Podcasts about Black hat

  • 1,262PODCASTS
  • 3,261EPISODES
  • 49mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Jul 17, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about Black hat

Show all podcasts related to black hat

Latest podcast episodes about Black hat

BarCode
Monzy Merza

BarCode

Play Episode Listen Later Jul 17, 2026 31:10


Crogl calls it a Knowledge Engine for Security Operations, and the idea is simple: analysts are drowning in alerts, and cutting corners isn't the fix. Every alert deserves a real look. So Crogl built an AI that works alongside the analyst, not instead of them, an assistant one investor called an "Iron Man suit" for security researchers. The goal isn't to replace the team. It's to make every single analyst as effective as the whole team combined. Monzy Merza, Co-founder and CEO of Crogl, joins us today on BarCode to talk community, what's coming at Black Hat, and why the best defense in cybersecurity might just be showing up and sharing what you know.SYMLINKS[Crogl] - https://crogl.com An AI-powered security operations platform that helps security teams investigate alerts, perform threat hunting, and automate cybersecurity workflows while keeping customer data within their own environment.[Monzy Mirza – LinkedIn] - https://www.linkedin.com/in/monzymerza/ The official LinkedIn profile of Monzy Mirza, Co-founder and CEO of Crogl, where he shares insights on AI, cybersecurity, and security operations.[MITRE ATT&CK® Framework] - https://attack.mitre.org/ A globally recognized cybersecurity knowledge base maintained by MITRE that documents adversary tactics, techniques, and procedures (TTPs). Crogl references the framework for investigating security alerts and threat hunting.[CISA] - https://www.cisa.gov/ The U.S. Cybersecurity and Infrastructure Security Agency. The episode discusses using CISA advisories, such as those related to Volt Typhoon, as inputs for threat hunting.[Volt Typhoon Advisory] - https://www.cisa.gov/news-events/cybersecurity-advisories CISA's collection of official cybersecurity advisories, including guidance on the Volt Typhoon threat actor. The episode references uploading these advisories into Crogl for automated threat hunting.[Slack] - https://slack.com/ A workplace collaboration platform. Crogl provides customers with access to a Slack community where users can interact directly with the engineering team and provide product feedback.[Black Hat USA] - https://www.blackhat.com/us-25/ One of the world's leading cybersecurity conferences. Monzy mentions that the Crogl team will host a booth, hackathon, and community sessions during Black Hat.

Resilient Cyber
Cyber Valuations, Moats & the Road to Black Hat

Resilient Cyber

Play Episode Listen Later Jul 16, 2026 41:54 Transcription Available


Cybersecurity investor Sid Trivedi of Foundation Capital joins me to dig into AI SOC valuations, services-as-software, moats, and what founders should know heading into Black Hat.Sid is a Partner at Foundation Capital, where he invests at the seed and Series A stage with a focus on cybersecurity and IT infrastructure. This is our annual pre-Black Hat check-in, and a lot has moved since last year, from massive M&A to record-setting rounds in categories like the AI SOC.In this episode:- What has actually changed a year into the AI wave, and what hasn't- Services-as-software, the $4.6 trillion market thesis, and automating cyber workflows across the SOC, IR, pen testing, and threat intel- What AI means for cybersecurity jobs and how practitioners should adapt- Consolidation vs. best-of-breed after Palo Alto's $25B CyberArk deal and Alphabet's $32B Wiz acquisition- AI SOC valuations, including Seven AI's record Series A and Torq crossing a $1B valuation- The double-edged sword of big raises and why founders should be cautious about the valuations they accept- Why you can't simply spend your way to growth in cybersecurity- Moats and defensibility when frontier labs can push into your category- The Black Hat Innovator Investor Summit and the Startup Spotlight competitionChapters:0:00 Intro0:52 What's changed a year into the AI wave2:42 Services-as-software and the AI SOC9:38 AI adoption and forward deployed engineers10:57 M&A, platformization, and best-of-breed14:17 IT and security convergence, plus AI SOC valuations18:48 Seed-stage risk calculus vs. later-stage investors21:43 The double-edged sword of big raises26:20 Why you can't spend your way to growth29:05 Moats and defensibility in the frontier-lab era32:25 Deal flow, pricing, and staying disciplined37:06 Black Hat Innovator Investor Summit40:17 Startup Spotlight competition43:28 Wrap-upBlack Hat is offering listeners $500 off registration with code USA500Resilient.Connect with Sid:LinkedIn: https://www.linkedin.com/in/siddhanttrivedi/Foundation Capital: https://foundationcapital.comResilient Cyber: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners, founders, and leaders.

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Want a sharper read on motivation design? Get the free Core Drives in the Wild guide, real cases decoded through this exact framework, one short email a day: professorgame.com/WildCD Episode Summary Rob argues that Black Hat motivation, the urgency and scarcity most designers treat as the villain, is the on-ramp that gets people to act at all. He breaks down the Octalysis Group's award-winning project with Procter & Gamble's distributor Navo Orbico, which reached 99.5% voluntary participation on a non-compulsory rollout and a 28.6% revenue increase by starting with pressure and handing off to meaning. Drawing on Ocean Hero as the rare frictionless exception, he shows why White Hat drives like Epic Meaning seldom start action on their own. Listeners learn the Black-Hat-to-White-Hat handoff and two diagnostic questions to test whether their own system can make the switch. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways The Octalysis Group's project with Procter & Gamble reached 99.5% voluntary participation on a non-compulsory rollout and a 28.6% revenue increase, evidence that Black Hat urgency and White Hat meaning work in sequence, not opposition. In the Octalysis framework, Black Hat and White Hat motivation are not good and evil. Black Hat (urgency, scarcity, pressure) gets people to act now; White Hat (meaning, empowerment) makes them glad they stayed. Relying only on grand meaning and Core Drive 3 (Empowerment of Creativity and Feedback) tends to produce a "someday," which in practice means never, because wanting to act is rarely a strong enough forcing function to overcome friction. The P&G rollout launched using Core Drive 5 (Social Influence and Relatedness) as pressure: getting into the system meant tracking down colleagues for an access code, which sparked FOMO (Core Drive 8) and curiosity (Core Drive 7) rather than belief in a grand vision. After the on-ramp, the system handed off to White Hat: reps became captains of trading ships, territories became open seas, and clients became colonies, activating Core Drive 1 (Epic Meaning) and Core Drive 2 (Development and Accomplishment). Ocean Hero is the rare case where White Hat alone starts action, because switching a search engine is one click of near-zero friction, so Core Drive 1 can carry the behavior with no urgency at all. Topics Covered 0:00 — Opening hook: why products stall 1:14 — The P&G result: 99.5% voluntary 3:05 — Black Hat and White Hat serve different moments 4:53 — The frictionless exception: Ocean Hero 6:07 — Inside the P&G rollout 7:30 — The handoff: reps become ship captains 9:16 — When Black Hat never matures into more 10:09 — Two diagnostic questions for your system 11:27 — What a mistimed handoff looks like 12:06 — Black Hat starts, White Hat sustains Mentioned in This Episode The Octalysis Group case study with Procter & Gamble's distributor Navo Orbico (Gamification Project of the Year, first presented in Brighton): 99.5% voluntary participation, 28.6% revenue increase Ocean Hero, the search engine whose revenue funds clearing plastic from the oceans (a project supported by The Octalysis Group) The Octalysis framework: Black Hat and White Hat motivation, and Core Drives 1 through 8 Episode 446, the airline miles loyalty teardown Episode 450, Amazon's internal AI leaderboard Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Search with Candour
How to rank in ChatGPT and AI search: Get AI traffic with listicles

Search with Candour

Play Episode Listen Later Jul 13, 2026 68:03


Léo Poitevin, founder and CEO of Astrak Agency, joins Search with Candour to discuss why your competitors may be recommended in ChatGPT and other AI search tools while you are not.Topics discussed:Why AI search engines are easier to manipulate than GoogleHow to identify competitors in AI searchHow to build trust signals for AI searchHow to use listicles and guest posts to rank in AI searchThe risks of self-promotional listiclesFollow Léo:Astrak Agency: https://astrak.agency/en/LinkedIn: https://www.linkedin.com/in/leo-poitevin/YouTube: https://www.youtube.com/@leopoitevinGet your tickets for SearchNorwichXLChapters00:00 Highlights of Léo Poitevin01:03 Introduction05:24 Leo's SEO background07:14 Are LLMs easier to game than Google?07:47 Google is good at fighting spam12:36 AI competitor research15:16 Competitor research for GEO19:47 Tracking volatility25:13 Imperfect data and KPIs for AI search30:11 A listicle strategy that works for LLMs33:01 Léo case studies36:07 The risks of listicles37:16 Self promotional listicles38:04 Ranking shifts in ChatGPT39:06 Listicles penalised by Google41:48 Testing new limits43:05 Links versus mentions46:18 Black Hat vs White Hate SEO49:15 Influencers and guest posts52:34 What hurts AI search56:20 Recommendation: Actionable tip57:51 Recommendation: Tool59:57 Recommendation: Cozy games01:05:14 Where to follow Léo01:06:44 Episode wrap-up

Resilient Cyber
Building an AI AppSec Engineer

Resilient Cyber

Play Episode Listen Later Jul 11, 2026 31:04


JJ of Gecko Security and former Disney and Costco CISO Ryan Knisley on why AppSec needs an AI security engineer, not another scanner.DescriptionAppSec has been stuck for years, drowning teams in noisy findings that never told them what was actually exploitable. JJ, co-founder and CEO of Gecko Security, and Ryan Knisley, former CISO at Disney and Costco, join Resilient Cyber to talk about what changes when an AI security engineer reasons across code, infrastructure, and design docs at once. We get into why business logic breaks traditional SAST, why attackers think in graphs while defenders think in lists, why MTTR is a broken metric, how Cal.com went closed source in the AI era, and where AI-driven AppSec consolidation lands over the next two years.Key takeawaysGecko is an AI security engineer, not another scanner. It reasons across code, infrastructure, and documentation, so a finding arrives already mapped to whether it is reachable in production and what data it touches.The context that tells you if a bug matters lives outside the code. Business logic, architecture, and runtime are where exploitability is decided, which is why scanning the code alone floods teams with noise.Business logic is why traditional SAST fails, and why an LLM alone will not fix it. The same endpoint with no auth check is a critical bug in a document store and expected behavior in a social app, and only design docs and architecture tell the two apart.Attackers think in graphs while defenders think in lists. A critical with a compensating control may not matter, while ten lows chained together can be the thing that actually reaches the asset you care about.Exploit development is being commoditized. JJ describes a near future where the whole internet becomes one big bug bounty scope with agents running campaign-level attacks, so the old severity-ranking lens no longer holds.Fix the class, not the ticket. Rather than patching bugs one by one, Gecko traces groups of findings back to the design decision that created them and eliminates every variant so the same issue never returns.MTTR is a broken metric. A variant of last week's bug returns with a fresh clock, so teams close tickets to look healthy while risk stays flat, which is why Gecko measures recurrence rate instead.Cal.com shows where open source is heading. After AI coding pushed its pull requests from about 30 a day to 100 with a one-person security team, being open source flipped from an advantage to a liability, so it went closed source and replaced four tools with one.Tool consolidation is a risk decision, not a cost exercise. Ryan's shiny object problem leaves teams stacking scanners nobody can fully staff, and collapsing the stack lets you cross-train people and reduce real complexity.The finding layer collapses, and human judgment moves up. When finding and fixing get cheap, the scarce work becomes deciding what is correct, whether to accept a risk on purpose, and owning the design decision for a whole class of bugs.Chapters00:00 Meet JJ and Ryan02:46 Why Gecko is an AI security engineer, not another scanner05:07 The trend of agentic and headless security tools05:53 Why business logic breaks traditional SAST06:27 The no-auth endpoint example and context outside the code09:06 Attackers think in graphs, defenders think in lists11:02 Commoditized exploit dev and the internet as one bug bounty13:55 Shift left and why MTTR is a broken metric15:07 Eliminating entire classes of vulnerabilities15:51 Recurrence rate and avoiding risky refactors18:22 The Cal.com case study and open source going closed20:48 Consolidation and the shiny object problem in security22:40 Where AI-driven AppSec lands in two years27:12 What it takes to trust an AI security engineer28:57 Where to find Gecko and the Black Hat talk

