Decipher Security Podcast

Follow Decipher Security Podcast
Share on
Copy link to clipboard

The editors of Decipher talk with a rotating cast of security practitioners, researchers, and executives about a variety of topics in the security and privacy fields.

Decipher


    • May 19, 2026 LATEST EPISODE
    • weekdays NEW EPISODES
    • 33m AVG DURATION
    • 353 EPISODES


    Search for episodes from Decipher Security Podcast with a specific topic:

    Latest episodes from Decipher Security Podcast

    What the Data Tells Us About Claude Mythos and Bug Exploitability | Jay Jacobs and Michael Roytman

    Play Episode Listen Later May 19, 2026 43:41


    Finding a huge pile of bugs with Claude Mythos is great, but the logical next step is figuring out how many of those vulnerabilities are likely to be exploited in the near future. Jay Jacobs and Michael Roytman of Empirical Security join Dennis to talk about how the Exploit Prediction Scoring System can help teams make informed decisions and prioritize patching the most important vulnerabilities. Jay and Michael are pioneers in the data-driven security field and help steer the EPSS effort.

    Solving Hard Security Problems With an Outsider's Perspective | Sravish Sridhar

    Play Episode Listen Later May 15, 2026 53:56


    Unlike a lot of founders in the industry, Sravish Sridhar hasn't spent his career in the security world. He comes from a background in distributed computing and advanced math, and is a successful entrepreneur who's now bringing that experience to bear at TrustCloud, where he's helping CISOs automate and streamline their compliance programs.

    AI Has a Security Measurement Problem | Gary McGraw

    Play Episode Listen Later May 13, 2026 38:02


    Few people (if any) have spent more time thinking about and working on the hard problems in security and software than Gary McGraw, and he also happens to have a PhD in cognitive science and computer science and has been studying neural nets and AI systems for 30+ years. Gary joins Dennis to talk about his team's new research into AI security benchmarks, measurement, and bringing a software security approach to LLMs and AI systems. LinksBIML report: https://berryvilleiml.com/results/no-security-meter-ai.pdf

    Inside the $285M Drift Protocol Heist | Ari Redbord

    Play Episode Listen Later May 11, 2026 34:11


    Ari Redbord, Global Head of Policy at TRM Labs, talks about the insane background behind the $285 million Drift Protocol crypto heist, how law enforcement agencies are investigating ransomware-linked cryptocurrency wallets, and how effective sanctions are on cybercrime.

    The Canvas Attack, Ivanti and Palo Alto Exploits, and Dirty Frag

    Play Episode Listen Later May 8, 2026 41:29


    If we needed any more evidence that the internet was a mistake, this week provided it. We kick things off with a discussion of the Canvas breach that has affected thousands of schools worldwide, then we dig into the disclosure of two new vulnerabilities in Ivanti and Palo Alto Networks products that are actively exploited, and then we talk about a new branded Linux bug called Dirty Frag. Finally, we wrap up with some comic relief from the Everything App.LinksIvanti bug: https://decipher.sc/2026/05/07/ivanti-warns-of-exploited-epmm-flaw-cve-2026-6973/Palo Alto bug: https://decipher.sc/2026/05/06/845/Dirty Frag: https://decipher.sc/2026/05/07/new-dirty-frag-linux-bug-emerges/The viral tweet: https://x.com/DennisF/status/2050682024587845690

    Fighting Cybercrime With Global Intelligence | Will Dixon

    Play Episode Listen Later May 6, 2026 44:23


    Will Dixon has seen the evolution of cybercrime as both a GCHQ intelligence officer and a private sector executive and analyst, and has seen the way these groups operate up close. He joins Dennis to talk about the ongoing threat from ransomware gangs, how organizations are managing their responses, and what he expects to come next.

    The fast16 Mystery, Stuxnet, and the History of Cyber Espionage | Juan Andres Guerrero-Saade

    Play Episode Listen Later May 4, 2026 68:31


    JAGS joins Dennis Fisher to unpack the complex history of fast16, a highly targeted cyber espionage platform that goes back as far as 2005, many years before Stuxnet, and was deployed against targets in Iran. JAGS has been in the APT hunting game for a long time, and brings his historical perspective and context around the Shadow Brokers leak, Stuxnet ties, and how this discovery changes what we know about the use of these tools.LinksSentinelLabs report: https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/

    cPanel Exploits, Copy Fail, and the History of Branded Bugs

    Play Episode Listen Later May 1, 2026 42:12


    The security news was out of hand this week, so we had to pick our spots. We start with the nasty cPanel/WHM vulnerability that affects tens of millions of domains in shared hosting environments, then we discuss the Copy Fail Linux bug and its effects before seguing into the delightful history of branded bugs, logos, and parodies. LinksBranded bugs and logos: https://io.netgarage.org/logo/

    Defeating Online Scams and Disrupting the Cybercrime Chain | Ariana Mirian

    Play Episode Listen Later Apr 28, 2026 50:33


    Ariana Mirian, cofounder of startup Beesafe, joins Dennis to talk about the mechanics of online romance and finance scams, how the scammers draw in victims over weeks or months, and why user awareness isn't the complete solution to the problem. LinksBeesafe AI: https://beesafe.ai/

    The Vercel Intrusion and What is Happening at CISA

    Play Episode Listen Later Apr 24, 2026 39:41


    This week we dig deep into the Vercel intrusion that emerged last weekend, how it happened, what the response was, and what the downstream effects may be for defenders. Then we talk about CISA's bizarre delayed response to the Axios npm compromise and what it signals about the agency's capabilities going forward.

    Claude Mythos, Automated Bug Hunting, and AI Eating Everything

    Play Episode Listen Later Apr 17, 2026 32:32


    It's been A WEEK. Security news never sleeps, and neither does AI, so Dennis and Lindsey dive into all of the storylines coming from the Claude Mythos and Project Glasswing announcements, how organizations will deal with the coming flood of CVEs and patches, NIST's decision to only enrich specific CVEs going forward, and what could possibly be next on the horizon.

    The Era of AI-Led Vulnerability Research With Tom Ptacek

    Play Episode Listen Later Apr 13, 2026 55:57


    Dennis sits down with Tom Ptacek of Fly.io, a veteran security researcher, founder, and observer of the vulnerability landscape, to talk about the recent wave of AI-assisted vulnerability discovery and exploit development, specifically from the use of frontier models such as Claude Mythos. Tom has strong opinions on what's coming and how human researchers and defenders need to respond. Tom's post: https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/

    Mapping the Cybercrime Ecosystem With Andrew Northern of Censys

    Play Episode Listen Later Apr 7, 2026 33:47


    The internet is dark and full of terrors, but thanks to folks such as Andrew Northern, a principal security researcher at internet-mapping pioneer Censys, it doesn't have to be, Andrew joins Dennis to talk about the cybercrime ecosystem, getting his start in security on a tiny team with huge responsibilities, and the value of a strong mentor.

    The Rapid Rise of AI Exploit Development and More Axios Compromise Effects

    Play Episode Listen Later Apr 3, 2026 51:24


    It's been quite a week in security news, and Dennis and Lindsey dig into the continued effects of the axios supply chain attack, the incredibly fast adoption of AI tools for vulnerability research and what that means for software makers and defenders, and what the future holds for vulnerability research and exploit development.Security Theater in Austin: https://material.security/theater-2026#theater-live-event

    Axios NPM Supply Chain Attack

    Play Episode Listen Later Mar 31, 2026 25:41


    Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer's account, the window of exposure for the malicious packages, the behavior of the RAT that's installed on victims' machines, and what the downstream effects may be. LinksHuntress post: https://www.huntress.com/blog/supply-chain-compromise-axios-npm-packageSocket analysis: https://socket.dev/blog/axios-npm-package-compromised

    RSA Recap: Dancing Robots, AI Everywhere, and the Future of Security

    Play Episode Listen Later Mar 27, 2026 51:00


    Fresh off the plane from RSA, Dennis fills Lindsey in on everything she missed (and didn't miss) at this year's conference (0:23), from the insanity of the expo floor (4:06) to the appearance of a line of synchronized robots or spacemen or something (8:18), to some very interesting conversations about the hyper speed of AI malware development and what's coming next for defenders (27:25).

