Harriet Farlow (HarrietHacks)
The AI Security Podcast
I missed the boat in computer hacking so now I hack AI instead. This podcast discusses all things at the intersection of AI and security. Hosted by me (Harriet Farlow aka. HarrietHacks) and Tania Sadhani and supported by Mileva Security Labs. Chat with Mileva Security Labs for your AI Security training and advisory needs: https://milevalabs.com/ Reach out to HarrietHacks if you want us to speak at your event: https://www.harriethacks.com/
Author
Harriet Farlow (HarrietHacks)
Category
Podcast website
Latest episode
May 27, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Explore the future or retreat from the present: a lecture by Jack Clark 27.05.2026 22:53
This week I discuss a lecture by Jack Clark, check it out here. And check out his newsletter Import AI. https://www.youtube.com/watch?v=8zIcP5WlShw
Claude Mythos and Project Glasswing 17.05.2026 22:19
This week we're finally delving into Claude Mythos and Project Glasswing! We discuss both the technical and geostrategic challenges, and what it means for the future of AI security. The announcement: https://red.anthropic.com/2026/mythos-preview/ Glasswing: https://www.anthropic.com/glasswing AISI: https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities And if...
How to get hired in AI security 22.03.2026 25:39
If you’re trying to break into AI security , it can feel confusing — do you need to be a machine learning expert, a cybersecurity professional, or both? In this episode, we break down practical tips for getting hired in AI security, from the skills that actually matter to the types of projects and experience that can help you stand out. We discuss how to build relevant expertise in areas like adve...
getting talks accepted into conferences! tips and tricks 25.01.2026 9:31
Want to give a great conference talk (and not bore everyone to death)? In this episode, I share practical tips for giving a strong conference talk — from structuring your idea to actually delivering it on stage. #PublicSpeaking #Conferences #CFP #TechTalks #Cybersecurity #AI
Do we need to secure model weights? 18.01.2026 36:58
In this episode, we dig into model weight security — what it means, why it’s emerging as a critical issue in AI security, and whether the framing in the recent RAND report on securing AI model weights actually helps defenders and policymakers. We discuss the RAND report Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models — exploring its core findings, including how model weig...
Model Context Protocol and Agent 2 Agent 🤖🕵️ 11.01.2026 28:29
In this episode, we dig into Model Context Protocol (MCP) and agent-to-agent (A2A) communication — what they are, why they matter, and where the real risks start to emerge. We cover:- What MCP actually enables beyond “tool calling”- How A2A changes the threat model for AI systems- Where trust boundaries break down when agents talk to each other- Why existing security assumptions don’t hold in agen...
Agentic AI Security | case studies by Microsoft, OWASP 04.01.2026 32:34
As promised, I’m back with Tania for a deep dive into the wild world of agentic AI security — how modern AI agents break, misbehave, or get exploited, and what real case studies are teaching us. We’re unpacking insights from the Taxonomy of Failure Modes in Agentic AI Systems, the core paper behind today’s discussion, and exploring what these failures look like in practice. We also break down thre...
a hacky christmas message 23.12.2025 3:43
A quick end-of-year message to say thanks. Thanks for being part of the channel this year — whether you’ve been watching quietly, sharing, or arguing with me in the comments. I really appreciate it. I hope you have a good Christmas and holiday period, whatever that looks like for you. Take a break if you can. See you in 2026.
Three Black Hat talks at just 18! My interview with Bandana Kaur. 21.12.2025 12:45
In this episode, I’m joined by Bandana Kaur — a cybersecurity researcher, speaker, and all-round superstar who somehow managed to do in her teens what most people are still figuring out in their thirties. 🤔 Bandana is just 18 years old, entirely self-taught in cybersecurity, already working in the field, and recently gave three talks at Black Hat. Yes, three! 😱 We talk about how she taught herse...
Effective Altruism and AI with Good Ancestors CEO Greg Sadler | part 2 14.12.2025 31:28
Remember that time I invited myself over to Greg's place with my camera? This is part 2 from that great conversation. I'm curious to hear whether you've heard a lot about EA? It's something really big in the AI world but I'm conscious a lot of people outside the bubble haven't heard of it. Let me know in the comments! Check out Greg's work here: https://www.goodancestor...
AI Safety with CEO of Good Ancestors Greg Sadler | part 1 07.12.2025 27:53
This week I invited myself over to Greg Sadler's place, the CEO of Good Ancestors, about AI safety. I brought sushi but I didn't have lunch so I ate most of it, and then I almost made him late for his next meeting. We specifically chat through AI capabilities, his work in policy, and building a not-profit. Greg is the kind of person who is so smart and cool that I feel like an absolute dum...
The United States AI Action Plan | will they win the AI race against China? 🤔 24.11.2025 30:09
Hi! 👋 In this episode, we’re diving into the US AI Action Plan — the White House’s new roadmap for how America plans to lead in AI.. and beat China. We’ll look at what’s inside the plan, what it really means for AI security and regulation, and whether it’s more of a policy promise… or a political one.📄 You can read the full plan here:https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas...