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Episode Summary Michael Lukich, a marketing analytics leader with more than 20 years across consulting, data, and strategy, explains why the fix for a struggling team is almost never more effort. He walks through the closed-loop trap he built early in his management career, the systems thinking tools he now uses to find leverage points, and why over-measuring single marketing channels quietly starves the top of the funnel. Drawing on the Cabreras' DSRP model, Donella Meadows, and nearly 25 years at the poker table, he shows how to see a whole system instead of optimizing one piece to the detriment of the goal. Listeners come away with a practical way to map any system, pick a single North Star metric, and design loops that let a team improve on its own. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Michael Lukich's early management trap was a closed loop with no exit: he could not step away until the team improved, and the team could not improve until he stepped away, which pushed him to 75-hour weeks before he redesigned the loop instead of adding effort. Accepting work at roughly 70 percent of his own output, paired with a tighter review cadence, let his team feel the consequences of their own decisions and turned him from a micromanager into a player coach. The "if you can't measure it, it doesn't exist" credo pushes budget toward easily measured lower-funnel channels and leaves the top of the funnel leaky, because no one can defend upper-funnel spend in a boardroom. The fix is whole-system measurement through multi-channel attribution and mixed models, not more measurement. Zynga over-relied on data and stacked Black Hat Core Drives that drive urgency and scarcity, a reminder that an A/B test measures one week, not how a feature performs as a system over two years. Derek and Laura Cabrera's DSRP model (Distinctions, Systems, Relationships, Perspectives) gives a four-part way to map almost any system, then find the bottleneck where one move has the biggest outsized effect. Poker trains decision-making under uncertainty and incomplete information, including the faulty learning loop where playing well can still lose and playing poorly can still win, which is why Michael says half the frameworks in his book started at the poker table. Topics Covered 0:00 — The loop you cannot escape 0:20 — Meet Michael Lukich: data, teaching, poker 2:41 — Designing your own life as a system 5:46 — Promoted into a trap with no exit 11:14 — The marketing measurement trap 13:53 — Frankenstein products, Zynga, and Black Hat 17:34 — A practical system: pick one metric 18:56 — Mapping systems with DSRP 22:23 — The strategy dashboard and the North Star 24:07 — James Clear, Ryan Holiday, and one book 26:54 — Translation and poker as the perfect game 30:25 — Where to find Michael and closing advice Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD About Michael Lukich Michael Lukich is a marketing analytics leader with more than 20 years across consulting, data, and business strategy, currently running marketing analytics for a major US marketing agency. He spent five years as an adjunct professor and has played poker for nearly 25 years, two habits that shaped how he thinks about teaching and making decisions under uncertainty. He writes the Stoic Systems Thinker newsletter, where ancient Stoic philosophy meets modern systems thinking, and is the author of the book of the same name. He lives in Ann Arbor, Michigan with his wife and two daughters. Find Michael Lukich Online The Stoic Systems Thinker (website and newsletter) LinkedIn The Stoic Systems Thinker on Substack Mentioned in This Episode Some links below are affiliate links. As an Amazon Associate, I earn from qualifying purchases. Thinking in Systems by Donella Meadows James Clear and Atomic Habits Ryan Holiday Poker The Stoic Systems Thinker by Michael Lukich Derek and Laura Cabrera's DSRP model (Distinctions, Systems, Relationships, Perspectives) Meditations by Marcus Aurelius Zynga The Octalysis Framework and Black Hat Core Drives Kaizen and Kaikaku (continuous improvement versus radical change) Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

The Cybersecurity Defenders Podcast
Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 1, 2026 30:01


Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.Chapters:0:00 Intro & catching up2:25 Cisco CUCM exploited within 24h of the PoC9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce & Warlock15:44 Gamaredon's upgraded TTPs against Ukraine22:18 Can AI email agents be phished?28:08 Wrap-up: Black Hat plans & the LimaCharlie suiteThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #ransomware #DFIR

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products, with one real-world example in your inbox each day: professorgame.com/WildCD Episode Summary Rob breaks down why disconnecting on vacation is so hard for driven people, and why it is a motivation problem rather than a willpower one. He maps the specific Octalysis Core Drives that keep high achievers tied to work during a break, including Core Drive 2 (progress addiction), Core Drive 8 (FOMO and Black Hat urgency), and Core Drive 1 (the mission needs me trap). Drawing on his own routine of leaving the phone at the apartment near the beach, he shows how to name each drive and switch off its trigger before the break starts. Listeners learn a pre-break diagnostic and how to design time off the same way they would design a user's exit from an engagement loop. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Driven people stay tied to work on vacation because their Core Drives keep firing in the background. This is a motivation issue, which is why pure willpower so often fails to deliver real rest. Core Drive 2 (Development and Accomplishment) shows up as progress addiction. With no momentum at work, a break can feel like your progress is being trumped, which pulls you back to the phone to make something move. Core Drive 8 (Loss and Avoidance) is Black Hat motivation built on FOMO. The fear that something breaks, or that everyone else is still shipping, creates urgency and pushes you to check in even when nothing is wrong. Core Drive 1 (Epic Meaning and Calling), the sense that the mission needs you, is the noble sounding trap. It can justify sacrificing rest you have earned, so naming it is what lets you stop it from firing back. The fix is to design your break the way you would design a user's exit from an engagement loop: kill the notifications, remove the triggers (Rob leaves his phone at the apartment), and push yourself out instead of staying half in. A real emergency that truly needs you is rare, roughly 0.1 percent of the time. Plan ahead, brief your team on what actually counts as an emergency, and trust them to handle the other 99.9 percent without you. Topics Covered [0:00] Why driven brains can't switch off [0:49] Disconnecting is a motivation problem [1:21] Core Drive 2: progress addiction [1:54] Core Drive 8: FOMO and urgency [2:30] Core Drive 1: the mission trap [3:08] Name the drive, deactivate the trigger [3:54] Leaving the phone at the beach [4:50] Why productive resting backfires [6:00] Design your break like an engagement loop [6:36] Diagnose your pull-back drive first [8:05] Rest is switching off the drives Mentioned in This Episode Core Drives in the Wild, Rob's free guide (one Core Drive example per day) The Octalysis Group The Octalysis Framework and its Eight Core Drives (Yu-kai Chou), the basis for Core Drives 1, 2, 5, and 8 discussed here Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

The Shared Security Show
Jay Beale on Kubernetes, DEF CON, and AI Attack Paths

The Shared Security Show

Play Episode Listen Later Jun 29, 2026 38:20 Transcription Available


This week on Shared Security, Tom and Kevin sit down with Jay Beale — founder of InGuardians, long-time Black Hat trainer, creator/contributor behind Kubernetes security training, and part of the team behind the DEF CON Kubernetes CTF. Jay shares stories from decades of offensive security work, including the time Tom hired him for a physical penetration test and Jay somehow ended up inside a call center instead of stuck in the lobby. The crew also digs into what makes good security training, why Kubernetes is such a natural platform for both defenders and attackers to understand deeply, and how the DEF CON Kubernetes CTF is designed to be welcoming for both competitors and learners. The episode closes with a practical look at AI infrastructure risk. Jay explains how production AI stacks running on Kubernetes can be attacked like any other cluster — and how modifying a vector database behind a RAG system can turn indirect prompt injection into a persistent, high-impact attack path.** Links mentioned on the show **Jay's Black Hat USA Course: Agentic AI-aided Kubernetes Attack and Defensehttps://blackhat.com/us-26/training/schedule/index.html?day=4daysattue#agentic-ai-aided-kubernetes-attack-and-defense-51318Jay Beale on LinkedInhttps://www.linkedin.com/in/jaybeale/InGuardianshttps://www.inguardians.com/DEF CONhttps://defcon.org/** Watch this episode on YouTube **https://youtu.be/aMHk62dprDA** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact

The Rebbe’s advice
4150 – Deliberation on Adopting Lubavitch Dress and Black Hat – התחבטות על אימוץ לבוש חב"די ומגבעת שחורה

The Rebbe’s advice

Play Episode Listen Later Jun 29, 2026


The Rebbe advises not to rush into adopting Lubavitch dress, such as a long coat and black hat, especially when uncertain and facing family opposition. Instead, he suggests focusing on diligent Torah study, particularly Chassidus, and reconsidering the decision later. https://www.torahrecordings.com/rebbe/igroskodesh/012/006/4150

ITSPmagazine | Technology. Cybersecurity. Society
Where Data Sovereignty and Always-On Security Operations Meet | A Brand Spotlight at Infosecurity Europe 2026 with Bill Peterson, Senior Director of Product Marketing of Sumo Logic

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 12, 2026 16:31


At Infosecurity Europe 2026 in London, Bill Peterson, Senior Director of Product Marketing at Sumo Logic, joins us to unpack a tension every regulated security team knows well. When an incident hits, the business has to keep running. At the same time, regulators expect sensitive data to stay in region. For a long time, those two demands have pulled in opposite directions. Sumo Logic has spent 15 years as a SaaS platform on AWS, processing roughly four exabytes of data a day for around 2,000 customers. The core promise is speed, driving mean time to resolve as low as possible. Peterson frames it in business terms, because the person signing the check wants to know the return, not the bits and bytes. The news from the show is Sumo Logic availability on the AWS European Sovereign Cloud. EU organizations can keep their data in region, handled by EU staff, while still running the full platform for incident response. That turns a painful either/or into a checklist a regulated buyer can complete. Genesys is the first customer live in the sovereign cloud, with payment processor OpenPay preparing to follow. How does this play out for highly regulated industries? Sumo Logic is focused on finance, healthcare, telco, and government, the verticals feeling the most pressure. The path Peterson describes is simple: let Sumo Logic handle incident management, let AWS move and grow the data in region, and check the sovereignty box without giving up operational readiness. Underneath sits a full-featured SIEM and Dojo AI, the agentic approach Sumo Logic launched earlier this year. The goal is not to replace analysts but to keep a human in the loop while handing proven, repetitive work to an agent. Fix one server, confirm the solution, then let an agent patch the other 599 under oversight. A SOC Analyst Agent reaches general availability at Black Hat later this year, alongside an MCP server. On observability, the differentiator is reading both structured and unstructured data without normalizing it first. A zip code is structured; a cryptic web hook error is not. Sumo Logic reads both, which feeds directly into faster time to identify and faster time to resolve. For any leader weighing sovereignty against uptime, Bill Peterson makes a clear case that they can finally live in the same plan. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Bill Peterson, Senior Director of Product Marketing, Sumo Logic LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic on the AWS European Sovereign Cloud (announced at Infosecurity Europe 2026): https://www.sumologic.com/newsroom Infosecurity Europe 2026 event coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, AWS European Sovereign Cloud, data sovereignty, incident response, mean time to resolve, SIEM, security operations, Dojo AI, agentic AI, SOC analyst agent, observability, log analytics, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Absolute AppSec
Episode 323 - Secrets Logs, Prompt Injection Risks

Absolute AppSec

Play Episode Listen Later Jun 9, 2026


In episode 323 of Absolute AppSec, co-hosts Ken Johnson and Seth Law focus heavily on core application security vulnerabilities, legacy operational struggles, and the challenges of generative AI systems. After briefly discussing Seth's recent trip to BSides Vancouver and confirming upcoming conference training logistics for Black Hat and DEF CON, the duo dives into the persistent problem of secrets and sensitive data leaking into log files. Referencing an article and talk by Alan Reyes, they unpack the compounding nature of logging failures, noting how system-level integrations and production error conditions often dump entire object blocks or environment variables into third-party tools. They caution that while pattern-based scanners exist, they remain too brittle to capture complex edge cases, and utilizing expensive AI agents to screen every real-time log line is economically impractical. Transitioning to AI security, Seth explores a multi-page research paper analyzing prompt injection. The paper establishes that because large language models mathematically process data through tokenization without any physical or architectural separation between instructions and data contexts, prompt injection cannot be completely solved at the model level. Likening prompt injection to automated social engineering, they argue that the onus currently falls entirely on developers to implement deterministic validation, guardrails, and secure application-level harnesses.

