top Cyber News NOW! - Ep 1158
▶︎

🔴 Jun 22's Top Cyber News NOW! - Ep 1158

Place your brain in the frequency of wealth, prosperity and total abundance - Attraction Law
▶︎

Place your brain in the frequency of wealth, prosperity and total abundance - Attraction Law

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit
▶︎

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

AI Is Creating A Rare Opportunity For Investors. How Jim Roppel Is Playing It. | Investing With IBD
▶︎

AI Is Creating A Rare Opportunity For Investors. How Jim Roppel Is Playing It. | Investing With IBD

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!
▶︎

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

Inside the Mind of Anthropic CEO Dario Amodei | The Circuit | Extended Interview
▶︎

Inside the Mind of Anthropic CEO Dario Amodei | The Circuit | Extended Interview

Tufayl ibn Amr (ra): The Hidden Legend | The Firsts | Dr. Omar Suleiman
▶︎

Tufayl ibn Amr (ra): The Hidden Legend | The Firsts | Dr. Omar Suleiman

Building an AI Dark Factory:  A Codebase That Writes Its Own Code, Live
▶︎

Building an AI Dark Factory: A Codebase That Writes Its Own Code, Live

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

JavaScript Tutorial For Beginners | JavaScript Training | JavaScript Course | Intellipaat
▶︎

JavaScript Tutorial For Beginners | JavaScript Training | JavaScript Course | Intellipaat

Power Automate Tutorial ⚡ Beginner To Pro [Full Course]
▶︎

Power Automate Tutorial ⚡ Beginner To Pro [Full Course]

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan
▶︎

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan