Podcasts about Black hat

  • 1,266PODCASTS
  • 3,282EPISODES
  • 49mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 2, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Black hat

Show all podcasts related to black hat

Latest podcast episodes about Black hat

The CyberWire
Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

The CyberWire

Play Episode Listen Later Aug 2, 2026 24:03


In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host ⁠Dave Bittner⁠ to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research in the Agentic Age." Join Yan and Dave to hear insights on the evolution of vulnerability research, the impact of AI and LLMs on cybersecurity, and the future of human expertise in the field. If you are heading to Black Hat, check out Yan's session on Thursday, August 6 at 9:15 AM.

The CyberWire
Claude outside the lines.

The CyberWire

Play Episode Listen Later Jul 31, 2026 30:39


Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon's blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm's tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data breach, a stealthy cryptominer hides in plain sight, AiTM phishing surges against law firms, and Finland severs one more digital link to Russia. Our guest is Yan Shoshitaishvili, Associate Professor, Arizona State University, previewing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." AI scammers may deserve a promotion. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Yan Shoshitaishvili, Associate Professor, Arizona State University, discussing his Black Hat 2026 keynote "Vulnerability Research in the Agentic Age." Be sure to tune in this Sunday for a special edition featuring our full, extended interview with Yan. Selected Reading Anthropic AI Models Hacked Three Organizations During Tests (Bloomberg) Anthropic, Pentagon Clash Over First Amendment Claims (GovInfo Security) EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels (SecurityWeek) FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers Meta and Snap (TechCrunch) Wordfence Finds Critical Backdoor in ARVE WordPress Plugin (Hackread) CareCloud Data Breach Impacts Over 350,000 (SecurityWeek) Cryptominer Abuses Linux PAM to Hide From SOC Analysts (Infosecurity Magazine) AiTM Phishing Becomes Top Initial Access Threat to Law Firms (Infosecurity Magazine) Finland to disconnect fiber-optic link to Russia as lease expires (The Record) AI Scammers Are Better at Building Trust Than Humans (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Mercedes In The Morning
MITM #2525 The "Black Hat Convention" One

Mercedes In The Morning

Play Episode Listen Later Jul 31, 2026 67:13


*5:00am: Slang From The 2010s *6:00am: Is This Prank Cruel? *7:00am: Audio Only Concert Tickets *8:00am: Black Hat Convention

ITSPmagazine | Technology. Cybersecurity. Society
Vulnerability Backlogs Can Finally Reach Zero | A Brand Spotlight Conversation with Ondrej Vlcek, Co-Founder and CEO of AISLE | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 31, 2026 17:45


Security leaders count open vulnerabilities in the hundreds of thousands, and in some organizations the number runs past a million. Ondrej Vlcek, Co-Founder and CEO of AISLE, describes teams with no practical route through that backlog while attackers use automation to shrink the time between a disclosure and a working exploit. The question worth asking is what a program looks like when remediation moves at the same speed as exploitation. What makes AI-driven remediation different from static code analysis? Reasoning replaces pattern matching. Linters and commercial scanners flag code that resembles a known error shape, while a reasoning model infers what the developer intended, compares that intent against the actual implementation, and evaluates how the gap could be abused. Ondrej Vlcek points to business logic flaws, timing errors, and race conditions as the classes that pattern matching leaves untouched. The judgment behind AISLE comes from a long run in the industry. Ondrej Vlcek wrote device drivers for Windows 95 in 1995 at a seven-person antivirus company called Avast, stayed more than twenty-five years, moved through CTO and COO into the CEO seat, and took the company public before its sale to NortonLifeLock in 2022. He co-founded AISLE in 2024 with Jaya Baloo, a three-time public company CISO, and Stanislav Fort, an AI researcher who worked at DeepMind and Anthropic. Why does the software supply chain deserve the larger share of attention? Because most of the code in a running application was written somewhere else. Ondrej Vlcek puts the typical enterprise application at roughly ten percent first-party code and ninety percent open source and dependency code, which is also level ground for an attacker reading the same source and pointing the same models at it. Reachability analysis becomes the deciding factor, separating the vulnerable functions your code actually calls from the thousands of transitive dependencies it never touches. For first-party code, AISLE closes the loop differently: read the documentation, the architectural material, and the threat model, then generate a patch aligned with the project's own conventions and test it automatically. The standard Ondrej Vlcek sets is a fix that reads as though a human maintainer wrote it. The customer spread runs from embedded firmware at Bose to smart contracts at the Ethereum Foundation, where heavily audited and sometimes formally verified code still benefits from another set of checks because the systems touch money flows directly. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Ondrej Vlcek, Co-Founder and CEO of AISLE On LinkedIn: https://www.linkedin.com/in/ondrejvlcek/ RESOURCES Learn more about AISLE: https://aisle.com Meet AISLE at Black Hat and DEF CON in Las Vegas: https://aisle.com/black-hat The AISLE platform: https://aisle.com/platform AISLE CVE discoveries: https://aisle.com/cve-discoveries Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS ondrej vlcek, aisle, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, vulnerability management, vulnerability remediation, agentic ai, cyber reasoning system, software supply chain security, reachability analysis, open source security, application security, first-party code, third-party dependencies, static code analysis, zero-day vulnerabilities, ai in cybersecurity, code patching, embedded firmware security, smart contract security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The Cybersecurity Defenders Podcast
Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 30, 2026 30:14


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.Stories covered:• https://huggingface.co/blog/security-incident-july-2026• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plantChapters:0:00 Intro & Black Hat plans2:07 Hugging Face's AI-agent breach disclosure12:39 WP2Shell: WordPress exploit chain20:59 Suno & Paidwork data breaches24:17 IRGC strikes on AWS Bahrain28:27 Google Threat Intel's new actor names29:29 Black Hat swag hunt & wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #databreach

Paul's Security Weekly
Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458

Paul's Security Weekly

Play Episode Listen Later Jul 29, 2026 41:10


Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type. Segment 1 Resources: https://www.PredictableProfits.com Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-458

Talos Takes
Q2 Talos IR Trends: Phishing and authentication abuse spike

Talos Takes

Play Episode Listen Later Jul 29, 2026 15:50 Transcription Available


In this episode, Amy and analyst Lexi DiScola unpack the trends Talos IR saw on the frontlines in Q2 2026. From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, we explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage.What configuration changes and visibility gaps  could be the difference between a minor incident and a full-scale breach? How can you harden your environment with limited resources? Tune into this episode to stay one step ahead of an evolving threat landscape.Talos IR Quarterly Trends Report: https://blog.talosintelligence.com/ir-trends-q2-2026Find Talos at Black Hat: https://blog.talosintelligence.com/preview-cisco-talos-at-black-hat-usa-2026/

Paul's Security Weekly TV
Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458

Paul's Security Weekly TV

Play Episode Listen Later Jul 29, 2026 41:10


Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type. Segment 1 Resources: https://www.PredictableProfits.com Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Show Notes: https://securityweekly.com/bsw-458