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real corporate cases: professorgame.com/WildCD Episode Summary Rob breaks down why enterprise AI adoption stalls even with paid licenses and training, while a group of students beat a locked, proctored exam with ChatGPT and no support at all. Reading both cases through the Octalysis Framework, he shows how the exam accidentally stacked Core Drive 8 (Loss & Avoidance), Core Drive 6 (Scarcity & Impatience), and Core Drive 2 (Development & Accomplishment) into a ferocious, if mispointed, motivation engine. The enterprise bought the most capable tool and surrounded it with zero motivation, so nobody opened the app. Listeners learn why AI adoption is a motivation problem wearing a tooling costume, and leave with a two-part diagnostic question to ask of any AI initiative. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Students beat a lockdown, proctored, face-to-face online exam by getting ChatGPT to answer questions live through a Chrome extension, with no license, no training, and no change management. Adoption was instant, total, and creative enough to defeat the security. The exam accidentally stacked three Black Hat Core Drives: Core Drive 8 (Loss & Avoidance, failing is high-stakes), Core Drive 6 (Scarcity & Impatience, one timed shot), and Core Drive 2 (Development & Accomplishment, clearing the hurdle to the grade). Enterprises buy the paid license, training, IT support, and a leadership mandate, then adoption stalls because none of those things are motivation. There is no personal loss for ignoring the tool and no personal win for using it. Motivation pointed at the wrong goal produces flawless adoption of exactly the behavior you did not want. The students aimed AI at passing, not learning, and got it. As AI removes capability constraints, the human motivation layer becomes the only constraint left, which is why behavioral design matters more in the AI era, not less. The diagnostic: ask what your team personally gains by using the tool and what they personally lose by ignoring it. If the honest answer is "nothing much either way," no rollout plan will save it. Topics Covered 0:00 - Students hacked a locked exam 0:52 - Same tech, opposite outcome 1:44 - Adoption was never the problem 2:39 - The exam's accidental motivation engine 4:31 - Almost entirely Black Hat motivation 5:18 - Why the funded enterprise stalls 6:30 - Adoption and direction both matter 7:41 - Why behavioral design matters with AI 7:55 - Your diagnostic question for today Mentioned in This Episode The Octalysis Framework, developed by Yu-kai Chou ChatGPT (OpenAI) Core Drives in the Wild, the Professor Game free guide Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

The PowerShell Podcast
Cookie Monster Has Entered the Teams Chat with Miriam Wiesner

The PowerShell Podcast

Play Episode Listen Later Jun 8, 2026 41:39


Recorded live at PSConfEU 2026, Andrew sits down with returning guest Miriam Wiesner, Senior Security Researcher at Microsoft, for a wide-ranging conversation on PowerShell security, cookie-based attacks, and the evolving threat landscape. Miriam walks through her two conference talks — one on Microsoft Teams session cookie hijacking (a follow-up to her 2025 Entra ID cookie talk, complete with Cookie Monster branding and actual handcuffs), and a joint session with Stéphane van Gulick on using Microsoft Defender's Live Response feature for incident investigation. The conversation also covers the current state of PowerShell security, why sophisticated attackers are moving away from PowerShell, and why defenders who haven't enabled script block logging and AMSI are leaving easy wins on the table. On top of the technical deep dive, Miriam and Andrew get into the human side of the conference community — nerves before presenting, imposter syndrome, and why showing up is already half the battle. Key Takeaways: Cookie-based identity attacks are an active and growing threat. Microsoft Teams, SharePoint, and OneDrive share session cookies, meaning a single cookie theft can give an attacker broad access across your organization's collaboration tools — no re-authentication required. Sophisticated threat actors are moving away from PowerShell specifically because its security features work. Script block logging, AMSI, and Constrained Language Mode make PowerShell activity highly visible and detectable. If your org hasn't enabled these, you're handing attackers an easy path. Visibility beats prevention. You can't prevent what you can't see. Detection through proper logging is not a consolation prize — it's a core security strategy, and Microsoft Defender's Live Response feature gives teams a powerful way to investigate isolated endpoints without needing RDP or PowerShell remoting enabled. Guest Bio: Miriam Wiesner is a Senior Security Research Program Manager at Microsoft with over 15 years of experience in IT security, penetration testing, and security automation. She works on research behind Microsoft Defender and Sentinel and is the creator of widely used open source PowerShell security tools EventList and JEAnalyzer. Miriam is a sought-after speaker at major security and PowerShell conferences including Black Hat, PSConfEU, and MITRE ATT&CK Workshops. She's also the author of "PowerShell Automation and Scripting for Cybersecurity," published by Packt. Her conference speaker career started at PSConfEU 2018 and she's been a fixture of the community ever since. Resource Links Miriam's 2025 Cookies talk - https://www.youtube.com/watch?v=8xDcq0pPNPs Book – PowerShell Automation and Scripting for Cybersecurity (Packt): https://www.amazon.com/PowerShell-Automation-Scripting-Cybersecurity-Hacking/dp/1800566379 Miriam on LinkedIn: https://www.linkedin.com/in/miriamwiesner Miriam on X/Twitter: https://x.com/MiriamXyra Miriam's GitHub (EventList, JEAnalyzer, and more): https://github.com/miriamxyra Miriam's Website: https://miriamxyra.com Connect with Andrew: https://andrewpla.tech/links The PowerShell Podcast on YouTube: https://youtu.be/zxJOqcEwgWE  

Security Conversations
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux

Security Conversations

Play Episode Listen Later Jun 5, 2026 144:29


(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem - Episode 100: We cover AI eating reverse engineering, the death of the malware report, running local models on the DGX Spark, where Google DeepMind stands, and whether the frontier labs will stay in cybersecurity. Plus, more on Anthropic's Mythos rollout and the thinly sourced Anthropic-NSA reports, the Fast16 sabotage of physics calculations, what researchers choose not to publish, Microsoft's bad Black Hat email, and Costin's Friday UFO files. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - JAGS at InfoSecurity Europe 3:40 - Sponsor: TLPBLACK 5:54 - A roadmap for security after the AI revolution 11:01 - Stripe Atlas and how easy it is to start a company 15:00 - If anyone could reverse engineer anything for $5 19:49 - Layoffs at Google's Threat Intelligence Group 21:06 - The death of reading the report 27:53 - Pitting the AI models against each other 32:07 - Grok, local models, and the DGX Spark 39:27 - Where is Google DeepMind? 45:29 - Will the frontier labs stay in cybersecurity? 52:41 - Mythos, Project Glasswing, and the NSA deal 1:16:33 - FAST16, Stuxnet, and sabotaging Iran's bomb 1:57:52 - Microsoft, Black Hat, and the chilling effect 2:14:14 - Shout-outs, UFO files, and 100 episodes

The Epstein Chronicles
From Wall Street to DEF CON: How Epstein Sought Access to Cybersecurity's Inner Circle

The Epstein Chronicles

Play Episode Listen Later Jun 2, 2026 19:25 Transcription Available


Documents released by the U.S. Justice Department show that convicted sex offender Jeffrey Epstein spent years corresponding with figures in the cybersecurity community and repeatedly tried to involve himself with two of the world's biggest hacker conventions, DEF CON and Black Hat, in Las Vegas. According to emails reviewed by Politico, Epstein's interest in cryptography and cybersecurity extended back to at least 2010, and he discussed topics ranging from network security to ways of pushing negative information about himself down in internet search results. Though he expressed a desire to attend these major events — even at times proposing to bring high-profile guests — there's no clear evidence he ever actually got into either conference, and organizers like Jeff Moss have said there's no proof he followed through on plans to attend.The documents also reveal Epstein's broader tech network, including contacts with researchers and entrepreneurs introduced through academic and startup circles. Among those mentioned was Italian security researcher Vincenzo Iozzo, who communicated with Epstein about potential business opportunities and emerging technologies but has denied doing any technical work for him. An FBI file included in the release also alleges Epstein may have had an unidentified “personal hacker” who developed offensive cyber tools sold to governments, though the name was redacted and some of the claims remain unverified.to contact me:bobbycapucci@protonmail.comsource:Jeffrey Epstein spent years building ties to well-known hackers - POLITICOBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-epstein-chronicles--5003294/support.

No on 15! All-cast hosted by 7Ceez
Season 7 Episode 16 You've Been Hacked vol. 4 and Black Hat

No on 15! All-cast hosted by 7Ceez

Play Episode Listen Later May 29, 2026 47:02


Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Episode Summary Rob breaks down why the most durable loyalty has almost nothing to do with points, contrasting a typical airline miles program with a neighborhood barber who keeps a customer for ten years with no app, no tiers, and no expiring rewards. He shows how the same Core Drive can run in opposite directions: airline programs fake Core Drive 4 (Ownership and Possession) with a points balance they control and devalue, while the barber builds real ownership through a relationship the customer actually owns. Along the way he names the over-justification effect, the moment a relationship becomes a calculation, and how Black Hat motivation can win in the short term while quietly corroding loyalty. Listeners come away with a clear diagnostic and a way to tell a real loyalty program apart from a price promotion on a delayed schedule. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways Most loyalty programs build a transactional dependency rather than loyalty: the customer ends up loyal to the points, not the brand, so the moment a competitor offers more points they defect. Airline miles run on a Black Hat stack of Core Drive 4 (Ownership and Possession), Core Drive 6 (Scarcity and Impatience) through tier status, and Core Drive 8 (Loss and Avoidance) through expiring miles, which shifts the flyer from chasing something they want to avoiding a loss. The over-justification effect is the damage mechanism: a flyer who genuinely liked an airline starts booking the worse flight (longer, worse time, sometimes pricier) purely because it earns miles, the moment the relationship becomes a calculation. A relationship turned into a calculation is trivially beatable. A competitor with a slightly better offer doesn't just win one trip, it reveals there was never loyalty to begin with. A ten-year barber relationship survives real inconvenience (further away, closer cheaper options nearby) using the calm side of the same Core Drives: Core Drive 5 (Social Influence and Relatedness) plus genuinely owned personalization the customer cannot port to a competitor. The diagnostic: strip the points, discounts, and digital rewards entirely. If the honest answer to "why would anyone stay" is nothing, it isn't a loyalty program, it's a price promotion with a delayed payment schedule. Topics Covered 0:00 — Loyalty to the points, not the brand 1:16 — The Black Hat machinery of airline miles 2:25 — The over-justification effect in action 4:13 — The ten-year barber with no points 5:11 — Same Core Drive, opposite direction 6:12 — Inverting Core Drive 8 into a safe choice 7:36 — Run the strip-the-points diagnostic Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Mentioned in This Episode Core Drives in the Wild (Professor Game free guide) The Octalysis Framework and its Core Drives (Yu-kai Chou) Black Hat and White Hat motivation The over-justification effect Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Music of America Podcast
BOBBY BLACKHAT - VIRGINIA - SEASON 3