    RSA 2026 Preview

    Play Episode Listen Later Mar 20, 2026 43:06


    With the RSA Conference on the horizon, Dennis and Lindsey are here with a preview of the conference's more interesting sessions and keynotes, a discussion of the recent and ancient history of the conference, and a quick game: Is this a security vendor or a prescription drug name?

    Mark Watney Is a Space Hacker in The Martian

    Play Episode Listen Later Mar 18, 2026 52:37


    Sure, space pirate is a cool title, but what about space hacker? Way cooler! With the imminent release of Project Hail Mary, Wendy Nather joins Dennis Fisher to dig into the nutrient-rich narrative soil that produced a modern classic that truly epitomizes the hacker ethos. We are the greatest podcasters on Mars!

    Fancy Tools From Fancy Bear, Another Proxy Network Takedown, and A Look Ahead

    Play Episode Listen Later Mar 13, 2026 15:50


    This week's news includes a reappearance by an old favorite, APT28, aka Fancy Bear, which is back with some nasty new implants and tools it is deploying against targets in Ukraine (2:10), and we also have another law enforcement disruption of a residential proxy network, this one known as SocksEscort, which had victims all over the globe (7:45). Lastly, we talk about some of the upcoming episodes, including a new hacker movie podcast and our RSA preview that's coming next week. LinksAPT28 reappears: https://decipher.sc/2026/03/10/apt28-reemerges-with-modern-espionage-arsenal-code-tied-to-2010s-operations/SocksEscort takedown: https://decipher.sc/2026/03/12/us-europol-crack-down-on-socksescort-residential-proxy-network/

    The Wild, Wild World of Exploits With Caitlin Condon

    Play Episode Listen Later Mar 10, 2026 46:05


    The process of developing and deploying exploits is a complex and controversial one and it's often a black box to outside observers. To help shine a light on how this all works, Caitlin Condon of VulnCheck joins Dennis Fisher for a deep dive into the zero day exploit landscape, what goes into exploit development, and what actually qualifies as a functional exploit.

    The Zero Day Landscape, Tycoon 2FA Disruption, and KEVology

    Play Episode Listen Later Mar 6, 2026 19:14


    Every day is zero day, and this week we talked about the new Google Threat Intelligence Group report on the zero day exploit landscape in 2025 (2:22) and who's exploiting what, then we discuss Microsoft's disruption of the Tycoon 2FA cybercrime operation (9:51), and finally we talk about the KEVology report from runZero and our new podcast with Tod Beardsley (13:25).

    We Need to Talk About KEV With Tod Beardsley

    Play Episode Listen Later Mar 2, 2026 47:09


    Tod Beardsley, VP of security research at runZero and former KEV section chief at CISA, joins Dennis Fisher to talk about the evolution of the Known Exploited Vulnerabilities catalog, how much value defenders should place on a specific bug being in the KEV, and his new KEVology report that breaks down all of the data in the KEV and sifts through it for specific insights for defenders.

    Cisco SD-WAN Zero Day, Google Disrupts Chinese Campaign, and More Cyber on The Pitt

    Play Episode Listen Later Feb 27, 2026 31:56


    This week Lindsey rejoins Dennis to talk about the attacks targeting a zero day in Cisco's Catalyst SD-WAN Controller (2:17), Google's disruption of a China-linked cyber espionage campaign targeting telecom infrastructure (6:30), and the new cyber developments on everyone's favorite tech show, The Pitt (13:13)!

    China Targets Dell Flaw, New Ivanti Exploitation, and Cyber Shenanigans on The Pitt!