Easy Prey
Convincing Deepfakes

Easy Prey

Play Episode Listen Later Jul 29, 2026 57:43


A familiar voice on the phone or a recognizable face on a video call used to offer some reassurance that you knew who you were dealing with. AI has changed that. Voice cloning, face swaps, and real-time video impersonation now allow scammers to convincingly pose as executives, job candidates, romantic interests, or even family members. Understanding how these attacks work and where they may be headed is a central part of Tom Cross's work as Head of Threat Research at GetReal Security. Tom has spent more than 30 years studying cybersecurity threats, software vulnerabilities, and the methods attackers use to exploit technology. Before joining GetReal Security, he held leadership roles at IBM X-Force, Lancope, and Drawbridge Networks, and he has shared his research at major security conferences including Black Hat and DEF CON. His current work focuses on deepfake-enabled social engineering and the development of tools that can detect digital impersonation, including signs that are often too subtle for a person to recognize. In this episode, we learn how little audio is needed to clone someone's voice, why live video is no longer reliable proof of identity, and how deepfakes are being used in romance scams, investment fraud, identity theft, and remote hiring schemes. We also talk about AI agents that can carry on persuasive conversations, adjust their behavior based on a victim's reactions, and repeat those tactics on a massive scale. The discussion offers a revealing look at why familiar advice for spotting fakes is quickly becoming outdated and what individuals and organizations will need to do differently as the technology improves. Show Notes: [01:05] Tom shares how his early work in vulnerability research led to a career studying sophisticated cybersecurity threats. [03:32] Running a bulletin board system as a teenager helped spark an enduring interest in hacking and computer security. [06:11] A look back at early online communities, text-based games, Fidonet, and the pre-internet era. [09:36] The conversation shifts to deepfake research and the technology being developed to detect manipulated media. [11:29] Deepfakes are divided into audio, visual, file-based, and real-time forms, each creating different risks. [15:20] Modern voice clones can fool both people and biometric authentication systems, making specialized detection increasingly important. [18:30] Virtual backgrounds and other subtle processing artifacts may reveal manipulation even when nothing looks obviously wrong. [20:31] Deepfake detection has become another cybersecurity arms race as attackers continually improve their methods. [22:30] Romance scams, investment fraud, remote job schemes, and identity theft are among the growing uses of deepfake technology. [25:26] Scammers succeed by exploiting desires, expectations, and the human tendency to rationalize warning signs. [27:56] Large-scale phishing and business email compromise attacks only need a small percentage of targets to respond. [29:22] Criminal compounds in Southeast Asia use trafficked workers and deepfake tools to conduct scams on a massive scale. [30:27] North Korean remote workers may use stolen identities and shared deepfake personas to secure jobs at American companies. [33:45] Purpose-built criminal software combines face swapping with appearance-enhancing features designed for romance scams. [35:05] Common visual tests for identifying deepfakes are becoming unreliable as the technology advances. [39:24] Emotional investment makes detection even harder because people often explain away signs that something is wrong. [40:47] Building authentication into the internet could help people determine whether digital content is genuine. [42:13] AI agents may soon conduct automated scams that respond naturally, apply pressure, and adjust to a victim's behavior. [45:14] Automation could allow criminals to target hundreds of thousands of people while making impersonation increasingly convincing. [46:22] Machine learning may create self-improving scams that test countless variations and concentrate on the tactics that work. [49:18] AI lowers the technical barrier to cybercrime by helping people create tools they could not build on their own. [51:06] Phones and messaging platforms may eventually require stronger controls as automated calls and texts become more common. [53:09] Digital signatures, watermarks, and verified content could help distinguish malicious deepfakes from authorized uses. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest GetReal Security Tom Cross - LinkedIn

Business Security Weekly (Audio)
Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458

Business Security Weekly (Audio)

Play Episode Listen Later Jul 29, 2026 41:10


Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type. Segment 1 Resources: https://www.PredictableProfits.com Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-458

Business Security Weekly (Video)
Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458

Business Security Weekly (Video)

Play Episode Listen Later Jul 29, 2026 41:10


Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type. Segment 1 Resources: https://www.PredictableProfits.com Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Show Notes: https://securityweekly.com/bsw-458

The Film Stage Show
The B-Side Ep. 188 – Michael Mann (with Blake Howard)

The Film Stage Show

Play Episode Listen Later Jul 28, 2026 130:46


Welcome to The B-Side! Here we talk about movie directors! Not the movies that made them famous or kept them famous, but the ones that they made in between. Today we discuss the great Michael Mann! Our B-Sides are The Keep, Public Enemies, Blackhat, and Ferrari. Our guest is the iconic Blake Howard of One Heat Minute Productions. We discuss the troubled making of The Keep, as well as that incredible Tangerine Dream score. The legendary Twilight Zone episode “The Howling Man” also comes up. There's also mention of how many movies about the French-Indian War there are (spoiler alert: not many!) Blake, Conor, and Dan Mecca discuss the legacy of Mann and his recent output of underappreciated films. Why is it that Michael Mann's films are often released to lesser success than their long-term reputations suggest? There's celebration of Mann's ever-evolving digital aesthetic, conversation about the contentious star-director relationship on the set of Public Enemies, and his demanding, exacting instincts. As legendary producer Amy Pascal once put working with the director: “You forget about the pain of childbirth too. I mean, whatever you go through, you still want another baby. It's like that with Michael too.”

Paul's Security Weekly
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469

Paul's Security Weekly

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a “dumb phone”? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-469

Security. Cryptography. Whatever.
An Odyssey of Lattice Cryptography with Mark Schultz-Wu

Security. Cryptography. Whatever.

Play Episode Listen Later Jul 27, 2026 77:09 Transcription Available


We invited Mark Schultz-Wu on the podcast to talk about the history of lattice cryptography. When lattices are explained in plain english, they are actually quite simple! I don't think any of us have ever seen Deirdre so happy. If you're watching the video version, there's a section that's 6.1 minutes long with no cuts and consists just of Deirdre vigorously agreeing with what Mark is saying while smiling. What a time to be alive.Anyway, we are hosting another happy hour in Vegas between Black Hat and DEF CON! It's sponsored by Teleport! Thank you to Teleport, and dear readers, you should go check them out. Check out our socials or the podcast site to register.Transcript: https://securitycryptographywhatever.com/2026/07/27/lattices-with-mark-schultz-wu/Links:Mark's IETF Post https://mailarchive.ietf.org/arch/msg/tls/HznE1IcCjstEjhh4M1p59qX1JlQ/NTRU https://en.wikipedia.org/wiki/NTRUThe original lattices are hard paper https://www.scirp.org/reference/referencespapers?referenceid=3401227The original LWE for cryptography paper https://arxiv.org/abs/2401.03703Entropic LWE https://eprint.iacr.org/2020/119Dilithium round 3 submission: https://pq-crystals.org/dilithium/data/dilithium-specification-round3.pdfRecent attacks on Classic McEliece: https://eprint.iacr.org/2024/1694Lectures on post-quantum cryptography from Alfred Menezes (an originator of elliptic curve cryptography) https://www.youtube.com/@cryptography101-alfredFalcon https://csrc.nist.gov/csrc/media/Presentations/2024/falcon/images-media/prest-falcon-pqc2024.pdfRegev: https://cims.nyu.edu/~regev/#researchTightness in Proofs: https://eprint.iacr.org/2016/360.pdf"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

Enterprise Security Weekly (Audio)
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a "dumb phone"? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-469

Paul's Security Weekly TV
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - O'Shea Bowens, Jeremiah Grossman - ESW #469

Paul's Security Weekly TV

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a "dumb phone"? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-469

Enterprise Security Weekly (Video)
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - O'Shea Bowens, Jeremiah Grossman - ESW #469

Enterprise Security Weekly (Video)

Play Episode Listen Later Jul 27, 2026 110:45


Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a "dumb phone"? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-469

Hacking Your Health
Def Con - A We Hack Health Survival Guide

Hacking Your Health

Play Episode Listen Later Jul 21, 2026 34:48 Transcription Available


Defcon is the biggest conference in the cybersecurity world accompanied with BlackHat and BSides Las Vegas - Hacker Summer Camp can be a difficult one to manage - join us this week where we break down how we plan to stay on top of our goals while battling Vegas. If you want more: https://www.wehackhealth.com/Book a coaching call hereSupport the showWant to know more about coaching? Book a call with Ben hereWhere to find usWe Hack Health: TwitterWe Hack Health: InstagramWe Hack Health: DiscordCheck out Overclock and Protein Protocol here 

BarCode
Monzy Merza

BarCode

Play Episode Listen Later Jul 17, 2026 31:10


Crogl calls it a Knowledge Engine for Security Operations, and the idea is simple: analysts are drowning in alerts, and cutting corners isn't the fix. Every alert deserves a real look. So Crogl built an AI that works alongside the analyst, not instead of them, an assistant one investor called an "Iron Man suit" for security researchers. The goal isn't to replace the team. It's to make every single analyst as effective as the whole team combined. Monzy Merza, Co-founder and CEO of Crogl, joins us today on BarCode to talk community, what's coming at Black Hat, and why the best defense in cybersecurity might just be showing up and sharing what you know.SYMLINKS[Crogl] - https://crogl.com An AI-powered security operations platform that helps security teams investigate alerts, perform threat hunting, and automate cybersecurity workflows while keeping customer data within their own environment.[Monzy Mirza – LinkedIn] - https://www.linkedin.com/in/monzymerza/ The official LinkedIn profile of Monzy Mirza, Co-founder and CEO of Crogl, where he shares insights on AI, cybersecurity, and security operations.[MITRE ATT&CK® Framework] - https://attack.mitre.org/ A globally recognized cybersecurity knowledge base maintained by MITRE that documents adversary tactics, techniques, and procedures (TTPs). Crogl references the framework for investigating security alerts and threat hunting.[CISA] - https://www.cisa.gov/ The U.S. Cybersecurity and Infrastructure Security Agency. The episode discusses using CISA advisories, such as those related to Volt Typhoon, as inputs for threat hunting.[Volt Typhoon Advisory] - https://www.cisa.gov/news-events/cybersecurity-advisories CISA's collection of official cybersecurity advisories, including guidance on the Volt Typhoon threat actor. The episode references uploading these advisories into Crogl for automated threat hunting.[Slack] - https://slack.com/ A workplace collaboration platform. Crogl provides customers with access to a Slack community where users can interact directly with the engineering team and provide product feedback.[Black Hat USA] - https://www.blackhat.com/us-25/ One of the world's leading cybersecurity conferences. Monzy mentions that the Crogl team will host a booth, hackathon, and community sessions during Black Hat.