Music of America Podcast

Play Episode Listen Later May 25, 2026 60:52


Season 3 of the Music of America Podcast VIRGINIA begins with a flashback to Season 1 where we met Bobby Black Hat. Bobby shares his philosophies of music with us along with songs I Smell Another Man On You, Put On Your Red Shoes and You Time Me Time We Time

The #Lockboss Show
Talking Red Team Tools with Deviant Ollam | #Lockboss 4.19

The #Lockboss Show

Play Episode Listen Later May 20, 2026 75:42


#Lockboss Show: Red Team Tools Explained with Deviant Ollam — Tubular Picks, Decoders, Safety Straps and MoreIf you want to understand physical security at the highest level, you go straight to the source.In this episode of the #Lockboss Show & Giveaway, PJ sits down with Deviant Ollam, penetration tester, DEF CON and Black Hat presenter, and author of Practical Lock Picking, one of the most referenced books in the physical security world. CLK Supplies is now carrying his line of Red Team Tools and this conversation goes deep into the products, the purpose behind them, and how professionals actually use them in the field.We break down:Deviant Ollam's background and his work in physical security and penetration testingWhat Red Team Tools are designed for and who uses themRTT Quick-Connect Tubular Lockpick and Impressioning HeadTubular Bitting Decoder and its real world applicationsDeadbolt Safety Strap and what vulnerabilities it addressesLever Door Handle Shroud Guard and how it works in the fieldAdditional tools from the Red Team Tools lineupThe philosophy behind building tools for real security work versus recreational useWhat locksmiths and security professionals can learn from the penetration testing worldWhether you are a locksmith, a security professional, or just deeply curious about how physical security actually works at the highest level, this episode is packed with insight you won't find anywhere else.

Michael and Us
#715 - Failure to Communicate (w/ Josh Lewis)

Michael and Us

Play Episode Listen Later May 19, 2026 46:15


One of the pillars of the cursed "Everything is Connected" trend of the 2000s, Alejandro González Iñárritu's BABEL (2006) offers a de-politicized look at our global village. Josh Lewis (of Sleazoids podcast fame) fills in for Luke to discuss one very heavy exampe of White Elephant Art. Join us on Patreon for an extra episode every week - https://www.patreon.com/michaelandus Check out Sleazoids - https://www.sleazoidspodcast.com/ If you're in Toronto on June 8, 2026, come see Josh present Michael Mann's Blackhat at the Paradise - https://paradiseonbloor.com/movies/blackhat-directors-cut/

Cybercrime Magazine Podcast
Cybercrime Magazine Update: Black Hat. New & Upcoming Videos.

Cybercrime Magazine Podcast

Play Episode Listen Later May 13, 2026 3:48


In a new Cybercrime Magazine 3-minute video, President Suzy Pallett explained why everyone in the cybersecurity community belongs at Black Hat USA 2026. In this episode, host Paul John Spaulding talks to Cybercrime Magazine Deputy Editor Amanda Glassner about the production, other exciting projects lined up with Black Hat, and more. The Cybercrime Magazine Update covers the latest projects and developments at Cybercrime Magazine. For more on cybersecurity, visit us at https://cybersecurityventures.com

Maula Podcast
#264: I wear the black hat, de Chuck Klosterman

Maula Podcast

Play Episode Listen Later May 12, 2026 102:19


Un monólogo de Villalobos respecto a un libro que se topó armando la bibliografía de un nuevo taller: I wear the black hat (Uso el sombrero negro), de Chuck Klosterman. Un ensayo sobre lo que significa ser una figura villanesca, ya sea en la literatura, el cine, la televisión o la vida real. Desde los Eagles a Hitler, pasando por Bill Clinton y Joe Paterno, acá el viaje es accidentado pero fascinante. 

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD Episode Summary Tetiana Kobzar, product designer with 18 years of experience and creator of the Comportance Framework, joins Rob to share how behavioral design turns clinical and educational software into products people actually want to use. She walks through the seven steps of Comportance (goal, baseline, emotion, hypothesis, minimum validation, cadence, and iteration) and shows how it shaped a gamified speech therapy app for Alder Hey Children's Hospital and a mini-game replacement for 27 cognitive assessment tests. The conversation covers why founders overload products with functionality, why Duolingo's Black Hat motivation works for some users and burns out others, and how Octalysis fits inside a wider behavioral design practice. Listeners leave with a practical structure for designing engagement and a sharper read on when game-based beats gamified. About the Host Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Key Takeaways The Comportance Framework runs seven steps in order: define the goal, set the baseline metrics, design the emotion (motivation and positioning), state one hypothesis, build the minimum validation, set the measurement cadence, and iterate. Most founders skip the goal and emotion steps and jump straight to functionality. Tetiana's team at Alder Hey Children's Hospital replaced weekly-only speech therapy with a gamified app where clinicians set tasks as mini games, letting kids practice pronunciation between sessions while the therapist tracks progress. A separate Tetiana project replaced 27 pen-and-paper cognitive assessment tests with mini games on tablets, capturing extra signal (timestamps, finger tremor, voice recordings) that paper tests cannot measure. Most products fail not because users are irrational but because founders treat them as rational agents. Behavioral biases and cognitive overload kill engagement faster than missing features. The Pareto trap in client work: founders spend 80% of their attention on the 20% of clients who complain, while the 80% of healthy clients who quietly bring most of the revenue get under-served. Reverse the ratio to protect recurring revenue. Duolingo's streak mechanic is heavy Black Hat motivation. It drives high retention but creates rage-quit risk: a user who loses a 4,000-day streak rarely returns. The near-miss has to threaten loss without delivering it. Game-based design (where the experience itself feels like a game) opens more creative options than gamification (points, badges, leaderboards bolted onto a non-game product), but both belong inside a wider behavioral design practice. Topics Covered 0:00 — Why Duolingo's Black Hat motivation backfires 0:24 — Rob's intro and the Core Drives in the Wild guide 2:47 — Daily life after the acquisition 4:14 — Favorite fail: design for the end game 8:16 — Alder Hey speech therapy app and 27 cognitive tests as games 11:26 — Game-based versus gamified, and where the line blurs 15:44 — Where Octalysis fits inside the Comportance Framework 17:11 — The seven steps of Comportance, walked end to end 23:50 — Cognitive overload and treating users as humans 27:24 — Duolingo streaks, near-miss design, and rage-quit risk 31:42 — Book picks: Cialdini, Yu-kai Chou, Don Norman 33:29 — Civilization, board games with the kids, final advice Get the free Core Drives in the Wild guide, behavioral design applied to real products: professorgame.com/WildCD About Tetiana Kobzar Tetiana Kobzar is a product strategist and behavioral designer with 18 years of experience building software for healthcare, wellness, and education. She is the creator of the Comportance Framework, a seven-step methodology that brings behavioral science structure to product design. Her recent work includes a gamified speech therapy app for Alder Hey Children's Hospital and a tablet-based replacement for 27 cognitive assessment tests, and she shares behavioral design ideas through her #BehaviouralDesignThursday LinkedIn series and industry talks. Find the Guest Online LinkedIn Tetiana-kobzar.com Instagram TikTok Mentioned in This Episode Proposed guest: someone from Duolingo Recommended book: Actionable Gamification by Yu-kai Chou Recommended book: Influence by Robert B. Cialdini Recommended book: The Design of Everyday Things by Don Norman Favorite game: Civilization series Duolingo Is Not A Free Language Learning App, It Is... (The Octalysis Group) Alder Hey Children's Hospital speech therapy app (Tetiana's project) Comportance Framework (Tetiana's seven-step methodology) Octalysis Framework by Yu-kai Chou Free Resources and Get in Touch Core Drives in the Wild: Professor Game Free Guide Get Daily Value on Your Email Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

BarCode
Michael Farnum and Phillip Wylie

BarCode

Play Episode Listen Later May 1, 2026 44:41


The Microsoft offices in downtown Houston initialized something in 2010 that its founders never intended to scale. Michael Farnum and his team triggered a regional conference with 120 attendees, built for the Texas cyber community. No grand ambitions. No national aspirations. Just a gathering for people who knew each other, wanted to learn together, and could afford to show up without corporate sponsorship covering a $2,700 entry fee.Meanwhile, Philip Wylie was running monthly meetups in Denton, traveling constantly, and discovering that building community meant something different than building an audience. The former professional wrestler turned pentester had launched DC940, authored bestselling books, and established himself as a global keynote speaker. But by fall 2024, the logistics became unsustainable. He stepped down from his DefCon group leadership role.That same night, walking away from the venue, an idea crystallized. The Dallas-Fort Worth area housed one of the world's largest cybersecurity communities, yet lacked a proper hacker conference. So Wylie sent a text message to Farnum. No expectations beyond advice. Within weeks, they had formalized a partnership that would bring CyberHackCon to the Plano Event Center, the same venue that hosted DalHackCon two decades earlier.What started as Houston's 15-year regional experiment had evolved into a national conference ecosystem. Companies were bypassing Black Hat and RSA entirely, sending whole teams to what was becoming CyberSecCon instead. The infrastructure now includes youth programs, executive events, OT-focused conferences, media arms, venture advisory, and nonprofit partnerships. Five full-time employees orchestrate an operation that refuses to gate its primary educational content behind paywalls, maintains community as the entry point for everything, and somehow preserves the feel of a high school reunion even as it approaches 400 attendees.TIMESTAMPS00:00 Building Community in Cybersecurity05:15 The Evolution of HusekCon to CyberSecCon12:00 The CyberSec Community Ecosystem20:14 Introducing Cyber Hack Con29:04 Call for Papers: Seeking Deep Tech Talks32:20 Engagement and Community Involvement33:44 Conference Experiences: Big vs. Small39:03 Post-Conference Content and Accessibility40:48 Creative Concepts: Cybersecurity-Themed Bar IdeasSYMLINKS[CyberSecCon] - https://www.cybrseccon.com/ Official website of CyberSecCon, a community-driven cybersecurity conference focused on accessibility, education, and bringing together professionals across all experience levels.[CyberSec Media] - https://www.cybrsecmedia.com/ Media platform that publishes cybersecurity talks, videos, and educational content from CyberSecCon and related community initiatives, available for free access.[DEF CON] - https://defcon.org/ One of the world's largest and most well-known hacker conferences, recognized for its deep technical content, hands-on learning, and strong hacker culture.[Michael Farnum – LinkedIn] - https://www.linkedin.com/in/mfarnum Professional profile of Michael Farnum, cybersecurity leader and co-founder of CyberSecCon, where he shares insights on community building and industry initiatives.[Phillip Wylie – LinkedIn] - https://www.linkedin.com/in/phillipwylie Professional profile of Phillip Wylie, penetration tester, instructor, and keynote speaker with extensive experience in cybersecurity and community mentorship.