    Play Episode Listen Later Feb 20, 2026 18:58


    It's a light news week, but we have some fun content for you! This week, we talk about our latest hacker movie episode--STAR WARS--which is up on the site and all of our feeds now (0:25), then we dig into a nasty hard-coded. credential bug in Dell RecoverPoint for Virtual Machines that Chinese threat actors are exploiting (4:20), and then we move on to an active campaign targeting two vulnerabilities in Ivanti EPMM that is hitting organizations across the U.S., Canada, and other countries (08:33). Finally, we talk a little about an interesting cybersecurity plot line on HBO's show The Pitt (12:15). Spoiler warning: If you're not caught up on this show, there's a minor spoiler, but nothing you haven't really seen in the previews. Support the show

    The Hacker Movie Canon: Star Wars

    Play Episode Listen Later Feb 18, 2026 64:35


    STAR WARS isn't just one of the more successful and iconic movies of all time and the basis for a worldwide sci-fi empire, it's also a true hacker story. Wade Baker and Rich Mogull, two Star Wars scholars, join Dennis Fisher to break down the Empire's pathetic perimeter defenses, R2D2's arc as a wily hacker, and how the movie hinges on a data breach.Support the show

    Six Zero Days From Microsoft, One From Apple, and a CSI: Cyber Throwback

    Play Episode Listen Later Feb 13, 2026 17:59


    This week was a cornucopia of zero days. We talk about the six (!) actively exploited vulnerabilities that Microsoft patched this week in its February update (2:46), then we discuss the one that Apple fixed in iOS 26.3, a vulnerability that has been used in what the company calls an "extremely sophisticated attack" against a few individuals (7:24). That's a clear indication that the vulnerability has likely been used in operations involving commercial spyware vendors. Finally, we give a little love to the long lost TV show CSI: Cyber, which starred James Van Der Beek, and the cameo that two famous hackers had on one episode (12:40). The old Threatpost CSI: Cyber running chat discussionSupport the show

    How to Stay Ahead of Attackers With watchTowr's Ryan Dewhurst

    Play Episode Listen Later Feb 9, 2026 49:38


    Attackers are moving faster and faster every day, and the challenge of keeping pace is a daunting one. But it's not impossible. watchTowr's Ryan Dewhurst joins Dennis Fisher to talk about how the "magic" of computers first captured his imagination when he was young, how defenders can learn  from attackers' tactics and adapt, and how the AI revolution is accelerating vulnerability disclosure and exploitation.Support the show

    ai attackers stay ahead dennis fisher ryan dewhurst
    Dumping Edge Security Devices, the SystemBC Botnet, and the Joy of Joybubbles

    Play Episode Listen Later Feb 6, 2026 16:56


    This week we talk about the new CISA Binding Operational Directive that sets a deadline for removing end of support edge security devices from federal government networks (1:15), then we discuss the new research from Silent Push on the new variant of the SystemBC botnet (6:45), and finally we have a movie recommendation for you: Joybubbles, the fascinating new documentary about phone phreaker Joe Engressia Jr.Support the show

    Fortinet and WinRAR Exploitation, Google's IPIDEA Disruption, and Our Favorite Cybersecurity Creators

    Play Episode Listen Later Jan 30, 2026 20:55


    It was a busy week in the cybers! Today we start with the targeted exploitation of another Fortinet vulnerability (CVE-2026-24858) that enables simple authentication bypass (1:15), then we discuss Google's disruption of a large residential proxy network called IPIDEA that has been abused by hundreds of threat actors (5:40), then we talk about the continued attacks on an older WinRAR bug by both cybercrime and APT groups (10:11). Finally, we shout out some of our favorite fellow creators in security community: the Three Buddy Problem podcast, John Hammond, and Matt Johansen. Support the show

    The RedVDS Takedown, Yet Another Chinese APT Emerges, and the StackWarp AMD Bug

    Play Episode Listen Later Jan 16, 2026 16:40


    This week, we talk about how Microsoft disrupted a long-running, large-scale cybercrime-as-a-service platform called RedVDS that has been active since 2019 and was used in high-volume phishing and BEC scams (1:00), then we discuss the research from Cisco Talos on another (!) Chinese APT called UAT-8837 that is targeting critical infrastructure organizations in North America (6:06), and finally there's the clever new StackWarp vulnerability in AMD processors that was disclosed this week (9:44).RedVDS takedownCisco Talos reportStackWarpSupport the show

