The editors of Decipher talk with a rotating cast of security practitioners, researchers, and executives about a variety of topics in the security and privacy fields.

Christine Gadsby of BlackBerry, a longtime security executive, joins Dennis to talk about her extensive experience in cybersecurity, the evolution of security practices, the challenges of securing mobile communications, and the impact of AI on the security industry.

It's our one year anniversary! This week we talk about the highlights of the last year, a new high-level phishing campaign that uses Microsoft Teams as an initial access vector, and the takedown of the ancient Sality P2P botnet. Then we offer some book and TV recommendations for the long weekend. LinksOne year of the new Decipher: https://decipher.sc/2026/09/02/one-ye...Microsoft Teams phishing: https://decipher.sc/2026/09/03/new-ca...Sality botnet takedown: https://www.justice.gov/usao-cdca/pr/...

Ken Bagnall, founder and CEO of Silent Push, talks about the August National Security Presidential Memorandum (NSPM) on transnational cyber-enabled crime, how organizations can make “real impact” with cybercriminal disruption, and the challenges of measuring success in disrupting the cybercriminal ecosystem.

This week we discuss the two arrests in Australia of alleged members of the TeamPCP cybercrime group that has targeted the open source ecosystem, the US government's disclosure of intrusion activity by the Chinese QTFY threat actor, and finally the long report from OpenAI on the Hugging Face incident.

Nicole Ozer, who took the helm this year as the new executive director at the Electronic Frontier Foundation (EFF), talks to Lindsey O'Donnell-Welch about the fine line between AI empowering us and undermining our rights and privacy – and where the tipping point is.

This week we discuss the new White House memo on using private sector operators in offensive cyber operations, Lindsey's deep dive into the origins of the ExploitGym AI benchmark, and the rash of attacks on water utilities in the U.S.LinksInside ExploitGym: https://decipher.sc/2026/08/20/inside...White House memo: https://www.whitehouse.gov/presidenti...OpenAI post: https://openai.com/index/the-defender...

Adam Meyers of CrowdStrike joins Dennis to dive into the rapidly changing nature of both attacker and defender behavior in the AI age and how organizations need to shift their priorities to combat agentic threats. Then we talk about the new White House policy loosening the restrictions on private sector operators doing offensive cyper ops.

AI security pioneer and machine learning expert Gary McGraw helps Dennis separate the facts from fiction about the recent OpenAI, Meta, and Anthropic model escapes, what the real risks to enterprises are from agentic AI, and what he sees as the true threats on the horizon.

We can't go a week without an AI model escaping its bounds, and this week we talk about a new test by the AI Security Institute in which OpenAI and Anthropic models escaped the evaluation environment and tried to start a supply chain attack, then we discuss news of Zbtlink routers having a persistent backdoor.

This week we talk about the OpenAI-Hugging Face incident and what it means for those companies and the way that AI models are tested, and then we discuss Anthropic's entry into the race with its own admission that some of its models escaped the playground and attacked outside organizations. LinksOpenAI-Hugging Face intrusion: https://decipher.sc/2026/07/29/openai...Anthropic blog: https://www.anthropic.com/news/invest...Ringer piece on the Hugging Face incident: https://www.theringer.com/2026/07/24/...

Project Hail Mary is many things: an instant classic, a heartwarming buddy movie, a brilliant scientific tale. And it's also a pure hacker movie. Wendy Nather and David Mortman join Dennis and Lindsey to talk about Ryland Grace's hacker ethos and why he and Rocky typify the can-do attitude of hackers everywhere. It's time go!

Cybercrime has become professionalized and industrialized to the point that these groups are essentially at the level of state-backed APTs. Mike Sweeney of Silent Push joins Dennis Fisher to talk about this evolution, how AI is enabling this shift, and how defenders and vendors are working to take incremental bites out of their ecosystem.

Michael Clark, director of Threat Research at Sysdig, talks about a recent LLM-driven extortion campaign dubbed JADEPUFFER, touching on how the team discovered it, how attackers' “intent is now legible,” and what that means for defenders.LinkSysdig research: https://www.sysdig.com/blog/jadepuffe...

This week we have some old-school disclosure drama when a researcher used full disclosure after months of silence from Cursor, then we discuss the enormous Patch Tuesday from Microsoft--662 bugs--and what it might mean going forward, and finally some news about DoJ sanctions and Scattered Spider members being sentenced.