Resilient Cyber
Cyber Valuations, Moats & the Road to Black Hat

Resilient Cyber

Play Episode Listen Later Jul 16, 2026 41:54 Transcription Available


Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat.Sid is a Partner at Foundation Capital, where he invests at the seed and Series A stage with a focus on cybersecurity and IT infrastructure. This is our annual pre-Black Hat check-in, and a lot has moved since last year, from massive M&A to record-setting rounds in categories like the AI SOC.In this episode:- What has actually changed a year into the AI wave, and what hasn't- Services-as-software, the $4.6 trillion market thesis, and automating cyber workflows across the SOC, IR, pen testing, and threat intel- What AI means for cybersecurity jobs and how practitioners should adapt- Consolidation vs. best-of-breed after Palo Alto's $25B CyberArk deal and Alphabet's $32B Wiz acquisition- AI SOC valuations, including Seven AI's record Series A and Torq crossing a $1B valuation- The double-edged sword of big raises and why founders should be cautious about the valuations they accept- Why you can't simply spend your way to growth in cybersecurity- Moats and defensibility when frontier labs can push into your category- The Black Hat Innovator Investor Summit and the Startup Spotlight competitionChapters:0:00 Intro0:52 What's changed a year into the AI wave2:42 Services-as-software and the AI SOC9:38 AI adoption and forward deployed engineers10:57 M&A, platformization, and best-of-breed14:17 IT and security convergence, plus AI SOC valuations18:48 Seed-stage risk calculus vs. later-stage investors21:43 The double-edged sword of big raises26:20 Why you can't spend your way to growth29:05 Moats and defensibility in the frontier-lab era32:25 Deal flow, pricing, and staying disciplined37:06 Black Hat Innovator Investor Summit40:17 Startup Spotlight competition43:28 Wrap-upBlack Hat is offering listeners $500 off registration with code USA500Resilient.Connect with Sid:LinkedIn: https://www.linkedin.com/in/siddhanttrivedi/Foundation Capital: https://foundationcapital.comResilient Cyber: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners, founders, and leaders.

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Want a sharper read on motivation design? Get the free Core Drives in the Wild guide, real cases decoded through this exact framework, one short email a day: professorgame.com/WildCD Episode Summary Rob argues that Black Hat motivation, the urgency and scarcity most designers treat as the villain, is the on-ramp that gets people to act at all. He breaks down the Octalysis Group's award-winning project with Procter & Gamble's distributor Navo Orbico, which reached 99.5% voluntary participation on a non-compulsory rollout and a 28.6% revenue increase by starting with pressure and handing off to meaning. Drawing on Ocean Hero as the rare frictionless exception, he shows why White Hat drives like Epic Meaning seldom start action on their own. Listeners learn the Black-Hat-to-White-Hat handoff and two diagnostic questions to test whether their own system can make the switch. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways The Octalysis Group's project with Procter & Gamble reached 99.5% voluntary participation on a non-compulsory rollout and a 28.6% revenue increase, evidence that Black Hat urgency and White Hat meaning work in sequence, not opposition. In the Octalysis framework, Black Hat and White Hat motivation are not good and evil. Black Hat (urgency, scarcity, pressure) gets people to act now; White Hat (meaning, empowerment) makes them glad they stayed. Relying only on grand meaning and Core Drive 3 (Empowerment of Creativity and Feedback) tends to produce a "someday," which in practice means never, because wanting to act is rarely a strong enough forcing function to overcome friction. The P&G rollout launched using Core Drive 5 (Social Influence and Relatedness) as pressure: getting into the system meant tracking down colleagues for an access code, which sparked FOMO (Core Drive 8) and curiosity (Core Drive 7) rather than belief in a grand vision. After the on-ramp, the system handed off to White Hat: reps became captains of trading ships, territories became open seas, and clients became colonies, activating Core Drive 1 (Epic Meaning) and Core Drive 2 (Development and Accomplishment). Ocean Hero is the rare case where White Hat alone starts action, because switching a search engine is one click of near-zero friction, so Core Drive 1 can carry the behavior with no urgency at all. Topics Covered 0:00 — Opening hook: why products stall 1:14 — The P&G result: 99.5% voluntary 3:05 — Black Hat and White Hat serve different moments 4:53 — The frictionless exception: Ocean Hero 6:07 — Inside the P&G rollout 7:30 — The handoff: reps become ship captains 9:16 — When Black Hat never matures into more 10:09 — Two diagnostic questions for your system 11:27 — What a mistimed handoff looks like 12:06 — Black Hat starts, White Hat sustains Mentioned in This Episode The Octalysis Group case study with Procter & Gamble's distributor Navo Orbico (Gamification Project of the Year, first presented in Brighton): 99.5% voluntary participation, 28.6% revenue increase Ocean Hero, the search engine whose revenue funds clearing plastic from the oceans (a project supported by The Octalysis Group) The Octalysis framework: Black Hat and White Hat motivation, and Core Drives 1 through 8 Episode 446, the airline miles loyalty teardown Episode 450, Amazon's internal AI leaderboard Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Search with Candour
How to rank in ChatGPT and AI search: Get AI traffic with listicles

Search with Candour

Play Episode Listen Later Jul 13, 2026 68:03


Léo Poitevin, founder and CEO of Astrak Agency, joins Search with Candour to discuss why your competitors may be recommended in ChatGPT and other AI search tools while you are not.Topics discussed:Why AI search engines are easier to manipulate than GoogleHow to identify competitors in AI searchHow to build trust signals for AI searchHow to use listicles and guest posts to rank in AI searchThe risks of self-promotional listiclesFollow Léo:Astrak Agency: https://astrak.agency/en/LinkedIn: https://www.linkedin.com/in/leo-poitevin/YouTube: https://www.youtube.com/@leopoitevinGet your tickets for SearchNorwichXLChapters00:00 Highlights of Léo Poitevin01:03 Introduction05:24 Leo's SEO background07:14 Are LLMs easier to game than Google?07:47 Google is good at fighting spam12:36 AI competitor research15:16 Competitor research for GEO19:47 Tracking volatility25:13 Imperfect data and KPIs for AI search30:11 A listicle strategy that works for LLMs33:01 Léo case studies36:07 The risks of listicles37:16 Self promotional listicles38:04 Ranking shifts in ChatGPT39:06 Listicles penalised by Google41:48 Testing new limits43:05 Links versus mentions46:18 Black Hat vs White Hate SEO49:15 Influencers and guest posts52:34 What hurts AI search56:20 Recommendation: Actionable tip57:51 Recommendation: Tool59:57 Recommendation: Cozy games01:05:14 Where to follow Léo01:06:44 Episode wrap-up

Resilient Cyber
Building an AI AppSec Engineer

Resilient Cyber

Play Episode Listen Later Jul 11, 2026 31:04


JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once. We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.Key takeawaysGecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.Chapters00:00 Meet JJ and Ryan02:46 Why Gecko is an AI security engineer, not another scanner05:07 The trend of agentic and headless security tools05:53 Why business logic breaks traditional SAST06:27 The no-auth endpoint example and context outside the code09:06 Attackers think in graphs, defenders think in lists11:02 Commoditized exploit dev and the internet as one bug bounty13:55 Shift left and why MTTR is a broken metric15:07 Eliminating entire classes of vulnerabilities15:51 Recurrence rate and avoiding risky refactors18:22 The Cal.com case study and open source going closed20:48 Consolidation and the shiny object problem in security22:40 Where AI-driven AppSec lands in two years27:12 What it takes to trust an AI security engineer28:57 Where to find Gecko and the Black Hat talk