Hidden In The Shadows Podcast
They Arrive Unannounced: Men in Black, Hat Man & the Hidden Connection

Hidden In The Shadows Podcast

Play Episode Listen Later Apr 20, 2026 47:20


Welcome back to Hidden In The Shadows Podcast.In this episode, we explore one of the most unsettling and mysterious phenomena in paranormal history: the Men in Black. Often described as silent enforcers, these figures appear without warning after UFO encounters, issuing threats, demanding silence, and leaving witnesses shaken.We trace the origins back to one of the earliest recorded encounters in 1947 and follow the pattern through decades of chilling reports. But the deeper we go, the more the question shifts from who they are… to what they are.Are they government agents working to suppress the truth about extraterrestrials, or something far more unnatural attempting to control human awareness?As the episode unfolds, we begin connecting the Men in Black to other phenomena, including shadow entities and the Hat Man, opening the door to a theory that these encounters may not be entirely physical at all.Because sometimes, they don't just observe.Chapters In This EpisodeIntroduction and Personal AnecdotesExploring the Men in Black PhenomenonFamous Encounters with the Men in BlackTheories and Speculations on Men in BlackExploring the Astral Realm and Its EntitiesPersonal Experiences with Alien EncountersThe Hat Man and Its Connection to the Men in BlackThe Gateway Program and Psychic AbilitiesMen in Black: Origins and Cultural ImpactGovernment Agencies and the ParanormalLocal Sightings and Personal AnecdotesMusic CreditsIntro and Outro Music: “Swamp Witch”Additional Intro Music: “Stacy Dahl” by MaudlinFollow Maudlin on TikTok and Instagram: @maudlinListen to Hidden in The Shadows Podcast on Spotify and YouTubeShare Your Paranormal ExperiencesSend us a message on social media, fill out our contact form, or email us:

Risky Business
Risky Business #833 -- The Great Mythos Freakout of 2026

Risky Business

Play Episode Listen Later Apr 15, 2026 59:45


On this week's show, Patrick Gray, Adam Boileau and James Wilson discuss the week's cybersecurity news. They cover: Everyone has an opinion about Claude Mythos… even though almost nobody has used it yet CISA adds a 2009 Excel bug to the KEV list, u wot? Adobe also parties like it's the 2000s, and fixes an Acrobat Reader bug Disgraced former Trenchant exec Peter Williams' sob story fails to resonate with … anyone Remember those crosswalk buttons hacked to play audio mocking Trump and Zuck? They were “secured” by the password: 1234. This week's episode is sponsored by mobile network operator, Cape. Ajit Gokhale talks with James about the ways to get being a telco right when you're starting from scratch and solving the security problems of 2026. This episode is also available on Youtube. Show notes Lab Space The “AI Vulnerability Storm”: Building a “Mythosready” Security Program Polymarket on X: "JUST IN: Goldman Sachs is reportedly ramping up its cyber defenses in preparation for Claude Mythos." Ananay on X: "Marcus Hutchins probably has the best take on Mythos doing vulnerability research" solst/ICE of Astarte on X: "Th vast majority of CISOs do not work at Google-sized companies, and will not have to worry about 0days" Charlie Miller on X: "we've gone through this before with early fuzzers, afl, etc" James Kettle on X: "'Can AI Do Novel Security Research? Meet the HTTP Terminator' will premiere at Blackhat" jeffrey lee funk on X: "We've been tricked, again. Many of the thousands of bugs and vulnerabilities Mythos found are in older software are impossible to exploit." Claude is getting worse, according to Claude • The Register Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain OpenAI's Mac apps need updates thanks to the Axios hack | CyberScoop Hack at Anodot leaves over a dozen breached companies facing extortion | TechCrunch Snowflake customers hit in data theft attacks after SaaS integrator breach Booking.com confirms hackers accessed customers' data CPUID hijacked to serve malware as HWMonitor downloads • The Register Known Exploited Vulnerabilities Catalog | CISA Adobe fixes PDF zero-day security bug that hackers have exploited for months | TechCrunch The Sad Decline of Trenchant Exec Who Had Everything, Before Deciding to Steal and Sell Zero Days to Russian Buyer FBI Extracts Suspect's Deleted Signal Messages Saved in iPhone Notification Database US operation evicts Russia from hacked SOHO routers used to breach critical infrastructure | Cybersecurity Dive Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market | WIRED The Dumbest Hack of the Year Exposed a Very Real Problem | WIRED

Small Efforts - with Sean Sun and Andrew Askins
Why We Stopped Paying for Cursor and Switched to Claude Max

Small Efforts - with Sean Sun and Andrew Askins

Play Episode Listen Later Apr 13, 2026 50:46


Andrew ditched Cursor for Claude Max and the economics made it an easy call. In this episode they get into the Meta Monster pivot toward content optimization, why Claude hallucinated an entire Wix API, and what the switch to Conductor actually looks like day to day. Links:Andrew's Twitter: @AndrewAskinsAndrew's website: https://www.andrewaskins.com/MetaMonster: https://metamonster.ai/Slackletter: https://slackletter.com/Sean's Twitter: @seanqsunMiscreants: http://miscreants.com/Margins: http://margins.so/Sean's website: https://seanqsun.com/For more information about the podcast, check out https://www.smalleffortspod.com/.Transcript: 00:00.47SeanCool. Thanks. What's up?00:03.03AndrewNot much. I haven't seen you in like three fucking months.00:06.58SeanYeah.00:06.74AndrewHow are you?00:08.06Seanah I'm good. Q1 is finally over. RSA is finally over. So now it's time to worry about Black Hat.00:15.45AndrewJesus.00:17.14Seanum But.00:19.03AndrewQ1 being finally over means we're like even closer to the death day for Metamonster.00:19.26Seanah00:25.67SeanOh, yeah. Yeah, yeah.00:27.03AndrewHave I told you this, that like Austin and I were like, if if it's not working by the middle of the summer, we're gonna, we need to like pull the plug.00:34.90SeanYou have. You have. yeah What would you do if you pulled the plug? Would you start a new thing, or can I finally hire you again?00:43.25AndrewDude, i I have, I don't know, is the short answer, but I have lots of thoughts. Like part of me wants to to buy a trad business, which is what I've been calling brick and mortar businesses lately.00:53.78AndrewAnd every time I say it, it makes people cringe, which is why I continue to say it.00:56.04SeanThat's horrible. du't That's disgusting. Mexico City is changing you. i can't believe you'd say that.01:02.13AndrewWhoa, whoa, whoa, whoa, whoa.01:03.16Seanforpin01:05.14AndrewNo, that's just me having a stupid sense of humor. You can't blame Mexico City for that.01:07.90SeanNo, no, it's good.01:09.10AndrewMexico City way too beautiful a place to blame for that.01:09.88SeanIt's good. Speaking, speaking of trad related things, have you seen the documentary?01:14.26AndrewOh God, where is this going?01:18.45SeanHave you been, ah have you been, ah did you watch the Manosphere documentary on Netflix with Louis Thoreau?01:24.79AndrewNo, but my little sister did and she was like, you have to watch it.01:28.22SeanIt's so good.01:28.28AndrewAnd i I haven't watched it yet. Yeah.01:30.15SeanIt's so good. It's all Ben and I could talk about at RSA.01:34.26AndrewNice.01:34.32SeanSorry.01:35.00AndrewHave you seen Project Hail Mary yet?01:37.11SeanNo, I hear it's good, but i don't know what it's about.01:38.71AndrewI hear it's really good. Yeah. Oh, you didn't read the book?01:42.21SeanNo, I don't read.01:43.86AndrewI forgot.01:44.73Seanyeah i think I think if all books were in AI chat bubbles, I would read all of it, but they're not. so that's01:52.77AndrewThat's the lamest thing you've ever said to me. It's almost as bad as trad businesses.01:59.32Seanit's It's probably worse.02:02.68Seanum How you been?02:03.89AndrewDude, I've been good.02:04.43SeanHow's life?02:06.32Andrewum We are working on a pivot for Metamonster. i am becoming, I'm embracing the fully AI-pilled by boy life.02:10.74SeanOK.02:18.71SeanOK.02:18.81Andrewum i still love Mexico. Yeah.02:23.66SeanGood.02:26.68Andrewyeah02:28.11SeanOK, can you tell me, can you just tell me what you're pivoting to before I like rip my hair out? Because I really need you to build some features at the moment.02:35.48AndrewSo it's I call it a pivot part somewhat facetiously. um02:39.31SeanOK.02:40.45Andrewwe're We're not really pivoting, like the tool is still going to work the same way it does now, um but we're going deep on content optimization.02:46.03SeanCool.02:51.03AndrewSo we're building we're building a single page view where you can still update metadata, but we also do SERP analysis and content recommendations for you and help you auto apply them.03:04.79Andrewum And so we're we're going to be adjusting our positioning to more directly take on ClearScope and Surfer. um03:15.96Seanand air ops.03:16.09AndrewSo the Yeah, air ops a little bit. I think of air ops as a little bit different. I think of air ops more as content orchestration, um like generate content at scale, whereas we're more content optimization.03:30.78AndrewSo like take your existing content or like new pieces of content and help you optimize it. Yeah.03:38.01SeanSick.03:39.39AndrewYep.03:40.43SeanCool.03:40.44Andrewum03:41.18Seanis Is this like a like like an editor that I'm writing in? And then, OK, cool. And then you can publish the web flow.03:49.05Andrewah Yeah, yeah, yeah, yeah.03:50.40SeanOh, good, good, good, good.03:50.74AndrewTotally, totally.03:52.44SeanYou should do it. You should do it so I can use it. i don't I don't care.03:55.22AndrewYeah.03:56.00SeanNo. What?03:56.73AndrewSo, the um I, did you see my LinkedIn post by chance? Dude, I spent like half of last week vibing with Claude on a Wix integration, and then I finally go to test it.04:13.21Andrewit It shouldn't have taken me a a whole week to test it. I just got distracted by like three other things. um And I finally go to test it, and I'm like, huh, it's not working. Why isn't it working?04:23.70AndrewAnd Claude goes, oh yeah, the Wix API I was using was purely speculative. Like, I just made it up. I was like, motherfucker Are you fucking kidding me? um And it turns out like Wix, like Squarespace does not support us updating SEO metadata for anything except blog posts. So I just scrapped the whole thing and was like, fuck this.04:48.31Andrewum04:49.72SeanWell, but you could do like cloud code browser use types of things to like manually.04:55.80AndrewI could and I did and it took for fucking ever. It took like two hours to update 30 pages. It was painfully slow and eventually ran out of context.05:04.43SeanGotcha.05:07.72SeanGotcha.05:07.77Andrewum05:08.57SeanDamn.05:08.92AndrewAnd I was just like, this is horrible. um So ah yeah, my hope is that like Wix and Squarespace wake the fuck up and realize what century they're living in and build a decent hal...

Mike Boyle Restaurant Show Podcast
Black Hat Cattle CO. Sushi AND Frozen Meals!! We Don't Discriminate!!!

Mike Boyle Restaurant Show Podcast

Play Episode Listen Later Apr 11, 2026 39:59


Mike tells us about his upcoming and soon to be recapped visit to Fontana Sushi then gives us the breakdown on The Black Hat Cattle Co's change in ownership and really good frozen Meals!!! We serve it all up!!! Stay Informed!!! www.mikeboyle.comSee omnystudio.com/listener for privacy information.