Old malware like Conficker never really dies, and in industrial control and SCADA environments it can live forever undisturbed. Lesley Carhart of Dragos joins Dennis Fisher to talk about the myriad challenges of incident response in ICS networks, how ancient malware can cause trouble for years on end, and why we need more ICS security engineers desperately.

Jack Cable, co-founder and CEO of Corridor and a former senior technical advisor at CISA, discusses AI's impact on cybersecurity, vulnerability discovery, and coding practices.

It's a pre-July 4th extravaganza! To celebrate, we dive into a little cybersecurity history with a story about the MySpace Samy worm, then we jumpe into the news of the week, including an update on the Fable 5 export control drama, and the emergence of the ARToken operator panel.

Hacker and legendary vulnerability disclosure expert Katie Moussouris of Luta Security joins Dennis to talk about the Fable 5 munitions classification controversy, the recent re-emergence of the disclosure debate, how AI-assisted bug hunting is reshaping the defensive landscape, and what the future holds for attackers and defenders.

It's a non-AI podcast! This week we dig into the new Gaslight macOS implant that tries to trick security researchers with some anti-forensics techniques, then we discuss the Operation Endgame takedown of some malware infrastructure, and finally we discuss a Cisco Catalyst SD-WAN bug that was exploited as a zero day.

Alex Pinto, one of the lead authors of the Verizon Data Breach Investigations Report, joins Dennis to talk about his organization's newest publication, the Breach Impact Study, which digs into the real world cost of breaches, both in dollars and in organizational impact. Spoiler: Breaches are expensive.Verizon BIS: https://www.verizon.com/business/resources/reports/2026-breach-impact-study-dbir.pdf

This week was blessedly free of any major supply chain compromises, so we start by talking about new research from Anthropic on the shrinking window between bug disclosure and exploitation, then we discuss the changing patch schedule for Cisco and how all of this is changing the prioritization process for security teams, and finally we discuss some upcoming episodes and our latest hacker movie podcast on The Conversation.LinksAnthropic research: https://decipher.sc/2026/06/10/anthropic-warns-of-llms-impact-on-already-shrinking-n-day-exploit-gap/Cisco patch change: https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discoveryThe Vulnpocalypse: https://thevulnpocalypse.com/

Perhaps no film captures the paranoia and anxiety of the 1970s better than The Conversation, Francis Ford Copolla's masterpiece about reclusive surveillance expert Harry Caul, a man who it's safe to say has some demons. Decades before we all agreed to carry tracking and recording devices in our pockets, The Conversation shows us just how invasive and damaging technology can be.

We regret to inform you that there are more npm supply chain attacks this week, and a new variant of the Shai Hulud worm is involved. We also talk about the new analysis from Anthropic on a year of data relating to how attackers are using AI in their operations, and the continuing adventures of Microsoft's relationship with security researchers.

The recent Nightmare-Eclipse zero day drop and attendant drama has stirred up all kinds of trouble and unfortunately spurred Microsoft to publish a post scolding security researchers for not using the "proper channels" to disclose bugs, threatening legal action, and generally dredging up every hobby horse from the threadbare disclosure debate. LinksMSRC post: https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosureDecipher story: https://decipher.sc/2026/05/28/the-past-is-always-present-in-vulnerability-disclosure/Expel event: https://info.expel.com/event-mythos-unhappy-hour.html

After being caught in one of the more notorious battles in modern American history, Matt Eversmann's military career has become the stuff of legend. The Battle of Mogadishu, immortalized in the book and movie Black Hawk Down, was a pivotal event in U.S. history and in the lives of Matt and his fellow soldiers. Now retired from the army and focusing on training the next generation of leaders, Matt joins Dennis Fisher to talk about his career, what he's learned from his failures and successes, and how vital resilience and perseverance are for success in any field. Matt's biography: https://thayerleadership.com/team-member/first-sergeant-matt-eversmann/

In the spring, a young attacker's fancy turns to supply chain compromises, and this season's crop includes the GitHub breach and the Grafana intrusion, which are connected and trace back to the TanStack supply chain attack and...TeamPCP. LinksGrafana attack: https://decipher.sc/2026/05/17/grafana-investigating-token-compromise-and-extortion-attempt/GitHub breach: https://decipher.sc/2026/05/20/github-confirms-internal-breach/

Finding a huge pile of bugs with Claude Mythos is great, but the logical next step is figuring out how many of those vulnerabilities are likely to be exploited in the near future. Jay Jacobs and Michael Roytman of Empirical Security join Dennis to talk about how the Exploit Prediction Scoring System can help teams make informed decisions and prioritize patching the most important vulnerabilities. Jay and Michael are pioneers in the data-driven security field and help steer the EPSS effort.