AI Security vs Application Security 09.11.2025 30:22
Welcome back! 👋 After taking a little break to reset and redesign everything behind the scenes, I’m back — and consolidating all my content. This episode is part of both The AI Security Podcast (on Spotify and Apple Podcasts) and my YouTube channel, HarrietHacks — so whether you prefer to listen or watch, you’ll get the same great conversations (and bad jokes) across both platforms. From now on,...
Agentic AI Security: A Primer 12.08.2025 19:02
For a while we've been wanting to talk about Agentic AI Security.. the thing is that we could spend multiple episodes talking about it! So we decided to do just that. This is part 1 - a primer - where we talk about exactly what AI agents are and why we may need to consider their security a bit differently. Stay tuned for the rest of the series!
How Likely Are AI Security Incidents? Updates From Our Final Report! 04.08.2025 31:28
Six months ago Tania and I made an episode about the interim report for our AI Security Likelihood Project.. and it is finally time to discuss the final report! You'll see it live at this link shortly: https://www.aisecurityfundamentals.com/ The premise was simple: are AI security incidents happening in the wild? What can we learn about future incidents from these historic ones? We answer som...
To open or close model weights? 23.07.2025 27:52
In this episode, Tania and I discuss the debate around closed or open model weights. What do you think? The RAND report we mention: https://www.rand.org/pubs/research_reports/RRA2849-1.html
Creative prompt injection in the wild 15.07.2025 31:10
In this episode, Tania and I talk through some creative examples of prompt injection/engineering we've seen in the wild.. think prompts hidden in papers, red-teaming and web-scraping. Your Brain on ChatGPT: https://arxiv.org/pdf/2506.08872 Paper with hidden text (p. 12): https://arxiv.org/abs/2502.19918v2 Interesting overview: https://www.theregister.com/2025/07/07/scholars_try_to_fool_llm_...
Threat intel digest: 23 June 2025 24.06.2025 52:13
This week we discussed multiple AI vulnerabilities, including Echolink in M365 Copilot, Agent Smith in Langchain, and a SQL injection flaw in Llama Index, all of which have been patched. We also covered a data exposure bug in Asana's MCP server and OWASP's project to create an AI vulnerability scoring system, while also outlining Google's defense layers for Gemini, Thomas Roccia&apo...
AI safety evaluations with Inspect 16.06.2025 32:52
I'm back from holiday, and this week Tania and I talk about a project she completed as part of the ARENA AI safety curriculum to replicate the findings of evaluations on frontier AI capabilities. Link to reasoning paper: https://arxiv.org/abs/2502.09696 Link to the Inspect dashboard: https://inspect-evals-dashboard.streamlit.app/ ARENA AI Safety course: https://www.arena.education/
Threat intel digest: 9 June 2025 10.06.2025 54:57
This week we try a new condensed format for the AI security digest! we covered critical CVEs, including vulnerabilities in AWS MCP, Llama Index, GitHub MCP integration, and tool poisoning attacks. We also reported on malware campaigns using spoofed AI installers, a supply chain attack via fake PyTorch models, and the AI-guided discovery of a Linux kernel vulnerability by Sean Healin using OpenAI&a...
Threat intel digest: 26 May 2025 30.05.2025 39:23
Sign up to receive in your inbox: http://eepurl.com/i7RgRM Tania Sadhani and Miranda R discussed various AI security topics, including critical CVEs affecting platforms like ChatGPT and Hugging Face, the potential for SharePoint Copilot in internal reconnaissance, and malicious npm packages targeting Cursor developers. They also covered the OASP Gen AI security initiative's Agent Name Service...
AI Vulnerability Research with Aditya Rana 20.05.2025 38:43
Ever wondered how security vulnerabilities are found in AI? Join us as we chat with Aditya, a Vulnerability Researcher at Mileva Security Labs!
Threat intel digest: 12 May 2025 12.05.2025 48:22
Sign up to receive in your inbox: http://eepurl.com/i7RgRM This week we note regular CVEs in AI libraries such as Nvidia TensorFlow and PyTorch. We discuss a novel prompt injection technique called "policy puppetry", along with malware dispersal through fake AI video generators and Meta's release of an open-source AI security tool set including Llama Firewall. We also covered Israe...
The evolution of data science and AI ethics with Dr Alberto Chierici 07.05.2025 49:59
This week I'm joined by my friend Alberto, he has an incredible storied career - from data science, insurance, AI risk, advising Tesla.. check out his book here! https://www.amazon.com.au/Ethics-I-Facts-Fictions-Forecasts/dp/1636763650
Stanford's 2025 AI Index Report 30.04.2025 35:36
We talk about Stanford Human-Centred AI's latest AI Index report, check it out here: https://hai.stanford.edu/ai-index/2025-ai-index-report
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.