    The Future of Vulnerability Management With Jeremiah Grossman and Robert "RSnake" Hansen

    Play Episode Listen Later Jan 13, 2026 64:56


    Jeremiah Grossman and Robert Hansen, two of the more influential and accomplished leaders and entrepreneurs in the cybersecurity community, have seen and done it all in their careers. From their roles as the driving forces behind pioneering web appsec firm WhiteHat Security to building out enterprise security programs to breaking large portions of the web (on purpose), Jeremiah and Robert have unique viewpoints on what works and what doesn't. Now, they're building something new, Root Evidence, a vulnerability management platform backed by data from actual breaches and designed to help security teams prioritize fixing the bugs that actually matter.Support the show

    hansen robert hansen vulnerability management whitehat security jeremiah grossman
    A New Chinese APT Debuts and React2Shell Attacks Spike

    Play Episode Listen Later Jan 9, 2026 14:06


    The new year is here! And so are the attacks. The first full week of 2026 brought us new research from Cisco Talos on a China-nexus APT group called UAT-7290 that is expanding its targeting and serving as an initial access group as well as a cyber espionage team (3:02). There is also some great data from GreyNoise on the attack volume from actors trying to exploit the React2Shell vulnerability from December (8:26). The volume is holding steady at more than 300,000 sessions per day, which is...high.Talos report: https://blog.talosintelligence.com/uat-7290/GreyNoise report: https://www.greynoise.io/blog/cve-2025-55182-react2shell-opportunistic-exploitation-in-the-wild-what-the-greynoise-observation-grid-is-seeing-so-farSupport the show

    The Hacker Movie Canon: Home Alone

    Play Episode Listen Later Dec 22, 2025 59:07


    There may not be any computers in Home Alone, but few movie characters embody the old-school hacker ethos like Kevin McCallister does. Resourceful, clever, determined, and creative, Kevin uses all of the tools and talents at his disposal to repel a pair of relentless adversaries. Merry Christmas ya filthy animals!Support the show

    Russian Targeting of Edge Devices. Cisco AsyncOS Zero Day, and React2Shell Won't Go Away

    Play Episode Listen Later Dec 19, 2025 21:25


    As we ease into the holidays, the security news doesn't stop coming. This week we discuss the research from AWS threat intelligence on Russian adversaries targeting a variety of network edge devices for opportunistic exploitation, then we break down attacks by a Chinese threat actor that target a new zero day in Cisco's AsyncOS, and finally we discuss the continued exploitation of the React2Shell vulnerability. Support the show

    The Hacker Movie Canon: Die Hard

    Play Episode Listen Later Dec 17, 2025 64:45


    Pete Baker and Zoe Lindsey join Dennis Fisher on the roof of Nakatomi Plaza to discuss one of the great action classics* and a beloved movie in the hacker community: Die Hard. Yippee ki-yay! *NOT a Christmas movieSupport the show

    More React Bugs Reaction, the Challenge of Vulnerability Management, and CI Attacks

    Play Episode Listen Later Dec 12, 2025 24:00


    This week gave us the gift of some more React Server Components vulnerabilities  and further exploitation of the previously disclosed bugs by a variety of threat groups. There were also a long list of vulnerabilities disclosed by Microsoft, Adobe, and others, which we discuss in the context of how difficult vulnerability management is right now. Finally, we discuss CISA's warning about continued Russian targeting of US critical infrastructure.GreyNoise report: https://info.greynoise.io/hubfs/At-The-Edge/Weekly-Intelligence-Brief-120825.pdf?_ga=2.212724369.466870115.1765553789-1325891860.1765553788Support the show

    From CIA Officer to a Career in Cybersecurity With Erin Whitmore

    Play Episode Listen Later Dec 10, 2025 81:42


    Coming from a military family, Erin Whitmore was prepared for a career of service. But her path took her not into the military, but the intelligence community, first in the private sector supporting the DIA and NGA, and later as a cybersecurty program manager in the Office of the Director of National Intelligence. She eventually joined CIA as an operations officer and served in locations around the world before moving back to the private sector where she now focuses on executive risk and strategic intelligence at CYPFER. Erin joins Dennis Fisher to talk about her unique path and how it's prepared her for today's threats and the nascent AI revolution.Support the show