Unlike a lot of founders in the industry, Sravish Sridhar hasn't spent his career in the security world. He comes from a background in distributed computing and advanced math, and is a successful entrepreneur who's now bringing that experience to bear at TrustCloud, where he's helping CISOs automate and streamline their compliance programs.

Few people (if any) have spent more time thinking about and working on the hard problems in security and software than Gary McGraw, and he also happens to have a PhD in cognitive science and computer science and has been studying neural nets and AI systems for 30+ years. Gary joins Dennis to talk about his team's new research into AI security benchmarks, measurement, and bringing a software security approach to LLMs and AI systems. LinksBIML report: https://berryvilleiml.com/results/no-security-meter-ai.pdf

Ari Redbord, Global Head of Policy at TRM Labs, talks about the insane background behind the $285 million Drift Protocol crypto heist, how law enforcement agencies are investigating ransomware-linked cryptocurrency wallets, and how effective sanctions are on cybercrime.

If we needed any more evidence that the internet was a mistake, this week provided it. We kick things off with a discussion of the Canvas breach that has affected thousands of schools worldwide, then we dig into the disclosure of two new vulnerabilities in Ivanti and Palo Alto Networks products that are actively exploited, and then we talk about a new branded Linux bug called Dirty Frag. Finally, we wrap up with some comic relief from the Everything App.LinksIvanti bug: https://decipher.sc/2026/05/07/ivanti-warns-of-exploited-epmm-flaw-cve-2026-6973/Palo Alto bug: https://decipher.sc/2026/05/06/845/Dirty Frag: https://decipher.sc/2026/05/07/new-dirty-frag-linux-bug-emerges/The viral tweet: https://x.com/DennisF/status/2050682024587845690

Will Dixon has seen the evolution of cybercrime as both a GCHQ intelligence officer and a private sector executive and analyst, and has seen the way these groups operate up close. He joins Dennis to talk about the ongoing threat from ransomware gangs, how organizations are managing their responses, and what he expects to come next.

JAGS joins Dennis Fisher to unpack the complex history of fast16, a highly targeted cyber espionage platform that goes back as far as 2005, many years before Stuxnet, and was deployed against targets in Iran. JAGS has been in the APT hunting game for a long time, and brings his historical perspective and context around the Shadow Brokers leak, Stuxnet ties, and how this discovery changes what we know about the use of these tools.LinksSentinelLabs report: https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/

The security news was out of hand this week, so we had to pick our spots. We start with the nasty cPanel/WHM vulnerability that affects tens of millions of domains in shared hosting environments, then we discuss the Copy Fail Linux bug and its effects before seguing into the delightful history of branded bugs, logos, and parodies. LinksBranded bugs and logos: https://io.netgarage.org/logo/

Ariana Mirian, cofounder of startup Beesafe, joins Dennis to talk about the mechanics of online romance and finance scams, how the scammers draw in victims over weeks or months, and why user awareness isn't the complete solution to the problem. LinksBeesafe AI: https://beesafe.ai/

This week we dig deep into the Vercel intrusion that emerged last weekend, how it happened, what the response was, and what the downstream effects may be for defenders. Then we talk about CISA's bizarre delayed response to the Axios npm compromise and what it signals about the agency's capabilities going forward.

It's been A WEEK. Security news never sleeps, and neither does AI, so Dennis and Lindsey dive into all of the storylines coming from the Claude Mythos and Project Glasswing announcements, how organizations will deal with the coming flood of CVEs and patches, NIST's decision to only enrich specific CVEs going forward, and what could possibly be next on the horizon.

Dennis sits down with Tom Ptacek of Fly.io, a veteran security researcher, founder, and observer of the vulnerability landscape, to talk about the recent wave of AI-assisted vulnerability discovery and exploit development, specifically from the use of frontier models such as Claude Mythos. Tom has strong opinions on what's coming and how human researchers and defenders need to respond. Tom's post: https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/

The internet is dark and full of terrors, but thanks to folks such as Andrew Northern, a principal security researcher at internet-mapping pioneer Censys, it doesn't have to be, Andrew joins Dennis to talk about the cybercrime ecosystem, getting his start in security on a tiny team with huge responsibilities, and the value of a strong mentor.

