CISSP Cyber Training Podcast - CISSP Training Program
CISSP Cyber Training Podcast - CISSP Training Program
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
CCT 367: Threat Modeling and the AI Agent That Breached Hugging Face (CISSP Domain 1.10)
42 minutes Posted Aug 24, 2026 at 12:00 pm.
Welcome And Episode Roadmap
The Sealed Test Room Breakout
How Hugging Face Got Abused
Alerts Fired But Nobody Acted
What Was Exposed And What Held
The Real Lesson Behind The Headlines
Threat Modeling Definition And Three Views
STRIDE Mapped To Real Failures
DREAD Scoring And PASTA Stages
Attack Trees Plus Other Framework Traps
Trust Boundaries And When To Remodel
CISSP Practice Questions And Exam Traps
Training Offers And Final Requests
0:00
42:52
Download MP3
Show notes
Send us Fan Mail A rogue AI agent didn’t “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying around. We walk through the Hugging Face intrusion story like a CISO briefing a board, step by step, translating a fast-moving AI-red-team narrative into the kind of clear threat modeling logic you need for ISC2 CISSP Domain 1.10 and for real risk decisions. From there, we shift into traini...