    React2Shell, Typhoon Attacks, and Why Our Infrastructure is So Vulnerable

    Play Episode Listen Later Dec 5, 2025 33:33


    Dennis and Lindsey react (!) to the React2Shell vulnerability disclosure and the quick exploitation of it by Chinese threat actors, then discuss the continues intrusions into critical infrastructure by the Salt Typhoon actors and this week's congressional hearing on telecom network security. Finally, we talk about some upcoming hacker movie episodes, including Die Hard and maybe Home Alone!Support the show

    Jeff Gothelf on Designing for Users, Enterprise Agility, and the AI Conundrum

    Play Episode Listen Later Dec 2, 2025 41:12


    Jeff Gothelf, a renowned author and product strategist and co-founder of Sense and Respond Learning, joins Dennis to discuss the need to design products with users in mind, how critical thinking can help teams succeed, and what the AI revolution means for security teams and other groups.Support the show

    DoJ Sanctions, the SEC Abandons the SolarWinds Action, and the FCC Reverses Course on Telecom Security

    Play Episode Listen Later Nov 21, 2025 36:56


    It's an acronym-filled, government-only bonanza this week! We discuss the DoJ sanctioning Russian bulletproof hosting provider Media Land (0:53), the SEC dropping its enforcement action against SolarWinds and its CISO (13:25), and the FCC reversing course on a longstanding security rule for telecom providers (26:00).Support the show

    Rich Mogull on the Cloudflare Outage, Resilience, and Single Points of Failure

    Play Episode Listen Later Nov 18, 2025 24:52


    Dennis is joined by Rich Mogull, chief analyst at the Cloud Security Alliance, cloud security trainer, and all around good guy to talk about the Cloudflare outage, why the internet is now just six companies, and what, if anything, organizations can do to improve their resilience in the current environment. Support the show

    Lighthouse Phishing Kit Takedown, Zero Day Mysteries, and Measuring Cyber Attack Costs

    Play Episode Listen Later Nov 14, 2025 46:11


    This week was a bit of a throwback to olden times, with the disclosure by Amazon threat intelligence of  zero days in Cisco and Citrix products that were exploited by an unnamed APT, and Google using legal action to disrupt the Lighthouse phishing service operation. We dig into those two stories, plus we discuss the challenge of trying to quantify the financial and other effects of a major cyber attack. Related stories:https://decipher.sc/2025/11/12/apt-targets-cisco-and-citrix-zero-days/https://decipher.sc/2025/11/14/marks-and-spencers-profit-drop-the-financial-toll-of-cyberattacks/https://decipher.sc/2025/11/12/google-wants-to-snuff-out-lighthouse-phishing-kit/https://censys.com/blog/highway-robbery-2-0Support the show

    The Hacker Movie Canon: The Social Network

    Play Episode Listen Later Nov 13, 2025 73:02


    "You know, you really don't need a forensics team to get to the bottom of this. If you guys were the inventors of Facebook, you'd have invented Facebook." Melanie Ensign joins Dennis Fisher and Lindsey O'Donnell-Welch to discuss David Fincher's massively successful 2010 film, The Social Network, a movie that opens a window into the dark side of Silicon Valley and the lengths that some people will go to in order to win.Support the show

    Yahoo's Sean Zadig on How to Raise a Hacker Safely and How Maybe AI Isn't Changing Everything

    Play Episode Listen Later Nov 5, 2025 51:29


    Yahoo CISO and Chief Paranoid Sean Zadig returns to the podcast for a discussion with Dennis Fisher  about how to go about getting kids interested in technology and teaching them about hacking (in the broad, classical sense) safely (9:10). Then they talk about how rapidly the cybersecurity industry is changing and what effects AI is and is not having on offense, defense, and the job market (45:00).Support the show