It's been quite a week in security news, and Dennis and Lindsey dig into the continued effects of the axios supply chain attack, the incredibly fast adoption of AI tools for vulnerability research and what that means for software makers and defenders, and what the future holds for vulnerability research and exploit development.Security Theater in Austin: https://material.security/theater-2026#theater-live-event

Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer's account, the window of exposure for the malicious packages, the behavior of the RAT that's installed on victims' machines, and what the downstream effects may be. LinksHuntress post: https://www.huntress.com/blog/supply-chain-compromise-axios-npm-packageSocket analysis: https://socket.dev/blog/axios-npm-package-compromised

Fresh off the plane from RSA, Dennis fills Lindsey in on everything she missed (and didn't miss) at this year's conference (0:23), from the insanity of the expo floor (4:06) to the appearance of a line of synchronized robots or spacemen or something (8:18), to some very interesting conversations about the hyper speed of AI malware development and what's coming next for defenders (27:25).

With the RSA Conference on the horizon, Dennis and Lindsey are here with a preview of the conference's more interesting sessions and keynotes, a discussion of the recent and ancient history of the conference, and a quick game: Is this a security vendor or a prescription drug name?

Sure, space pirate is a cool title, but what about space hacker? Way cooler! With the imminent release of Project Hail Mary, Wendy Nather joins Dennis Fisher to dig into the nutrient-rich narrative soil that produced a modern classic that truly epitomizes the hacker ethos. We are the greatest podcasters on Mars!

This week's news includes a reappearance by an old favorite, APT28, aka Fancy Bear, which is back with some nasty new implants and tools it is deploying against targets in Ukraine (2:10), and we also have another law enforcement disruption of a residential proxy network, this one known as SocksEscort, which had victims all over the globe (7:45). Lastly, we talk about some of the upcoming episodes, including a new hacker movie podcast and our RSA preview that's coming next week. LinksAPT28 reappears: https://decipher.sc/2026/03/10/apt28-reemerges-with-modern-espionage-arsenal-code-tied-to-2010s-operations/SocksEscort takedown: https://decipher.sc/2026/03/12/us-europol-crack-down-on-socksescort-residential-proxy-network/

The process of developing and deploying exploits is a complex and controversial one and it's often a black box to outside observers. To help shine a light on how this all works, Caitlin Condon of VulnCheck joins Dennis Fisher for a deep dive into the zero day exploit landscape, what goes into exploit development, and what actually qualifies as a functional exploit.

Every day is zero day, and this week we talked about the new Google Threat Intelligence Group report on the zero day exploit landscape in 2025 (2:22) and who's exploiting what, then we discuss Microsoft's disruption of the Tycoon 2FA cybercrime operation (9:51), and finally we talk about the KEVology report from runZero and our new podcast with Tod Beardsley (13:25).

Tod Beardsley, VP of security research at runZero and former KEV section chief at CISA, joins Dennis Fisher to talk about the evolution of the Known Exploited Vulnerabilities catalog, how much value defenders should place on a specific bug being in the KEV, and his new KEVology report that breaks down all of the data in the KEV and sifts through it for specific insights for defenders.

This week Lindsey rejoins Dennis to talk about the attacks targeting a zero day in Cisco's Catalyst SD-WAN Controller (2:17), Google's disruption of a China-linked cyber espionage campaign targeting telecom infrastructure (6:30), and the new cyber developments on everyone's favorite tech show, The Pitt (13:13)!

It's a light news week, but we have some fun content for you! This week, we talk about our latest hacker movie episode--STAR WARS--which is up on the site and all of our feeds now (0:25), then we dig into a nasty hard-coded. credential bug in Dell RecoverPoint for Virtual Machines that Chinese threat actors are exploiting (4:20), and then we move on to an active campaign targeting two vulnerabilities in Ivanti EPMM that is hitting organizations across the U.S., Canada, and other countries (08:33). Finally, we talk a little about an interesting cybersecurity plot line on HBO's show The Pitt (12:15). Spoiler warning: If you're not caught up on this show, there's a minor spoiler, but nothing you haven't really seen in the previews. Support the show

STAR WARS isn't just one of the more successful and iconic movies of all time and the basis for a worldwide sci-fi empire, it's also a true hacker story. Wade Baker and Rich Mogull, two Star Wars scholars, join Dennis Fisher to break down the Empire's pathetic perimeter defenses, R2D2's arc as a wily hacker, and how the movie hinges on a data breach.Support the show