Cybersecurity News & Analysis by Cyber Sidekicks - Your Weekly Update’ · Christina Richmond | Rory Duncan - Cybersecurity Experts | Richmond Advisory Group

API vulnerabilities & AI: Cequence Security's Randolph Barr tells us why we should care!

·43 min·2 clips
AI-related vulnerabilities jumped from 39 in 2023 to 439 in 2024.
1. Cyber Sidekicks focuses on API vulnerabilities, AI, and a weekly cybersecurity news roundup with Randolph Barr from Sequence Security. 2. Rory Duncan and Christina Richmond host the show as Richmond Advisory Group principal analysts, and Barr appears as the CISO of Sequence Security. 3. The episode asks how AI changes cybersecurity risk, developer behavior, and the security market. 4. Christina Richmond describes INCH360 Summit in Spokane as a free cybersecurity and AI conference with 8 CPEs. 5. She says Eastern Washington University Army ROTC presented the colors and the event included awards, sponsors, and a full-day agenda. 6. Kane McGladrey led a ransomware tabletop exercise for 150 to 200 attendees at INCH360. 7. Christina says the room worked through communication, stakeholder handling, and response decisions with “24 hours left.” 8. She also names panels on audit and insurance factors, the intersection of AI and cybersecurity, and lessons learned from a breach. 9. The episode names IBM X-Force and Google Mandiant as panel participants. 10. Randolph Barr says he is in the Philippines and works with the Cybersecurity Society of the Philippines, or CyberSocPH. 11. He says his foundation helps orphanages and visits universities to support computer science graduates who need paths into the field. 12. Barr says the group’s focus this year is AI, and he wants more professionals in the Philippines to move into cyber and technology roles. 13. Barr says what keeps him up at night is his calendar because global meetings can appear hours before they start. 14. He connects that to prompt injection, email, Slack, and targeted AI attacks against older people and bank accounts. 15. Christina cites a paper from June that says AI-related vulnerabilities in the CVE database rose from 39 in 2023 to 439 in 2024. 16. She says almost 99% of those vulnerabilities are API vulnerabilities, including 77.4% directly API-related and 22% indirectly through third parties. 17. Barr says many AI attacks are really basic security hygiene failures that teams never fixed. 18. He argues that a fully agentic AI vulnerability management lifecycle would still need guardrails and human review before any production change. 19. The conversation is interview-based, conversational, and tied closely to current security research, conference observations, and market news. 20. Listeners who follow API security, AI risk, or cybersecurity operations will get the most from this episode, while people seeking deep theory or light entertainment may skip it.

As heard by us

API security becomes a bigger operational problem when AI amplifies old hygiene failures.

API security, AI-driven attack surfaces, and the stubborn problem of discovery sit at the center of this episode, and the discussion keeps circling back to those same pressures.

Read the full review in PlayNext →

Why you'd press play

If API sprawl and AI risk are colliding, this gives you a cleaner read.

Read the full recommendation in PlayNext →
Listen to the show on