The Nomad Solopreneur Show
#153 - From Organic Farming to SEO: Greg Heilers Impressive Journey

The Nomad Solopreneur Show

Play Episode Listen Later Apr 7, 2026 47:31


Greg Heilers recounts spending nearly seven years on organic farms and conservation projects worldwide before abandoning a planned culinary internship in Rome to move to Beijing after meeting his now-wife in Guatemala, shifting from “voluntourist” nomad life to building a home and transitioning into digital work.He describes adapting to China as a foreigner, starting with English and cultural localization editing, then moving into writing and realizing he had entered the SEO content ecosystem, later specializing in offsite SEO and journalist outreach.Greg contrasts “black hat” ROI-driven tactics with sustainable brand-focused strategies, discusses the costs of manipulating consumers, and explains how AI and platform deals (Google-Reddit, Reddit-OpenAI) reshaped SEO, pushing toward “SEO plus AI search.”He shares how he manages learning and building time as a business owner, the realities of running an agency, contingency plans if the business failed, misconceptions about living in China, and practical earned-media steps, maintaining consistent brand identity and EEAT signals.

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education
Why is EVERYONE Failing At Gamification? (WHAT'S REALLY GOING ON?) | Episode 439

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Play Episode Listen Later Apr 6, 2026 6:54


Master the science of motivation and see how top experts do it right. Get the free 9-day "Core Drives in the Wild" email sequence here: professorgame.com/WildCD We break down three massive gamification disasters from 3 huge companies to reveal exactly what happens when we ignore behavioral science. We explain how well-intentioned features like leaderboards and point systems can accidentally create toxic work environments or destroy thriving communities. By applying the Octalysis framework, we highlight the dangers of relying too heavily on Black Hat motivation and extrinsic rewards without balancing them correctly. You will learn how to design systems that drive genuine engagement rather than building expensive burnout traps. Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia.   Lets's do stuff together! Core Drives in the Wild: Professor Game Guide Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Risky Business
How the World Got Owned Episode 2: The 1990s, Part One

Risky Business

Play Episode Listen Later Apr 3, 2026 46:46


In this special documentary episode, Patrick Gray and Amberleigh Jack take a look back at hacking throughout the 1990s, from the feel-good vibes of the early hacking communities to the antics of young hackers who wound up on the run from the FBI. Part one features recollections from: Jeff Moss (The Dark Tangent), DefCon and Black Hat founder Chris Wysopal (Weld Pond), L0pht member, co-founder, @Stake Kevin Poulsen (Dark Dante), 1990s hacker turned journalist Elias Levy (Aleph One), author of Smashing the Stack for Fun and Profit, Phrack, 1996 How the World Got Owned is produced in partnership with SentinelOne. Show notes Elias Levy (Aleph1), Former Principle Engineer, Google Kevin Poulsen, Journalist Jeff Moss, DefCon founder Chris Wysopal, @Stake founder, L0pht member Hackers testifying at the United States Senate, May 19, 1998 Hackers May ‘Net' Good PR for Studio DefCon Archives | DefCon 1 A Not So Terribly Brief History of the Electronic Frontier Foundation Innocent Hackers Want Their Computers Back Breakdowns in Computer Security Unsolved Mysteries, Season 3, Episode 4 The Last Hacker: He Called Himself Dark Dante. His Compulsion Led Him to Secret Files and, Eventually, The Bar of Justice Justia appeal summary, Kevin Poulsen, 1994 Smashing the Stack for Fun and Profit, Phrack Magazine, November 1996 From subversives to CEOs: How radical hackers built today's cybersecurity industry

Dark Rhino Security Podcast
S19 E0 (VIDEO) How Hackers Exploit Hidden Vulnerabilities

Dark Rhino Security Podcast

Play Episode Listen Later Apr 2, 2026 40:06


#SecurityConfidential #DarkRhiinoSecurityDiyar Saadi Ali is a cybersecurity professional specializing in cybercrime investigations, SOC operations, and malware analysis. A contributor to the MITRE ATT&CK framework, Diyar has helped strengthen global threat intelligence efforts and defensive strategies. Diyar regularly speaks at international cybersecurity conferences including Arab Cyber Security, DeepSec, GISEC, BlackHat, and SulyCon, contributing to the advancement of the global cyber community.00:00 Intro02:26 Our Guest03:42 Learning Cybersecurity in Iraq07:40 The MITRE attack Framework: Is that all the knowledge we know? 11:30 There are still tons of unknown vulnerabilities13:30 You can't fake motivation17:00 Defenders are to blame19:16 Who is coming up with Malware?22:10 Every crime leaves a trace24:12 AI is making malware easy29:00 Governance and Trust38:02 Presentations and News from Diyar----------------------------------------------------------------------To learn more about Diyar visit https://www.linkedin.com/in/diyarsaadi/To learn more about Dark Rhiino Security visit https://www.darkrhiinosecurity.com

Dark Rhino Security Podcast
S19 E0 How Hackers Exploit Hidden Vulnerabilities

Dark Rhino Security Podcast

Play Episode Listen Later Apr 1, 2026 40:06


Diyar Saadi Ali is a cybersecurity professional specializing in cybercrime investigations, SOC operations, and malware analysis. A contributor to the MITRE ATT&CK framework, Diyar has helped strengthen global threat intelligence efforts and defensive strategies. Diyar regularly speaks at international cybersecurity conferences, including Arab Cyber Security, DeepSec, GISEC, BlackHat, and SulyCon, contributing to the advancement of the global cyber community.00:00 Intro02:26 Our Guest03:42 Learning Cybersecurity in Iraq07:40 The MITRE attack Framework: Is that all the knowledge we know? 11:30 There are still tons of unknown vulnerabilities13:30 You can't fake motivation17:00 Defenders are to blame19:16 Who is coming up with Malware?22:10 Every crime leaves a trace24:12 AI is making malware easy29:00 Governance and Trust38:02 Presentations and News from Diyar

DrZeroTrust
Balancing Hoodies and Suits in Cybersecurity

DrZeroTrust

Play Episode Listen Later Mar 30, 2026 23:08


Most cybersecurity conferences have become echo chambers filled with repetitive buzzwords and the same problems dressed up in new clothes—until now. At RSA 2023, Chase Cunningham and industry insiders peel back the hype, revealing why much of what's marketed as revolutionary is just a rehash of old issues with a shiny AI layer. They expose the industry's broken system, the deluge of vendors pushing features over real solutions, and the absurdity of AI washing across booths.You'll discover how the cybersecurity industry is fundamentally broken—sold and purchased like healthcare, with vendors cashing in on the chaos. Chase highlights what's really valuable on the show floor, distinguishing between blind VC pump-and-dump tactics and genuine game-changing innovations. He breaks down why AI, despite the hype, is exposing long-standing vulnerabilities rather than creating new solutions, and how the race to be the loudest often masks the lack of substance.We break down the political landscape of cybersecurity conferences: RSA vs. Black Hat vs. DEF CON—what they reveal about the industry's focus, and why the most meaningful conversations happen in smaller, more intimate settings. Chase warns of the coming AI hype backlash and warns CISOs to resist being lured into buying solutions that won't deliver. Instead, he advocates returning to fundamentals—doing the basics well with clarity and focus—while leveraging AI to enhance, not replace, core security practices.Why does this matter? Because the current cycle is setting organizations up for disappointment and missed opportunities. Yet, amid the noise, there's genuine innovation, a shift in community dynamics, and a growing recognition that cybersecurity's true future depends on embracing the basics again. This episode is essential listening for leaders tired of the hype and hungry for real strategy, honest conversations, and practical solutions in a rapidly evolving landscape.Want to understand what's really happening behind the corporate curtain at RSA? Curious about why the AI frenzy might do more harm than good? Or looking for how to cut through the noise and get back to what works? Tap in now—this episode is your strategic reset.

The Cybersecurity Defenders Podcast
Bringing 40+ year old industrial security systems into the 21st century with Justin Searle from InGuardians [#304]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Mar 25, 2026 31:08


Justin Searle, Director of ICS Security at InGuardians, joins us today to talk about the challenges facing industrial control system security. With increased attack surface areas and maintaining and updating decades-old systems, Justin's dedication to informing and educating newcomers and experts alike is more important now than ever before.As the Director of ICS Security at InGuardians, Justin specializes in ICS security architecture design and penetration testing. He led the Smart Grid Security Architecture group in creating the NIST Interagency Report 7628 and has played key roles in the Advanced Security Acceleration Project for the Smart Grid (ASAP-SG), National Electric Sector Cybersecurity Organization Resources (NESCOR), and Smart Grid Interoperability Panel (SGIP). Justin is the owner of ControlThings LLC, a member of the SANS faculty, and an instructor at BlackHat. He has authored and taught numerous courses such as ICS410: ICS/SCADA Security Essentials, Assessing and Exploiting Control Systems and IIoT, Assessing and Exploiting Web Applications with SamuraiWTF, and SEC542: Web App Penetration Testing and Ethical Hacking. Justin also presents on a range of cybersecurity topics at leading security conferences across the globe.Learn more at: controlthings.ioSupport our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

Don't experiment on your own revenue with broken game mechanics. Get our guide "Core Drives in the Wild" to learn how to apply real behavioral science to your product: professorgame.com/WildCD We dismantle the myth that simply adding points, badges, and leaderboards will fix a broken product. We explore why superficial rewards often lead to a 90% failure rate in corporate gamification and cause dangerous spikes followed by massive engagement crashes. By contrasting Google News's failed badge system with Wikipedia's intrinsic motivation model, we highlight the critical shift from transactional features to human-focused behavioral science. You can learn how to balance White Hat techniques like Epic Meaning with Black Hat mechanics like Scarcity to build long-term retention without burning out your user base. Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia. Links and resources Google News: https://news.google.com Wikipedia: https://www.wikipedia.org Duolingo: https://www.duolingo.com The Octalysis Group: https://octalysisgroup.com Lets's do stuff together! Core Drives in the Wild: Professor Game Guide Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Coffee and Open Source
Nir Valtman

Coffee and Open Source

Play Episode Listen Later Mar 17, 2026 56:44


Nir is an experienced information security leader, executive, expert and a public speaker at leading conferences globally, including Black Hat, Defcon, BSides, and RSA. Before founding Arnica, Nir lead the product and data security across Finastra, established security at Kabbage (acquired by Amex) as CISO, and headed application security across NCR. Innovation is a key driver for Nir, as reflected by his contribution to open source projects and invention of 7 patents in software security.You can find Nir on the following sites:BlogLinkedInXYouTubeHere are some links provided by Nir:Arnica PLEASE SUBSCRIBE TO THE PODCASTSpotifyApple PodcastsYouTube MusicAmazon MusicRSS FeedYou can check out more episodes of Coffee and Open Source on https://www.coffeeandopensource.comCoffee and Open Source is hosted by Isaac Levin

Layer 8 Podcast
Episode 138: Layer 8 Keynote Speaker Christina Lekati

Layer 8 Podcast

Play Episode Listen Later Mar 16, 2026 40:29


The Layer 8 Conference is excited to announce the first of its keynote speakers for 2026, Christina Lekati!Christina is a social engineering specialist who works with Cyber Risk, GmbH in Munich, Germany. She got her undergraduate degree in Psychology and has a Masters in International Business Studies. She has been a part of the OSINT Curious team and has taught her classes at Black Hat in Las Vegas but will also be offering her two-day social engineering class at the Layer 8 Conference this year. Come join us at the Layer 8 Conference, meet Christina and all of our other incredible speakers in Boston, MA on June 5-6.

ITSPmagazine | Technology. Cybersecurity. Society
Task by Task: The Workflows We're Handing to AI — One Decision at a Time | Lens Four by Sean Martin | Read by TAPE9

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Mar 10, 2026 28:56


Nobody decided to build a human-optional workflow — they just kept making reasonable procurement decisions, task by task, until the human became optional across hiring, contracting, finance, and security operations. Sean Martin traces what organizations have actually assembled, where accountability lives when it goes wrong, and why the regulatory window for getting ahead of it is closing faster than most leaders realize. In this edition of Lens Four, Sean Martin looks at the agentic AI landscape through three lenses — programs, innovation, and messaging — to connect the signals that matter.

