惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
The GitHub Blog
The GitHub Blog
月光博客
月光博客
T
Tailwind CSS Blog
小众软件
小众软件
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
B
Blog RSS Feed
博客园 - 司徒正美
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 聂微东
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
博客园 - Franky
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Azure Blog
Microsoft Azure Blog
T
The Blog of Author Tim Ferriss
GbyAI
GbyAI
Apple Machine Learning Research
Apple Machine Learning Research

Blog on 1Password Blog

NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password Expanding Programmatic Access to 1Password | 1Password
Password Manager for Families, Enterprise & Business | 1P...
info@1passwo · 2026-06-12 · via Blog on 1Password Blog

Listen to this episode on Apple Podcasts

Listen to this episode on Spotify

Anyone who thinks security leaders are humorless sticklers for the rules has never spent half an hour with Jaya Baloo. But in this episode of Chasing Entropy, Dave Lewis does just that, and the result is a frank and irreverent conversation that proves that security may be serious business, but it’s still a fun job. Baloo is the co-founder and COO/CISO of Aisle, an AI-powered vulnerability management startup with the bold goal of “zero exploitable vulnerabilities.”

Baloo’s career has spanned telecom, cryptography, enterprise security, and AI-driven security research, but her love of computers started when she got her first computer (a Commodore 64) at age 9. The conversation tracks her journey from early BBS war dialing and CompuServe stories to the modern challenge of defending organizations against increasingly autonomous systems.

A major focus of the episode is the growing hype around AI-powered vulnerability discovery. Baloo acknowledges the seriousness of the threat, saying “It introduces this asymmetry in terms of attacker-defender advantage, where the advantage would strongly go to the attacker if they’re capable of finding new and novel vulnerabilities, and the ability to exploit them, and potentially doing this at scale, autonomously.” However, she cautions that fear of a Mythos-level model shouldn’t leave security leaders feeling too overwhelmed to take action. “We have elevated this to a level of hype that is not that beneficial to actually doing something about the problem.” 

Instead of panicking about the unknown, Baloo advises security to start by addressing the problems they are aware of. Organizations already struggle with asset visibility, remediation backlogs, inconsistent logging, and weak operational hygiene. AI may have increased the blast radius of these risks, but they existed long before LLMs.

The discussion also explores how smaller, open-source models can rival or exceed the results of heavily funded proprietary systems when paired with the right orchestration and context. Baloo explains how her team at Aisle used lightweight models to identify vulnerabilities in OpenSSL, including issues other systems missed entirely. She says, “If you can find new and novel vulnerabilities in the same codebase that were missed by this incredibly intelligent and well-resourced model, then maybe it’s not about the model. Maybe it’s about the way you’re running the model, and everything else around it.”

Dave also brings up the governance failures emerging around enterprise AI adoption. Internal copilots, third-party integrations, and poorly understood permission models are creating new forms of insider risk. “Our permissioning models need to change, and identity is a really big part of that,” Baloo acknowledges, pointedly hinting that 1Password could help drive that change.

Later, Baloo candidly addresses thorny issues of leadership and board accountability, particularly how CISOs are expected to manage risk they did not create. Baloo argues that security teams are often left cleaning up years of operational debt accumulated elsewhere in the business. She offers a pragmatic approach to tackling these issues, but is vehemently critical of “risk acceptance” culture, having seen organizations normalize small unresolved issues until they compound into systemic failures. “No risk acceptance! What a nonsense term,” she quips.

As always, Dave closes the episode by asking what advice his guest has for security professionals just starting in their careers. Baloo says she found success by following her interests and values, rather than her ambitions, and that this has led her not only to a successful career, but a happy one.

Subscribe to Chasing Entropy

Subscribe to Chasing Entropy for honest, expert-led conversations on agentic AI, security, shadow IT, and extended access control from industry leaders.