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Episode Summary Michael Lukich, a marketing analytics leader with more than 20 years across consulting, data, and strategy, explains why the fix for a struggling team is almost never more effort. He walks through the closed-loop trap he built early in his management career, the systems thinking tools he now uses to find leverage points, and why over-measuring single marketing channels quietly starves the top of the funnel. Drawing on the Cabreras' DSRP model, Donella Meadows, and nearly 25 years at the poker table, he shows how to see a whole system instead of optimizing one piece to the detriment of the goal. Listeners come away with a practical way to map any system, pick a single North Star metric, and design loops that let a team improve on its own. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Michael Lukich's early management trap was a closed loop with no exit: he could not step away until the team improved, and the team could not improve until he stepped away, which pushed him to 75-hour weeks before he redesigned the loop instead of adding effort. Accepting work at roughly 70 percent of his own output, paired with a tighter review cadence, let his team feel the consequences of their own decisions and turned him from a micromanager into a player coach. The "if you can't measure it, it doesn't exist" credo pushes budget toward easily measured lower-funnel channels and leaves the top of the funnel leaky, because no one can defend upper-funnel spend in a boardroom. The fix is whole-system measurement through multi-channel attribution and mixed models, not more measurement. Zynga over-relied on data and stacked Black Hat Core Drives that drive urgency and scarcity, a reminder that an A/B test measures one week, not how a feature performs as a system over two years. Derek and Laura Cabrera's DSRP model (Distinctions, Systems, Relationships, Perspectives) gives a four-part way to map almost any system, then find the bottleneck where one move has the biggest outsized effect. Poker trains decision-making under uncertainty and incomplete information, including the faulty learning loop where playing well can still lose and playing poorly can still win, which is why Michael says half the frameworks in his book started at the poker table. Topics Covered 0:00 — The loop you cannot escape 0:20 — Meet Michael Lukich: data, teaching, poker 2:41 — Designing your own life as a system 5:46 — Promoted into a trap with no exit 11:14 — The marketing measurement trap 13:53 — Frankenstein products, Zynga, and Black Hat 17:34 — A practical system: pick one metric 18:56 — Mapping systems with DSRP 22:23 — The strategy dashboard and the North Star 24:07 — James Clear, Ryan Holiday, and one book 26:54 — Translation and poker as the perfect game 30:25 — Where to find Michael and closing advice Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD About Michael Lukich Michael Lukich is a marketing analytics leader with more than 20 years across consulting, data, and business strategy, currently running marketing analytics for a major US marketing agency. He spent five years as an adjunct professor and has played poker for nearly 25 years, two habits that shaped how he thinks about teaching and making decisions under uncertainty. He writes the Stoic Systems Thinker newsletter, where ancient Stoic philosophy meets modern systems thinking, and is the author of the book of the same name. He lives in Ann Arbor, Michigan with his wife and two daughters. Find Michael Lukich Online The Stoic Systems Thinker (website and newsletter) LinkedIn The Stoic Systems Thinker on Substack Mentioned in This Episode Some links below are affiliate links. As an Amazon Associate, I earn from qualifying purchases. Thinking in Systems by Donella Meadows James Clear and Atomic Habits Ryan Holiday Poker The Stoic Systems Thinker by Michael Lukich Derek and Laura Cabrera's DSRP model (Distinctions, Systems, Relationships, Perspectives) Meditations by Marcus Aurelius Zynga The Octalysis Framework and Black Hat Core Drives Kaizen and Kaikaku (continuous improvement versus radical change) Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

The Cybersecurity Defenders Podcast
Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 1, 2026 30:01


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.Chapters:0:00 Intro & catching up2:25 Cisco CUCM exploited within 24h of the PoC9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce & Warlock15:44 Gamaredon's upgraded TTPs against Ukraine22:18 Can AI email agents be phished?28:08 Wrap-up: Black Hat plans & the LimaCharlie suiteThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #ransomware #DFIR

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products, with one real-world example in your inbox each day: professorgame.com/WildCD Episode Summary Rob breaks down why disconnecting on vacation is so hard for driven people, and why it is a motivation problem rather than a willpower one. He maps the specific Octalysis Core Drives that keep high achievers tied to work during a break, including Core Drive 2 (progress addiction), Core Drive 8 (FOMO and Black Hat urgency), and Core Drive 1 (the mission needs me trap). Drawing on his own routine of leaving the phone at the apartment near the beach, he shows how to name each drive and switch off its trigger before the break starts. Listeners learn a pre-break diagnostic and how to design time off the same way they would design a user's exit from an engagement loop. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Driven people stay tied to work on vacation because their Core Drives keep firing in the background. This is a motivation issue, which is why pure willpower so often fails to deliver real rest. Core Drive 2 (Development and Accomplishment) shows up as progress addiction. With no momentum at work, a break can feel like your progress is being trumped, which pulls you back to the phone to make something move. Core Drive 8 (Loss and Avoidance) is Black Hat motivation built on FOMO. The fear that something breaks, or that everyone else is still shipping, creates urgency and pushes you to check in even when nothing is wrong. Core Drive 1 (Epic Meaning and Calling), the sense that the mission needs you, is the noble sounding trap. It can justify sacrificing rest you have earned, so naming it is what lets you stop it from firing back. The fix is to design your break the way you would design a user's exit from an engagement loop: kill the notifications, remove the triggers (Rob leaves his phone at the apartment), and push yourself out instead of staying half in. A real emergency that truly needs you is rare, roughly 0.1 percent of the time. Plan ahead, brief your team on what actually counts as an emergency, and trust them to handle the other 99.9 percent without you. Topics Covered [0:00] Why driven brains can't switch off [0:49] Disconnecting is a motivation problem [1:21] Core Drive 2: progress addiction [1:54] Core Drive 8: FOMO and urgency [2:30] Core Drive 1: the mission trap [3:08] Name the drive, deactivate the trigger [3:54] Leaving the phone at the beach [4:50] Why productive resting backfires [6:00] Design your break like an engagement loop [6:36] Diagnose your pull-back drive first [8:05] Rest is switching off the drives Mentioned in This Episode Core Drives in the Wild, Rob's free guide (one Core Drive example per day) The Octalysis Group The Octalysis Framework and its Eight Core Drives (Yu-kai Chou), the basis for Core Drives 1, 2, 5, and 8 discussed here Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

The Shared Security Show
Jay Beale on Kubernetes, DEF CON, and AI Attack Paths

The Shared Security Show

Play Episode Listen Later Jun 29, 2026 38:20 Transcription Available


This week on Shared Security, Tom and Kevin sit down with Jay Beale — founder of InGuardians, long-time Black Hat trainer, creator/contributor behind Kubernetes security training, and part of the team behind the DEF CON Kubernetes CTF. Jay shares stories from decades of offensive security work, including the time Tom hired him for a physical penetration test and Jay somehow ended up inside a call center instead of stuck in the lobby. The crew also digs into what makes good security training, why Kubernetes is such a natural platform for both defenders and attackers to understand deeply, and how the DEF CON Kubernetes CTF is designed to be welcoming for both competitors and learners. The episode closes with a practical look at AI infrastructure risk. Jay explains how production AI stacks running on Kubernetes can be attacked like any other cluster — and how modifying a vector database behind a RAG system can turn indirect prompt injection into a persistent, high-impact attack path.** Links mentioned on the show **Jay's Black Hat USA Course: Agentic AI-aided Kubernetes Attack and Defensehttps://blackhat.com/us-26/training/schedule/index.html?day=4daysattue#agentic-ai-aided-kubernetes-attack-and-defense-51318Jay Beale on LinkedInhttps://www.linkedin.com/in/jaybeale/InGuardianshttps://www.inguardians.com/DEF CONhttps://defcon.org/** Watch this episode on YouTube **https://youtu.be/aMHk62dprDA** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

The Rebbe’s advice
4150 – Deliberation on Adopting Lubavitch Dress and Black Hat – התחבטות על אימוץ לבוש חב"די ומגבעת שחורה

The Rebbe’s advice

Play Episode Listen Later Jun 29, 2026


The Rebbe advises not to rush into adopting Lubavitch dress, such as a long coat and black hat, especially when uncertain and facing family opposition. Instead, he suggests focusing on diligent Torah study, particularly Chassidus, and reconsidering the decision later. https://www.torahrecordings.com/rebbe/igroskodesh/012/006/4150

ITSPmagazine | Technology. Cybersecurity. Society
Where Data Sovereignty and Always-On Security Operations Meet | A Brand Spotlight at Infosecurity Europe 2026 with Bill Peterson, Senior Director of Product Marketing of Sumo Logic