Professor Game Podcast | Rob Alvarez Bucholska chats with gamification gurus, experts and practitioners about education

If you're implementing AI and want to realize that promised ROI, let's see if Octalysis fits → professorgame.com/chat Breaking down why most AI projects fail despite being technically flawless. The problem isn't the code; it's the lack of behavioral design. By applying the Octalysis Framework, we see how to move away from "Black Hat" implementations that trigger resistance and identity threats. Instead, we shares how to design AI as an individual contributor's superpower. It is a deep dive into balancing short-term Black Hat-driven data bumps with long-term White Hat engagement to ensure your team feels like masters of their craft rather than data entry clerks for an algorithm. Rob Alvarez is Head of Engagement Strategy, Europe at The Octalysis Group (TOG), a leading gamification and behavioral design consultancy. A globally recognized gamification strategist and TEDx speaker, he founded and hosts Professor Game, the #1 gamification podcast, and has interviewed hundreds of global experts. He designs evidence-based engagement systems that drive motivation, loyalty, and results, and teaches LEGO® SERIOUS PLAY® and gamification at top institutions including IE Business School, EFMD, and EBS University across Europe, the Americas, and Asia.   Links to episode mentions: Let's implement AI successfully leveraging Octalysis Behavioral Design professorgame.com/chat How gamifying AI shapes customer motivation, engagement, and purchase behavior Harmonizing human-AI synergy: behavioral science in AI-integrated design Digital tracking, gamification, social media, and AI: How technology influences motivation AI-Driven Gamification Approaches: Enhancing Engagement Through Intelligent  Systems Some of The Octalysis Group's resources: Why Your Sales Leaderboard is Killing Performance (And What AI-Driven Motivation Actually Looks Like) How AI Loyalty Programs are Rewriting Loyalty Why Corporate Learning Platforms Fail (AI Corporate Learning) AI-Powered Behavioral Design for Customer Loyalty The Fintech Engagement Crisis: Why AI Without Behavioral Design Creates Apps Nobody Uses AI Powered FMCG Loyalty: Escaping the Points Trap with Behavioral Design   Lets's do stuff together! Let's chat about your gamification project YouTube LinkedIn Instagram Facebook Start Your Community on Skool for Free Ask a question

Bankless
AI Finds 70% of Smart Contract Exploits | Alpin Yukseloglu

Bankless

Play Episode Listen Later Mar 5, 2026 61:38


AI is getting dangerously good at smart contract security. Faster than crypto is ready for. Alpin Yukseloglu joins Bankless to break down EVMBench (built with OpenAI), a benchmark testing whether AI agents can detect, patch, and exploit real fund-draining bugs and why the jump from ~12–13% exploit-finding to 70%+ could rewrite today's security assumptions. We unpack what that “70%” really means, why crypto's verifiability is an ideal training ground, why AI labs haven't prioritized crypto data yet, and what a 24/7 blackhat vs whitehat AI arms race means for DeFi. ---

Critical Thinking - Bug Bounty Podcast
Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND

Critical Thinking - Bug Bounty Podcast

Play Episode Listen Later Mar 5, 2026 71:56


Episode 164: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Tommy DeVoss to talk about his origin story, Yahoo bugs, and how Tommy first got Justin into Bug BountyFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest: https://x.com/thedawgyg====== This Week in Bug Bounty ======Python pitfalls: Turning developer mistakes into vulnerabilitieshttps://www.yeswehack.com/learn-bug-bounty/python-pitfalls-turning-developer-mistakes?utm_source=critical-thinking&utm_medium=sponsored&utm_campaign=article-research-python-pitfalls====== Timestamps ======(00:00:00) Introduction(00:06:22) Yahoo SSRF(00:14:56) Tommy's Origin(00:44:10) Bug Bounty(00:51:47) SSRF Attraction, AI implementation, & Browser Hacking

BarCode
Moo Muhammad

BarCode

Play Episode Listen Later Mar 3, 2026 41:17


An Uber ride. A stranger in the backseat. A conversation that changes everything. What if the person who redirects your entire life is someone you've walked past a thousand times and never noticed? This is the story of a kid from West Philly who didn't know what a server was, what the cloud meant, or why Windows OS mattered and then turned that into a cybersecurity career built on hustle, community, and an obsession with doing the work. 00:00 Moo's Journey into Cybersecurity09:14 Navigating Distractions in Tech13:26 Finding Passion and Purpose17:11 The Reality of Rapid Industry Changes23:11 Supporting Newcomers in Cybersecurity25:53 Starting Over: Lessons Learned29:41 Experiencing Hacker Summer Camp35:07 The Culture of Networking and Community38:39 Unique Bar Experiences and Networking44:10 Creative Drink Ideas and Closing ThoughtsSYMLINKSMoo Muhammad – LinkedInhttps://www.linkedin.com/in/munirmuhammad/Cybersecurity professional specializing in application security, incident response, and hands-on technical projects. Connect to follow his work, insights, and career journey in tech.National Society of Black Engineers (NSBE) – https://www.nsbe.orgA professional organization supporting Black engineering students and professionals through mentorship, scholarships, and career development.IEEE (Institute of Electrical and Electronics Engineers) – https://www.ieee.orgA global professional organization advancing technology, offering resources, publications, and networking for engineers and technologists.Women in Cybersecurity (WiCyS) – https://www.wicys.orgA nonprofit organization dedicated to recruiting, retaining, and advancing women in cybersecurity through mentorship, conferences, and career opportunities.DEF CON – https://defcon.orgOne of the world's largest and most well-known hacker conferences, held annually in Las Vegas as part of “Hacker Summer Camp.”Black Hat – https://www.blackhat.comA premier cybersecurity conference series featuring technical training, research briefings, and industry networking events.

Beyond The Horizon
From Wall Street to DEF CON: How Epstein Sought Access to Cybersecurity's Inner Circle (2/16/26)

Beyond The Horizon

Play Episode Listen Later Feb 16, 2026 19:25 Transcription Available


Documents released by the U.S. Justice Department show that convicted sex offender Jeffrey Epstein spent years corresponding with figures in the cybersecurity community and repeatedly tried to involve himself with two of the world's biggest hacker conventions, DEF CON and Black Hat, in Las Vegas. According to emails reviewed by Politico, Epstein's interest in cryptography and cybersecurity extended back to at least 2010, and he discussed topics ranging from network security to ways of pushing negative information about himself down in internet search results. Though he expressed a desire to attend these major events — even at times proposing to bring high-profile guests — there's no clear evidence he ever actually got into either conference, and organizers like Jeff Moss have said there's no proof he followed through on plans to attend.The documents also reveal Epstein's broader tech network, including contacts with researchers and entrepreneurs introduced through academic and startup circles. Among those mentioned was Italian security researcher Vincenzo Iozzo, who communicated with Epstein about potential business opportunities and emerging technologies but has denied doing any technical work for him. An FBI file included in the release also alleges Epstein may have had an unidentified “personal hacker” who developed offensive cyber tools sold to governments, though the name was redacted and some of the claims remain unverified.to contact me:bobbycapucci@protonmail.comsource:Jeffrey Epstein spent years building ties to well-known hackers - POLITICO

The Epstein Chronicles
From Wall Street to DEF CON: How Epstein Sought Access to Cybersecurity's Inner Circle (2/16/26)

The Epstein Chronicles

Play Episode Listen Later Feb 16, 2026 19:25 Transcription Available


Documents released by the U.S. Justice Department show that convicted sex offender Jeffrey Epstein spent years corresponding with figures in the cybersecurity community and repeatedly tried to involve himself with two of the world's biggest hacker conventions, DEF CON and Black Hat, in Las Vegas. According to emails reviewed by Politico, Epstein's interest in cryptography and cybersecurity extended back to at least 2010, and he discussed topics ranging from network security to ways of pushing negative information about himself down in internet search results. Though he expressed a desire to attend these major events — even at times proposing to bring high-profile guests — there's no clear evidence he ever actually got into either conference, and organizers like Jeff Moss have said there's no proof he followed through on plans to attend.The documents also reveal Epstein's broader tech network, including contacts with researchers and entrepreneurs introduced through academic and startup circles. Among those mentioned was Italian security researcher Vincenzo Iozzo, who communicated with Epstein about potential business opportunities and emerging technologies but has denied doing any technical work for him. An FBI file included in the release also alleges Epstein may have had an unidentified “personal hacker” who developed offensive cyber tools sold to governments, though the name was redacted and some of the claims remain unverified.to contact me:bobbycapucci@protonmail.comsource:Jeffrey Epstein spent years building ties to well-known hackers - POLITICOBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-epstein-chronicles--5003294/support.

Cybercrime Magazine Podcast
Cybercrime News For Feb. 16, 2026. Black Hat Removes Epstein-Linked Hacker. WCYB Digital Radio.

Cybercrime Magazine Podcast

Play Episode Listen Later Feb 16, 2026 2:29


The Cybercrime Magazine Podcast brings you daily cybercrime news on WCYB Digital Radio, the first and only 7x24x365 internet radio station devoted to cybersecurity. Stay updated on the latest cyberattacks, hacks, data breaches, and more with our host. Don't miss an episode, airing every half-hour on WCYB Digital Radio and daily on our podcast. Listen to today's news at https://soundcloud.com/cybercrimemagazine/sets/cybercrime-daily-news. Brought to you by our Partner, Evolution Equity Partners, an international venture capital investor partnering with exceptional entrepreneurs to develop market leading cyber-security and enterprise software companies. Learn more at https://evolutionequity.com

Ultimate Guide to Partnering™
288 – The Millions You're Losing Without Even Knowing It

