Cloudflare Outage, AI-Powered Attacks & The Rise of GRC Engineering | Distilled Security Podcast

In this episode, we break down a major Cloudflare outage, explore how a nation-state used AI agents to automate a cyberattack, and discuss the growing risks around MCP integrations. We also highlight why GRC Engineering is becoming essential to modern security programs and wrap up with key regulatory updates, including CMMC changes affecting thousands of contractors.

Topics covered:
• Cloudflare outage impact and root cause
• Nation-state attack using AI agents to automate intrusion steps
• MCP (Model Context Protocol): power, risks, and examples
• Why GRC Engineering is the future of compliance and automation
• Updates on GDPR, ISO 27701, California AB 5866, and SEC rules
• CMMC assessor shortages and what organizations must prepare for

Spirit of the Episode
• Knob Creek 21-Year Limited Release – rich caramel notes, heavy char, smooth for 100 proof

Timestamps
  • 0:02- Cloudflare Outage Stories & Global Impact
  • 3:07- Root Cause, Not a Cyberattack & Third-Party Risk Reality
  • 10:38 - China Uses Anthropic’s Claude + MCP for Automated Cyberattacks
  • 14:17 - Full AI Attack Lifecycle Explained
  • 27:18 - MCP: The API for AI & Its Security Risks
  • 44:05 - Bourbon Break: Knob Creek 21-Year Review
  • 50:02 - GRC Engineering Deep Dive: Automation & Controls-as-Code
  • 1:24:13 - Regulatory Roundup: GDPR, ISO 27701, California AB 566, SEC SP
  • 1:44:27 - CMMC 2.0 Crisis: Auditor Shortages & DoD Contract Impact
  • 2:11:20 - Closing Thoughts & Episode Wrap-Up
Hosts
  • Justin Leapline – @justinleapline
  • Joe Wynn – @wynnjoe
  • Rick Yocum – @rickyocum

Connect with Us
  • Website: distilledsecuritypodcast.com
  • X:  @DisSecPod
  • Email: hello@distilledsecuritypodcast.com

Creators and Guests

Joe Wynn
Host
Joe Wynn
Founder & CEO @ Seiso | IANS Faculty Member | Co-founder of BSidesPGH
Justin Leapline
Host
Justin Leapline
Founder of episki | IANS Faculty Member
Rick Yocum
Host
Rick Yocum
Optimize IT Founder | Managing Director, TrustedSec
Cloudflare Outage, AI-Powered Attacks & The Rise of GRC Engineering | Distilled Security Podcast
Broadcast by