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 12, 2026 16:31


At Infosecurity Europe 2026 in London, Bill Peterson, Senior Director of Product Marketing at Sumo Logic, joins us to unpack a tension every regulated security team knows well. When an incident hits, the business has to keep running. At the same time, regulators expect sensitive data to stay in region. For a long time, those two demands have pulled in opposite directions. Sumo Logic has spent 15 years as a SaaS platform on AWS, processing roughly four exabytes of data a day for around 2,000 customers. The core promise is speed, driving mean time to resolve as low as possible. Peterson frames it in business terms, because the person signing the check wants to know the return, not the bits and bytes. The news from the show is Sumo Logic availability on the AWS European Sovereign Cloud. EU organizations can keep their data in region, handled by EU staff, while still running the full platform for incident response. That turns a painful either/or into a checklist a regulated buyer can complete. Genesys is the first customer live in the sovereign cloud, with payment processor OpenPay preparing to follow. How does this play out for highly regulated industries? Sumo Logic is focused on finance, healthcare, telco, and government, the verticals feeling the most pressure. The path Peterson describes is simple: let Sumo Logic handle incident management, let AWS move and grow the data in region, and check the sovereignty box without giving up operational readiness. Underneath sits a full-featured SIEM and Dojo AI, the agentic approach Sumo Logic launched earlier this year. The goal is not to replace analysts but to keep a human in the loop while handing proven, repetitive work to an agent. Fix one server, confirm the solution, then let an agent patch the other 599 under oversight. A SOC Analyst Agent reaches general availability at Black Hat later this year, alongside an MCP server. On observability, the differentiator is reading both structured and unstructured data without normalizing it first. A zip code is structured; a cryptic web hook error is not. Sumo Logic reads both, which feeds directly into faster time to identify and faster time to resolve. For any leader weighing sovereignty against uptime, Bill Peterson makes a clear case that they can finally live in the same plan. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Bill Peterson, Senior Director of Product Marketing, Sumo Logic LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic on the AWS European Sovereign Cloud (announced at Infosecurity Europe 2026): https://www.sumologic.com/newsroom Infosecurity Europe 2026 event coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, AWS European Sovereign Cloud, data sovereignty, incident response, mean time to resolve, SIEM, security operations, Dojo AI, agentic AI, SOC analyst agent, observability, log analytics, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Absolute AppSec
Episode 323 - Secrets Logs, Prompt Injection Risks

Absolute AppSec

Play Episode Listen Later Jun 9, 2026


In episode 323 of Absolute AppSec, co-hosts Ken Johnson and Seth Law focus heavily on core application security vulnerabilities, legacy operational struggles, and the challenges of generative AI systems. After briefly discussing Seth's recent trip to BSides Vancouver and confirming upcoming conference training logistics for Black Hat and DEF CON, the duo dives into the persistent problem of secrets and sensitive data leaking into log files. Referencing an article and talk by Alan Reyes, they unpack the compounding nature of logging failures, noting how system-level integrations and production error conditions often dump entire object blocks or environment variables into third-party tools. They caution that while pattern-based scanners exist, they remain too brittle to capture complex edge cases, and utilizing expensive AI agents to screen every real-time log line is economically impractical. Transitioning to AI security, Seth explores a multi-page research paper analyzing prompt injection. The paper establishes that because large language models mathematically process data through tokenization without any physical or architectural separation between instructions and data contexts, prompt injection cannot be completely solved at the model level. Likening prompt injection to automated social engineering, they argue that the onus currently falls entirely on developers to implement deterministic validation, guardrails, and secure application-level harnesses.

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real corporate cases: professorgame.com/WildCD Episode Summary Rob breaks down why enterprise AI adoption stalls even with paid licenses and training, while a group of students beat a locked, proctored exam with ChatGPT and no support at all. Reading both cases through the Octalysis Framework, he shows how the exam accidentally stacked Core Drive 8 (Loss & Avoidance), Core Drive 6 (Scarcity & Impatience), and Core Drive 2 (Development & Accomplishment) into a ferocious, if mispointed, motivation engine. The enterprise bought the most capable tool and surrounded it with zero motivation, so nobody opened the app. Listeners learn why AI adoption is a motivation problem wearing a tooling costume, and leave with a two-part diagnostic question to ask of any AI initiative. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Students beat a lockdown, proctored, face-to-face online exam by getting ChatGPT to answer questions live through a Chrome extension, with no license, no training, and no change management. Adoption was instant, total, and creative enough to defeat the security. The exam accidentally stacked three Black Hat Core Drives: Core Drive 8 (Loss & Avoidance, failing is high-stakes), Core Drive 6 (Scarcity & Impatience, one timed shot), and Core Drive 2 (Development & Accomplishment, clearing the hurdle to the grade). Enterprises buy the paid license, training, IT support, and a leadership mandate, then adoption stalls because none of those things are motivation. There is no personal loss for ignoring the tool and no personal win for using it. Motivation pointed at the wrong goal produces flawless adoption of exactly the behavior you did not want. The students aimed AI at passing, not learning, and got it. As AI removes capability constraints, the human motivation layer becomes the only constraint left, which is why behavioral design matters more in the AI era, not less. The diagnostic: ask what your team personally gains by using the tool and what they personally lose by ignoring it. If the honest answer is "nothing much either way," no rollout plan will save it. Topics Covered 0:00 - Students hacked a locked exam 0:52 - Same tech, opposite outcome 1:44 - Adoption was never the problem 2:39 - The exam's accidental motivation engine 4:31 - Almost entirely Black Hat motivation 5:18 - Why the funded enterprise stalls 6:30 - Adoption and direction both matter 7:41 - Why behavioral design matters with AI 7:55 - Your diagnostic question for today Mentioned in This Episode The Octalysis Framework, developed by Yu-kai Chou ChatGPT (OpenAI) Core Drives in the Wild, the Professor Game free guide Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

The PowerShell Podcast
Cookie Monster Has Entered the Teams Chat with Miriam Wiesner

The PowerShell Podcast

Play Episode Listen Later Jun 8, 2026 41:39


Recorded live at PSConfEU 2026, Andrew sits down with returning guest Miriam Wiesner, Senior Security Researcher at Microsoft, for a wide-ranging conversation on PowerShell security, cookie-based attacks, and the evolving threat landscape. Miriam walks through her two conference talks — one on Microsoft Teams session cookie hijacking (a follow-up to her 2025 Entra ID cookie talk, complete with Cookie Monster branding and actual handcuffs), and a joint session with Stéphane van Gulick on using Microsoft Defender's Live Response feature for incident investigation. The conversation also covers the current state of PowerShell security, why sophisticated attackers are moving away from PowerShell, and why defenders who haven't enabled script block logging and AMSI are leaving easy wins on the table. On top of the technical deep dive, Miriam and Andrew get into the human side of the conference community — nerves before presenting, imposter syndrome, and why showing up is already half the battle. Key Takeaways: Cookie-based identity attacks are an active and growing threat. Microsoft Teams, SharePoint, and OneDrive share session cookies, meaning a single cookie theft can give an attacker broad access across your organization's collaboration tools — no re-authentication required. Sophisticated threat actors are moving away from PowerShell specifically because its security features work. Script block logging, AMSI, and Constrained Language Mode make PowerShell activity highly visible and detectable. If your org hasn't enabled these, you're handing attackers an easy path. Visibility beats prevention. You can't prevent what you can't see. Detection through proper logging is not a consolation prize — it's a core security strategy, and Microsoft Defender's Live Response feature gives teams a powerful way to investigate isolated endpoints without needing RDP or PowerShell remoting enabled. Guest Bio: Miriam Wiesner is a Senior Security Research Program Manager at Microsoft with over 15 years of experience in IT security, penetration testing, and security automation. She works on research behind Microsoft Defender and Sentinel and is the creator of widely used open source PowerShell security tools EventList and JEAnalyzer. Miriam is a sought-after speaker at major security and PowerShell conferences including Black Hat, PSConfEU, and MITRE ATT&CK Workshops. She's also the author of "PowerShell Automation and Scripting for Cybersecurity," published by Packt. Her conference speaker career started at PSConfEU 2018 and she's been a fixture of the community ever since. Resource Links Miriam's 2025 Cookies talk - https://www.youtube.com/watch?v=8xDcq0pPNPs Book – PowerShell Automation and Scripting for Cybersecurity (Packt): https://www.amazon.com/PowerShell-Automation-Scripting-Cybersecurity-Hacking/dp/1800566379 Miriam on LinkedIn: https://www.linkedin.com/in/miriamwiesner Miriam on X/Twitter: https://x.com/MiriamXyra Miriam's GitHub (EventList, JEAnalyzer, and more): https://github.com/miriamxyra Miriam's Website: https://miriamxyra.com Connect with Andrew: https://andrewpla.tech/links The PowerShell Podcast on YouTube: https://youtu.be/zxJOqcEwgWE  