    Shadow AI Is Eating the World, the Return of Hacking Team, and the Commercial Spyware Landscape

    Play Episode Listen Later Oct 30, 2025 41:28


    We don't do holiday themed episodes in this house, so no tricks, but we have some treats for you. First we discuss the problem of shadow AI (1:00) and how it seems like we're just repeating the mistakes of previous tech waves in ignoring security until it's too late. Then we dig into a new report from Kaspersky about a crazy exploit they discovered for a Chrome sandbox escape that led them to identify the new version of Hacking Team's spyware called Dante (23:00). Finally, we provide some important updates on our respective wildlife encounters (33:00).Kaspersky report: https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/ Support the show

    US Cybersecurity Going in Reverse, the AWS Outage, and is CISA Okay

    Play Episode Listen Later Oct 24, 2025 43:35


    This week saw a blessed lack of major vulnerabilities, but there was plenty of other news to dig into. We discuss the fallout from the AWS outage (0:36), the conclusions from the latest Cyberspace Solarium Commission report (4:37), and the effects of CISA's shakeup on the private sector (14:07), and the continued effects of the F5 incident (21:21). Finally, we have some extremely important updates on whether Dennis has a dog yet and a WILD story about woodland creatures in Lindsey's house that can not be missed! (32:50)

    The Hacker Movie Canon: Real Genius

    Play Episode Listen Later Oct 22, 2025 53:09


    Mitch, there's something you need to know. Compared to you, most people have the IQ of a carrot. Real Genius has it all: '80s movie icon Val Kilmer at his coolest, a brilliant hacker named Laszlo living in a closet, a giant space laser, and the absolute embodiment of the hacker ethos. Join us as we dig into this classic with our pal Wendy Nather. It's a moral imperative.Slate article on the inspiration for Jordan: https://slate.com/technology/2015/08/real-genius-30th-anniversary-how-i-helped-inspire-the-lead-female-character.html

    Breaking Down the F5 Breach

    Play Episode Listen Later Oct 16, 2025 27:12


    In the wake of the disclosure of a serious intrusion at F5 that reportedly lasted about a year, we talk about the details of the disclosure, the potential link to Chinese state actors, the fallout from the attackers' access to source code and bug reports, and what this could mean in the long term. 

    AI Attack and Defense With Adam Meyers and Elia Zaitsev of CrowdStrike

    Play Episode Listen Later Oct 15, 2025 57:26


    Have you heard about this AI thing? It's wild. Turns out, attackers are using it for all kinds of things we'd rather not have them doing. Dennis Fisher is joined by two experts from CrowdStrike--Adam Meyers, head of counter adversary operations, and Elia Zaitsev, CTO--to talk about how both defenders and attackers are leveraging AI and where things might be going in the next few years. 

    More Cl0p Clues and Huge Apple Bug Bounty Changes

    Play Episode Listen Later Oct 10, 2025 14:17


    This week brings some new insights into the origins and length of the Cl0p extortion attacks tied to the Oracle E-Business Suite vulnerability, big surges in scanning for Cisco ASA, Palo Alto, and Fortinet devices, and a huge upgrade to Apple bug bounty payouts.  Plus: Does Dennis have a dog yet?https://security.apple.com/blog/apple-security-bounty-evolved/https://decipher.sc/2025/10/08/data-connects-scanning-surges-for-cisco-fortinet-pan-devices/https://decipher.sc/2025/10/09/oracle-clop-data-theft-campaign-started-months-ago/

    The Hacker Movie Canon: WARGAMES

    Play Episode Listen Later Oct 8, 2025 64:30


    What you see on these screens up here is a fantasy; a computer-enhanced hallucination. WarGames may be 42 years old (!) but its prescience about our current technocracy and race to take humans out of the loop is as clear as ever. Dennis Fisher, Lindsey O-Donnell-Welch, Zoe Lindsey, and Pete Baker sit down in front of an IMSAI 8080 with some raw corn on the cob and a can of Tab to talk about this brilliant hacker movie classic. 

    Claim Decipher Security Podcast

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel