w/ Rein Daelman, Security researcher
AI is creeping into every part of software development — including CI/CD pipelines — and attackers are already abusing it. In this episode of the Secure Disclosure Podcast, we break down: A brand-new vulnerability class called Prompt Pwn, where prompt injection inside GitHub Actions can leak secrets and compromise supply chains A sophisticated malvertising campaign targeting developers via GitHub Pages and Docker Hub And the reality behind the cybersecurity job market: is there a skills shortage, a hiring freeze, or both? Featuring security researcher Rein Daelman on AI-driven CI/CD risks, and recruiter Barry Prost on how AI is reshaping cybersecurity hiring, skills, and careers. If you care about AppSec, DevOps, supply chain security, or breaking into cybersecurity in 2025, this one’s for you. More information PromptPwn - https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents Guest Linkedin - https://www.linkedin.com/in/rein-daelman/ Rent a Recruiter - https://rentarecruiter.com/ Guest LinkedIn Barry Prost - https://www.linkedin.com/in/barryprost/ Sponsors Aikido Security - https://aikido.dev Chapters 00:00 – Intro 02:00 – AI prompt injection in CI/CD, GitHub Actions, Prompt Pwn 12:09 – Sponsor Segment 12:59 – Malvertising campaigns targeting devs 16:39 – Cybersecurity job market with Barry Prost
Tell us who, why, and how to reach them. We read every submission.