Security Conversations
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux

Security Conversations

Play Episode Listen Later Jun 5, 2026 144:29


(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 100: We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay in cybersecurity. Plus, more on Anthropic's Mythos rollout and the thinly sourced Anthropic-NSA reports, the Fast16 sabotage of physics calculations, what researchers choose not to publish, Microsoft's bad Black Hat email, and Costin's Friday UFO files. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - JAGS at InfoSecurity Europe 3:40 - Sponsor: TLPBLACK 5:54 - A roadmap for security after the AI revolution 11:01 - Stripe Atlas and how easy it is to start a company 15:00 - If anyone could reverse engineer anything for $5 19:49 - Layoffs at Google's Threat Intelligence Group 21:06 - The death of reading the report 27:53 - Pitting the AI models against each other 32:07 - Grok, local models, and the DGX Spark 39:27 - Where is Google DeepMind? 45:29 - Will the frontier labs stay in cybersecurity? 52:41 - Mythos, Project Glasswing, and the NSA deal 1:16:33 - FAST16, Stuxnet, and sabotaging Iran's bomb 1:57:52 - Microsoft, Black Hat, and the chilling effect 2:14:14 - Shout-outs, UFO files, and 100 episodes

The Epstein Chronicles
From Wall Street to DEF CON: How Epstein Sought Access to Cybersecurity's Inner Circle

The Epstein Chronicles

Play Episode Listen Later Jun 2, 2026 19:25 Transcription Available


Documents released by the U.S. Justice Department show that convicted sex offender Jeffrey Epstein spent years corresponding with figures in the cybersecurity community and repeatedly tried to involve himself with two of the world's biggest hacker conventions, DEF CON and Black Hat, in Las Vegas. According to emails reviewed by Politico, Epstein's interest in cryptography and cybersecurity extended back to at least 2010, and he discussed topics ranging from network security to ways of pushing negative information about himself down in internet search results. Though he expressed a desire to attend these major events — even at times proposing to bring high-profile guests — there's no clear evidence he ever actually got into either conference, and organizers like Jeff Moss have said there's no proof he followed through on plans to attend.The documents also reveal Epstein's broader tech network, including contacts with researchers and entrepreneurs introduced through academic and startup circles. Among those mentioned was Italian security researcher Vincenzo Iozzo, who communicated with Epstein about potential business opportunities and emerging technologies but has denied doing any technical work for him. An FBI file included in the release also alleges Epstein may have had an unidentified “personal hacker” who developed offensive cyber tools sold to governments, though the name was redacted and some of the claims remain unverified.to contact me:bobbycapucci@protonmail.comsource:Jeffrey Epstein spent years building ties to well-known hackers - POLITICOBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-epstein-chronicles--5003294/support.

No on 15! All-cast hosted by 7Ceez
Season 7 Episode 16 You've Been Hacked vol. 4 and Black Hat

No on 15! All-cast hosted by 7Ceez

Play Episode Listen Later May 29, 2026 47:02


Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Episode Summary Rob breaks down why the most durable loyalty has almost nothing to do with points, contrasting a typical airline miles program with a neighborhood barber who keeps a customer for ten years with no app, no tiers, and no expiring rewards. He shows how the same Core Drive can run in opposite directions: airline programs fake Core Drive 4 (Ownership and Possession) with a points balance they control and devalue, while the barber builds real ownership through a relationship the customer actually owns. Along the way he names the over-justification effect, the moment a relationship becomes a calculation, and how Black Hat motivation can win in the short term while quietly corroding loyalty. Listeners come away with a clear diagnostic and a way to tell a real loyalty program apart from a price promotion on a delayed schedule. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Most loyalty programs build a transactional dependency rather than loyalty: the customer ends up loyal to the points, not the brand, so the moment a competitor offers more points they defect. Airline miles run on a Black Hat stack of Core Drive 4 (Ownership and Possession), Core Drive 6 (Scarcity and Impatience) through tier status, and Core Drive 8 (Loss and Avoidance) through expiring miles, which shifts the flyer from chasing something they want to avoiding a loss. The over-justification effect is the damage mechanism: a flyer who genuinely liked an airline starts booking the worse flight (longer, worse time, sometimes pricier) purely because it earns miles, the moment the relationship becomes a calculation. A relationship turned into a calculation is trivially beatable. A competitor with a slightly better offer doesn't just win one trip, it reveals there was never loyalty to begin with. A ten-year barber relationship survives real inconvenience (further away, closer cheaper options nearby) using the calm side of the same Core Drives: Core Drive 5 (Social Influence and Relatedness) plus genuinely owned personalization the customer cannot port to a competitor. The diagnostic: strip the points, discounts, and digital rewards entirely. If the honest answer to "why would anyone stay" is nothing, it isn't a loyalty program, it's a price promotion with a delayed payment schedule. Topics Covered 0:00 — Loyalty to the points, not the brand 1:16 — The Black Hat machinery of airline miles 2:25 — The over-justification effect in action 4:13 — The ten-year barber with no points 5:11 — Same Core Drive, opposite direction 6:12 — Inverting Core Drive 8 into a safe choice 7:36 — Run the strip-the-points diagnostic Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Mentioned in This Episode Core Drives in the Wild (Professor Game free guide) The Octalysis Framework and its Core Drives (Yu-kai Chou) Black Hat and White Hat motivation The over-justification effect Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Music of America Podcast
BOBBY BLACKHAT - VIRGINIA - SEASON 3

Music of America Podcast

Play Episode Listen Later May 25, 2026 60:52


Season 3 of the Music of America Podcast VIRGINIA begins with a flashback to Season 1 where we met Bobby Black Hat. Bobby shares his philosophies of music with us along with songs I Smell Another Man On You, Put On Your Red Shoes and You Time Me Time We Time

The #Lockboss Show
Talking Red Team Tools with Deviant Ollam | #Lockboss 4.19

The #Lockboss Show

Play Episode Listen Later May 20, 2026 75:42


#Lockboss Show: Red Team Tools Explained with Deviant Ollam — Tubular Picks, Decoders, Safety Straps and MoreIf you want to understand physical security at the highest level, you go straight to the source.In this episode of the #Lockboss Show & Giveaway, PJ sits down with Deviant Ollam, penetration tester, DEF CON and Black Hat presenter, and author of Practical Lock Picking, one of the most referenced books in the physical security world. CLK Supplies is now carrying his line of Red Team Tools and this conversation goes deep into the products, the purpose behind them, and how professionals actually use them in the field.We break down:Deviant Ollam's background and his work in physical security and penetration testingWhat Red Team Tools are designed for and who uses themRTT Quick-Connect Tubular Lockpick and Impressioning HeadTubular Bitting Decoder and its real world applicationsDeadbolt Safety Strap and what vulnerabilities it addressesLever Door Handle Shroud Guard and how it works in the fieldAdditional tools from the Red Team Tools lineupThe philosophy behind building tools for real security work versus recreational useWhat locksmiths and security professionals can learn from the penetration testing worldWhether you are a locksmith, a security professional, or just deeply curious about how physical security actually works at the highest level, this episode is packed with insight you won't find anywhere else.

Michael and Us
#715 - Failure to Communicate (w/ Josh Lewis)

Michael and Us

Play Episode Listen Later May 19, 2026 46:15


One of the pillars of the cursed "Everything is Connected" trend of the 2000s, Alejandro González Iñárritu's BABEL (2006) offers a de-politicized look at our global village. Josh Lewis (of Sleazoids podcast fame) fills in for Luke to discuss one very heavy exampe of White Elephant Art. Join us on Patreon for an extra episode every week - https://www.patreon.com/michaelandus Check out Sleazoids - https://www.sleazoidspodcast.com/ If you're in Toronto on June 8, 2026, come see Josh present Michael Mann's Blackhat at the Paradise - https://paradiseonbloor.com/movies/blackhat-directors-cut/

Cybercrime Magazine Podcast
Cybercrime Magazine Update: Black Hat. New & Upcoming Videos.

Cybercrime Magazine Podcast

Play Episode Listen Later May 13, 2026 3:48


In a new Cybercrime Magazine 3-minute video, President Suzy Pallett explained why everyone in the cybersecurity community belongs at Black Hat USA 2026. In this episode, host Paul John Spaulding talks to Cybercrime Magazine Deputy Editor Amanda Glassner about the production, other exciting projects lined up with Black Hat, and more. The Cybercrime Magazine Update covers the latest projects and developments at Cybercrime Magazine. For more on cybersecurity, visit us at https://cybersecurityventures.com

Maula Podcast
#264: I wear the black hat, de Chuck Klosterman

Maula Podcast

Play Episode Listen Later May 12, 2026 102:19


Un monólogo de Villalobos respecto a un libro que se topó armando la bibliografía de un nuevo taller: I wear the black hat (Uso el sombrero negro), de Chuck Klosterman. Un ensayo sobre lo que significa ser una figura villanesca, ya sea en la literatura, el cine, la televisión o la vida real. Desde los Eagles a Hitler, pasando por Bill Clinton y Joe Paterno, acá el viaje es accidentado pero fascinante. 

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Episode Summary Tetiana Kobzar, product designer with 18 years of experience and creator of the Comportance Framework, joins Rob to share how behavioral design turns clinical and educational software into products people actually want to use. She walks through the seven steps of Comportance (goal, baseline, emotion, hypothesis, minimum validation, cadence, and iteration) and shows how it shaped a gamified speech therapy app for Alder Hey Children's Hospital and a mini-game replacement for 27 cognitive assessment tests. The conversation covers why founders overload products with functionality, why Duolingo's Black Hat motivation works for some users and burns out others, and how Octalysis fits inside a wider behavioral design practice. Listeners leave with a practical structure for designing engagement and a sharper read on when game-based beats gamified. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways The Comportance Framework runs seven steps in order: define the goal, set the baseline metrics, design the emotion (motivation and positioning), state one hypothesis, build the minimum validation, set the measurement cadence, and iterate. Most founders skip the goal and emotion steps and jump straight to functionality. Tetiana's team at Alder Hey Children's Hospital replaced weekly-only speech therapy with a gamified app where clinicians set tasks as mini games, letting kids practice pronunciation between sessions while the therapist tracks progress. A separate Tetiana project replaced 27 pen-and-paper cognitive assessment tests with mini games on tablets, capturing extra signal (timestamps, finger tremor, voice recordings) that paper tests cannot measure. Most products fail not because users are irrational but because founders treat them as rational agents. Behavioral biases and cognitive overload kill engagement faster than missing features. The Pareto trap in client work: founders spend 80% of their attention on the 20% of clients who complain, while the 80% of healthy clients who quietly bring most of the revenue get under-served. Reverse the ratio to protect recurring revenue. Duolingo's streak mechanic is heavy Black Hat motivation. It drives high retention but creates rage-quit risk: a user who loses a 4,000-day streak rarely returns. The near-miss has to threaten loss without delivering it. Game-based design (where the experience itself feels like a game) opens more creative options than gamification (points, badges, leaderboards bolted onto a non-game product), but both belong inside a wider behavioral design practice. Topics Covered 0:00 — Why Duolingo's Black Hat motivation backfires 0:24 — Rob's intro and the Core Drives in the Wild guide 2:47 — Daily life after the acquisition 4:14 — Favorite fail: design for the end game 8:16 — Alder Hey speech therapy app and 27 cognitive tests as games 11:26 — Game-based versus gamified, and where the line blurs 15:44 — Where Octalysis fits inside the Comportance Framework 17:11 — The seven steps of Comportance, walked end to end 23:50 — Cognitive overload and treating users as humans 27:24 — Duolingo streaks, near-miss design, and rage-quit risk 31:42 — Book picks: Cialdini, Yu-kai Chou, Don Norman 33:29 — Civilization, board games with the kids, final advice Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD About Tetiana Kobzar Tetiana Kobzar is a product strategist and behavioral designer with 18 years of experience building software for healthcare, wellness, and education. She is the creator of the Comportance Framework, a seven-step methodology that brings behavioral science structure to product design. Her recent work includes a gamified speech therapy app for Alder Hey Children's Hospital and a tablet-based replacement for 27 cognitive assessment tests, and she shares behavioral design ideas through her #BehaviouralDesignThursday LinkedIn series and industry talks. Find the Guest Online LinkedIn Tetiana-kobzar.com Instagram TikTok Mentioned in This Episode Proposed guest: someone from Duolingo Recommended book: Actionable Gamification by Yu-kai Chou Recommended book: Influence by Robert B. Cialdini Recommended book: The Design of Everyday Things by Don Norman Favorite game: Civilization series Duolingo Is Not A Free Language Learning App, It Is... (The Octalysis Group) Alder Hey Children's Hospital speech therapy app (Tetiana's project) Comportance Framework (Tetiana's seven-step methodology) Octalysis Framework by Yu-kai Chou Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

BarCode
Michael Farnum and Phillip Wylie

BarCode

Play Episode Listen Later May 1, 2026 44:41


The Microsoft offices in downtown Houston initialized something in 2010 that its founders never intended to scale. Michael Farnum and his team triggered a regional conference with 120 attendees, built for the Texas cyber community. No grand ambitions. No national aspirations. Just a gathering for people who knew each other, wanted to learn together, and could afford to show up without corporate sponsorship covering a $2,700 entry fee.Meanwhile, Philip Wylie was running monthly meetups in Denton, traveling constantly, and discovering that building community meant something different than building an audience. The former professional wrestler turned pentester had launched DC940, authored bestselling books, and established himself as a global keynote speaker. But by fall 2024, the logistics became unsustainable. He stepped down from his DefCon group leadership role.That same night, walking away from the venue, an idea crystallized. The Dallas-Fort Worth area housed one of the world's largest cybersecurity communities, yet lacked a proper hacker conference. So Wylie sent a text message to Farnum. No expectations beyond advice. Within weeks, they had formalized a partnership that would bring CyberHackCon to the Plano Event Center, the same venue that hosted DalHackCon two decades earlier.What started as Houston's 15-year regional experiment had evolved into a national conference ecosystem. Companies were bypassing Black Hat and RSA entirely, sending whole teams to what was becoming CyberSecCon instead. The infrastructure now includes youth programs, executive events, OT-focused conferences, media arms, venture advisory, and nonprofit partnerships. Five full-time employees orchestrate an operation that refuses to gate its primary educational content behind paywalls, maintains community as the entry point for everything, and somehow preserves the feel of a high school reunion even as it approaches 400 attendees.TIMESTAMPS00:00 Building Community in Cybersecurity05:15 The Evolution of HusekCon to CyberSecCon12:00 The CyberSec Community Ecosystem20:14 Introducing Cyber Hack Con29:04 Call for Papers: Seeking Deep Tech Talks32:20 Engagement and Community Involvement33:44 Conference Experiences: Big vs. Small39:03 Post-Conference Content and Accessibility40:48 Creative Concepts: Cybersecurity-Themed Bar IdeasSYMLINKS[CyberSecCon] - https://www.cybrseccon.com/ Official website of CyberSecCon, a community-driven cybersecurity conference focused on accessibility, education, and bringing together professionals across all experience levels.[CyberSec Media] - https://www.cybrsecmedia.com/ Media platform that publishes cybersecurity talks, videos, and educational content from CyberSecCon and related community initiatives, available for free access.[DEF CON] - https://defcon.org/ One of the world's largest and most well-known hacker conferences, recognized for its deep technical content, hands-on learning, and strong hacker culture.[Michael Farnum – LinkedIn] - https://www.linkedin.com/in/mfarnum Professional profile of Michael Farnum, cybersecurity leader and co-founder of CyberSecCon, where he shares insights on community building and industry initiatives.[Phillip Wylie – LinkedIn] - https://www.linkedin.com/in/phillipwylie Professional profile of Phillip Wylie, penetration tester, instructor, and keynote speaker with extensive experience in cybersecurity and community mentorship.

Risky Business
Risky Business #833 -- The Great Mythos Freakout of 2026

Risky Business

Play Episode Listen Later Apr 15, 2026 59:45


On this week's show, Patrick Gray, Adam Boileau and James Wilson discuss the week's cybersecurity news. They cover: Everyone has an opinion about Claude Mythos… even though almost nobody has used it yet CISA adds a 2009 Excel bug to the KEV list, u wot? Adobe also parties like it's the 2000s, and fixes an Acrobat Reader bug Disgraced former Trenchant exec Peter Williams' sob story fails to resonate with … anyone Remember those crosswalk buttons hacked to play audio mocking Trump and Zuck? They were “secured” by the password: 1234. This week's episode is sponsored by mobile network operator, Cape. Ajit Gokhale talks with James about the ways to get being a telco right when you're starting from scratch and solving the security problems of 2026. This episode is also available on Youtube. Show notes Lab Space The “AI Vulnerability Storm”: Building a “Mythosready” Security Program Polymarket on X: "JUST IN: Goldman Sachs is reportedly ramping up its cyber defenses in preparation for Claude Mythos." Ananay on X: "Marcus Hutchins probably has the best take on Mythos doing vulnerability research" solst/ICE of Astarte on X: "Th vast majority of CISOs do not work at Google-sized companies, and will not have to worry about 0days" Charlie Miller on X: "we've gone through this before with early fuzzers, afl, etc" James Kettle on X: "'Can AI Do Novel Security Research? Meet the HTTP Terminator' will premiere at Blackhat" jeffrey lee funk on X: "We've been tricked, again. Many of the thousands of bugs and vulnerabilities Mythos found are in older software are impossible to exploit." Claude is getting worse, according to Claude • The Register Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain OpenAI's Mac apps need updates thanks to the Axios hack | CyberScoop Hack at Anodot leaves over a dozen breached companies facing extortion | TechCrunch Snowflake customers hit in data theft attacks after SaaS integrator breach Booking.com confirms hackers accessed customers' data CPUID hijacked to serve malware as HWMonitor downloads • The Register Known Exploited Vulnerabilities Catalog | CISA Adobe fixes PDF zero-day security bug that hackers have exploited for months | TechCrunch The Sad Decline of Trenchant Exec Who Had Everything, Before Deciding to Steal and Sell Zero Days to Russian Buyer FBI Extracts Suspect's Deleted Signal Messages Saved in iPhone Notification Database US operation evicts Russia from hacked SOHO routers used to breach critical infrastructure | Cybersecurity Dive Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market | WIRED The Dumbest Hack of the Year Exposed a Very Real Problem | WIRED

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education
Why is EVERYONE Failing At Gamification? (WHAT'S REALLY GOING ON?) | Episode 439

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Play Episode Listen Later Apr 6, 2026 6:54


Master the science of motivation and see how top experts do it right. Get the free 9-day "Core Drives in the Wild" email sequence here: professorgame.com/WildCD We break down three massive gamification disasters from 3 huge companies to reveal exactly what happens when we ignore behavioral science. We explain how well-intentioned features like leaderboards and point systems can accidentally create toxic work environments or destroy thriving communities. By applying the Octalysis framework, we highlight the dangers of relying too heavily on Black Hat motivation and extrinsic rewards without balancing them correctly. You will learn how to design systems that drive genuine engagement rather than building expensive burnout traps. Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia.   Lets's do stuff together! Core Drives in the Wild: Professor Game Guide Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Risky Business
How the World Got Owned Episode 2: The 1990s, Part One

Risky Business

Play Episode Listen Later Apr 3, 2026 46:46


In this special documentary episode, Patrick Gray and Amberleigh Jack take a look back at hacking throughout the 1990s, from the feel-good vibes of the early hacking communities to the antics of young hackers who wound up on the run from the FBI. Part one features recollections from: Jeff Moss (The Dark Tangent), DefCon and Black Hat founder Chris Wysopal (Weld Pond), L0pht member, co-founder, @Stake Kevin Poulsen (Dark Dante), 1990s hacker turned journalist Elias Levy (Aleph One), author of Smashing the Stack for Fun and Profit, Phrack, 1996 How the World Got Owned is produced in partnership with SentinelOne. Show notes Elias Levy (Aleph1), Former Principle Engineer, Google Kevin Poulsen, Journalist Jeff Moss, DefCon founder Chris Wysopal, @Stake founder, L0pht member Hackers testifying at the United States Senate, May 19, 1998 Hackers May ‘Net' Good PR for Studio DefCon Archives | DefCon 1 A Not So Terribly Brief History of the Electronic Frontier Foundation Innocent Hackers Want Their Computers Back Breakdowns in Computer Security Unsolved Mysteries, Season 3, Episode 4 The Last Hacker: He Called Himself Dark Dante. His Compulsion Led Him to Secret Files and, Eventually, The Bar of Justice Justia appeal summary, Kevin Poulsen, 1994 Smashing the Stack for Fun and Profit, Phrack Magazine, November 1996 From subversives to CEOs: How radical hackers built today's cybersecurity industry

Dark Rhino Security Podcast
S19 E0 (VIDEO) How Hackers Exploit Hidden Vulnerabilities

Dark Rhino Security Podcast

Play Episode Listen Later Apr 2, 2026 40:06


#SecurityConfidential #DarkRhiinoSecurityDiyar Saadi Ali is a cybersecurity professional specializing in cybercrime investigations, SOC operations, and malware analysis. A contributor to the MITRE ATT&CK framework, Diyar has helped strengthen global threat intelligence efforts and defensive strategies. Diyar regularly speaks at international cybersecurity conferences including Arab Cyber Security, DeepSec, GISEC, BlackHat, and SulyCon, contributing to the advancement of the global cyber community.00:00 Intro02:26 Our Guest03:42 Learning Cybersecurity in Iraq07:40 The MITRE attack Framework: Is that all the knowledge we know? 11:30 There are still tons of unknown vulnerabilities13:30 You can't fake motivation17:00 Defenders are to blame19:16 Who is coming up with Malware?22:10 Every crime leaves a trace24:12 AI is making malware easy29:00 Governance and Trust38:02 Presentations and News from Diyar----------------------------------------------------------------------To learn more about Diyar visit https://www.linkedin.com/in/diyarsaadi/To learn more about Dark Rhiino Security visit https://www.darkrhiinosecurity.com

The Cybersecurity Defenders Podcast
Bringing 40+ year old industrial security systems into the 21st century with Justin Searle from InGuardians [#304]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Mar 25, 2026 31:08


Justin Searle, Director of ICS Security at InGuardians, joins us today to talk about the challenges facing industrial control system security. With increased attack surface areas and maintaining and updating decades-old systems, Justin's dedication to informing and educating newcomers and experts alike is more important now than ever before.As the Director of ICS Security at InGuardians, Justin specializes in ICS security architecture design and penetration testing. He led the Smart Grid Security Architecture group in creating the NIST Interagency Report 7628 and has played key roles in the Advanced Security Acceleration Project for the Smart Grid (ASAP-SG), National Electric Sector Cybersecurity Organization Resources (NESCOR), and Smart Grid Interoperability Panel (SGIP). Justin is the owner of ControlThings LLC, a member of the SANS faculty, and an instructor at BlackHat. He has authored and taught numerous courses such as ICS410: ICS/SCADA Security Essentials, Assessing and Exploiting Control Systems and IIoT, Assessing and Exploiting Web Applications with SamuraiWTF, and SEC542: Web App Penetration Testing and Ethical Hacking. Justin also presents on a range of cybersecurity topics at leading security conferences across the globe.Learn more at: controlthings.ioSupport our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Don't experiment on your own revenue with broken game mechanics. Get our guide "Core Drives in the Wild" to learn how to apply real behavioral science to your product: professorgame.com/WildCD We dismantle the myth that simply adding points, badges, and leaderboards will fix a broken product. We explore why superficial rewards often lead to a 90% failure rate in corporate gamification and cause dangerous spikes followed by massive engagement crashes. By contrasting Google News's failed badge system with Wikipedia's intrinsic motivation model, we highlight the critical shift from transactional features to human-focused behavioral science. You can learn how to balance White Hat techniques like Epic Meaning with Black Hat mechanics like Scarcity to build long-term retention without burning out your user base. Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Links and resources Google News: https://news.google.com Wikipedia: https://www.wikipedia.org Duolingo: https://www.duolingo.com The Octalysis Group: https://octalysisgroup.com Lets's do stuff together! Core Drives in the Wild: Professor Game Guide Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Bankless
AI Finds 70% of Smart Contract Exploits | Alpin Yukseloglu

Bankless

Play Episode Listen Later Mar 5, 2026 61:38


AI is getting dangerously good at smart contract security. Faster than crypto is ready for. Alpin Yukseloglu joins Bankless to break down EVMBench (built with OpenAI), a benchmark testing whether AI agents can detect, patch, and exploit real fund-draining bugs and why the jump from ~12–13% exploit-finding to 70%+ could rewrite today's security assumptions. We unpack what that “70%” really means, why crypto's verifiability is an ideal training ground, why AI labs haven't prioritized crypto data yet, and what a 24/7 blackhat vs whitehat AI arms race means for DeFi. ---