Ultimate Guide to Partnering™

Play Episode Listen Later Feb 15, 2026 12:02


The Deal You Never Knew Existed. Subscribe to our Newsletter: https://theultimatepartner.com/ebook-subscribe/ Check Out UPX: https://theultimatepartner.com/experience/ In this deep dive, Jay McBain reveals the harsh reality of the “28 Moments” in a modern B2B buying journey, using a multi-million dollar SAP deal at AstraZeneca as a wake-up call for vendors. He explains how traditional marketing leads are failing in the “decade of the ecosystem,” where trusted partners like NTT and SoftwareOne are winning deals in “light blue” partnership moments months before a customer ever downloads an ebook. If you aren’t visible in the seven-layer stack or collaborating with the partners who hold the customer’s trust, you aren’t just losing the deal—you're losing the entire market. https://youtu.be/NO-P6X2dTAo?si=8e_sVesqvwaC0M-E Key Takeaways Most vendors lose major deals without ever knowing a transaction was even taking place. The average considered purchase involves 28 distinct moments of research and influence before a sale. Trusted partners often close the deal in the “middle moments” months before the money is actually spent. Traditional marketing leads (MQLs) are often too “flimsy” compared to deep partner-led relationships. Winning in the ecosystem requires being part of a “seven-layer stack” of integrated technology and services. Data-sharing platforms like Crossbeam and Workspan are now essential to seeing the “invisible” pipeline. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags: 28 Moments, Jay McBain, Ecosystem Strategy, AstraZeneca SAP Deal, Seven Layer Stack, B2B Buying Journey, Partner Ecosystem, NTT, SoftwareOne, Channel Strategy, Buyer Intent, Informa TechTarget, Collaborative Selling, Crossbeam, Partner Tap, Workspan, Marketplace Tracking, Co-selling, Tech Integration, Revenue Architecture, Pipeline Growth, Trusted Advisor, Digital Transformation, SAP Optimization, Microsoft AWS Competition. Transcript: [00:00:00] Jay McBain: So if you’re a vendor trying to get into that seven layer stack and you don’t have that relationship, or you don’t have the knowledge that NTT or software one is going in, this will have been a deal that would’ve never hit your pipeline and you’ll have no knowledge. So you will have lost this deal without knowing there was a deal. [00:00:19] Vince Menzione: We’ve been talking 28 moments, but you have a slide. I thought we’d spend some time here because, you know, every conversation with you is about 28 moments, but you finally took the time to analyze one of your deals or one of the deals that was going on with one of your clients and come up with the 28 moments. [00:00:36] Vince Menzione: I thought we’d spend a little time here because this journey slide is a wake up call. Uh, it’s, it’s, it’s all around. Why, why we need to think about all of those. Points we need to think about communities and analysts and marketplaces and proof of concepts and architecture and everything else. I thought maybe you’d take us through this a little bit. [00:00:53] Vince Menzione: ’cause this was for a client, AstraZeneca, by the way. This was, uh, if you don’t know this, ICI Americas was the precursor of mm-hmm. AstraZeneca. It was the first SAP customer in North America. [00:01:03] Jay McBain: Nice. I did [00:01:04] Vince Menzione: not know that. That’s why Microsoft and SAP both headquartered. In that area, near nearby, that client. [00:01:10] Vince Menzione: That’s, uh, news, new news. [00:01:11] Jay McBain: And by the way, this is an SAP deal we’re looking at. Yeah. Uh, so two things here. One is that, um, while I was declaring the decade of the ecosystem, you know, spending time with you and Boca, in between that time we got acquired. Canals, which was Latin for channel, got acquired by oia, part of Informa TechTarget, part of this bigger informa company, which is a Fortune 100 company outta the uk. [00:01:32] Jay McBain: Fantastic. You know, we’re part of this massive organization that is really around buyer intent. How, you know, a tech target and, uh, running hundreds of magazines like Information Week and Computer Week that customers and partners read running hundreds of events, the biggest events on the planet. [00:01:49] Vince Menzione: Crazy [00:01:49] Jay McBain: in B2B, like Black Hat and all these things are run by [00:01:52] Vince Menzione: Yeah, [00:01:53] Jay McBain: informa. [00:01:53] Jay McBain: So it’s got this massive mountain of data. About the 28 moments. So when you start to think if you’re a CMO and you start to think about the early moments, you, you think about somebody reading an ebook or, um, going to a, a webinar or going onto a LinkedIn live just like this one. Yeah, going to a major event and getting a pair of socks from you. [00:02:13] Jay McBain: Um, but anything early in the journey. These are the m qls. These are the things that I need enough of them to be credible before I hand them over to my sales team. ’cause I don’t wanna be laughed out of the room. Hey, they read an ebook. They must, AstraZeneca must be buying millions of dollars of stuff. [00:02:27] Vince Menzione: Traditional marketing lead. [00:02:29] Jay McBain: Traditional marketing lead. So they’re a bit nervous about sharing that. And then later on, the sales motions, the demos and all the progression of the sales. This was the two decades before us, the decade of sales, decade of marketing. But the 28 moments, just to take a step back, if you haven’t heard, it is just a considered purchase. [00:02:46] Jay McBain: It’s about psychology, human psychology. When you go and buy a car, second most expensive thing that you will purchase you on average will go through 28 moments getting ready for that purchase. Some people go through two moments and they just drive to the Cadillac dealership to see Larry, who’s been selling Cadillacs to the family for 80 years. [00:03:04] Jay McBain: Yep. Some people spend 58 moments. That’s probably me. [00:03:07] Vince Menzione: That’s you, a, [00:03:08] Jay McBain: you know, going through all the depreciation, watching every YouTube video, you know, going to the end of the earth. But the average is 28. So you start to think about this, this is the same buying a car considered purchase, that you would buy a million dollars in software. [00:03:21] Jay McBain: From Microsoft or SAP. So when you look at these moments, you start to think, you know, how is you before you buy that car, downloading the invoice price, downloading this month’s backend rebates. Should I buy it in January? Should I buy it in February? All these decisions you make before you get to that dealership, you’re smarter than the salesperson, smarter than the sales manager. [00:03:39] Jay McBain: You know what 5,000 people bought the car for within 50 miles of you? I mean, you’re just so smart. You actually don’t need the dealership anymore. Just Carvana to me, hand me the keys. Exactly. But now in buying technology, hardware, software services, customers are getting this smart. And here’s all the moments they take to get this smart. [00:03:57] Jay McBain: But the thing we always had in mind in this decade of the ecosystem was the 96% there are trusted people. Yeah. Spending decades building that trust that come in in critical moments. They’re not marketing moments, they’re not sales moments. They are fully partnership moments. Yeah. And they’re on this slide in light blue. [00:04:15] Jay McBain: So if you were to look at this deal and, and somebody in marketing is finding these eBooks and webinars and they think there might be something, AWS got a direct hit on their website. So there’s something brewing at AstraZeneca. It, it might be in, it’s a big pharmaceutical company, so you’re probably spending millions of dollars if something’s brewing. [00:04:31] Jay McBain: Yep. But guess what? At the same time, in December on this six month journey. Partners come in with five different paid projects, consulting, advisory design projects, and in this case it was NTT software one, Yash and uh, ISV was there. Yep. But NTT won three different. Deals right at that critical stage. It wasn’t Accenture, it wasn’t Deloitte, NTT at this particular department of AstraZeneca had spent the decades building those relationships. [00:04:58] Jay McBain: So they were the one, and they won critical part of this. And so that’s when the deal is won. And it’s not at April when the money’s being spent. Yeah, it’s, it’s not in March when a couple more ISVs joined the mix, that seven layer stack that solves this particular problem, it was right there. So if you’re a vendor trying to get into that seven layer stack and you don’t have that relationship, or you don’t have the knowledge that NTT or software one is going in, this will have been a deal that would’ve never hit your pipeline and you’ll have no knowledge. [00:05:30] Jay McBain: So you will have lost this deal without knowing there was a deal, which makes up again, the majority of your tam. [00:05:34] Vince Menzione: Yeah. [00:05:35] Jay McBain: But what if I did have this agentic ability to see this deal coming, and I’m a cybersecurity company, I’m just competing for layer five of the deal, but I know that it’s all happening in December. [00:05:46] Jay McBain: So the two things that jump out on this particular slide is one, they don’t just show up in December. [00:05:51] Vince Menzione: Yeah, [00:05:51] Jay McBain: this went closed one in their Salesforce CRM in August, September, well, before the customer ever read an ebook. So now you’re not dealing with a flimsy MQL. You’re dealing with a couple of great, you know, top partner 1000 sized firms. [00:06:09] Jay McBain: One of them is a partner, 30 firm. [00:06:11] Vince Menzione: Exactly. [00:06:12] Jay McBain: That is absolutely going into and earning hundreds of thousands of dollars in services to guide the customer to a millions of dollars in purchase. And, and you can imagine in that boardroom. With A CMO saying, Hey, I got this stuff here. And the head of channels or partnerships saying, no, no, this is real. [00:06:32] Jay McBain: Here’s the names, faces, and places. Yeah. And here’s how it’s happening. And this is exactly, this is the Gantt chart, this is the show up, this is the project, this is the outcome. This is exactly how it’s playing out. Now if I could go back and the board and the C-suite should be asking us, well, how many more deals like this can you see? [00:06:50] Vince Menzione: Yeah. [00:06:51] Jay McBain: If our TAM is, you know, how many billions of dollars? Could you double our pipeline by seeing more of these middle moments? And if we got a couple of months to spend with these partners before they get in front of the customer, could they build more of our portfolio into the deal so we’re not just layer five, maybe we’re layer three and layer five. [00:07:10] Vince Menzione: This slide screams at me. Integr Tech integration Cha. A partner channel integration of tech, uh, whether it’s Crossbeam, whether it’s Partner Tap, whether it’s work span, or any of these other technologies, tackle any of these technologies that are tracking marketplace, that are tracking partner to partner, co-selling. [00:07:30] Vince Menzione: Getting the integration points. The only way to really understand the situation here, because this is a multinational company. Yeah. It’s being touched at all PO points around the globe. And to understand who’s calling who, who’s influencing who, and getting a real view, you know, a uber view of what that looks like is super important. [00:07:47] Jay McBain: It is. And you know, if I’m trying to sell like a cross beam or partner tab or work span or something into my executive team, I’m just showing them this slide. [00:07:54] Vince Menzione: Exactly. [00:07:54] Jay McBain: Would you like to know about this deal? Like you see, October is the start of the timeline here. Would you like to know about this deal in August, September? [00:08:00] Vince Menzione: Yep. [00:08:01] Jay McBain: Would you like to know about it automatically? Again, we’re not waiting for somebody, a human in a cubicle to go fill out a form. We’re not waiting for them to call somebody at our in, in a cubicle at our company. Yeah. We’re literally age genically sharing platforms, and so when this triggers that AstraZeneca and now triggers in our CRM system as well, our team on AstraZeneca gets notified and it gets notified in September before the 28 moments even starts. [00:08:27] Jay McBain: This, the power of this, of doubling, tripling your pipeline and then winning a bigger yield, a bigger percentage of that pipeline. This is the holy grail of our industry, and no one’s gonna get to a hundred percent. You’re not gonna have a hundred percent of your tam covered by your pipeline. No one’s gonna win a hundred percent of that. [00:08:43] Jay McBain: But again, we only have to be 10 or 20% better than our competitors and we need to start moving on this now. [00:08:50] Vince Menzione: So your imperative for the partners here, well everyone watching here today, I mean, this screams to me build your ecosystem strategy in such a strong and succinct way. What else would you say to them? [00:09:00] Jay McBain: I mean, the second thing that jumps out, you see two AWS direct touches here. This is something that this would be inbound. This AWS would see this deal in their pipeline. [00:09:09] Vince Menzione: Yeah. [00:09:10] Jay McBain: Because the customer came to them. AWS lost this deal. Crazy. So Microsoft won this deal. I, I mentioned Microsoft outgrowing AWS Yeah. [00:09:19] Jay McBain: ’cause in this particular case, NTT and Software One and Yash came in with Microsoft. Yeah. To solve an SAP optimization, Microsoft, and, you know, seven layer deal. So whether you’re in AWS, whether you’re in Microsoft, whether you’re anywhere else in this industry, you’re thinking like, you’re not gonna probably overtake what happens in December. [00:09:39] Jay McBain: These are the most trusted, smartest people in the room. And whatever happens in those projects is the seven layer stack the customer’s gonna buy in March, April. So I, I start to think about this and go, I need to win. ’cause NTT has a wonderful relationship with AWS. [00:09:55] Vince Menzione: They do, [00:09:56] Jay McBain: I mean, partner of the year level. [00:09:57] Jay McBain: I mean, they’ve got 10,000 people certified. I mean, there’s just a, you know, there’s no one at AWS that, um, you know, would take a, a loss here because it’s a wonderful relationship. And Software One, they [00:10:09] Vince Menzione: go back to Microsoft actually 30, 40 years though they do. They were Dimension data before that. Yeah. [00:10:14] Vince Menzione: And they have the long hit Legacy And Software One. Software one as well. You, [00:10:19] Jay McBain: you know, well Software one is Microsoft’s biggest reseller, uh, in Europe. And now with Crayon, you know, one of the biggest in the world. So I would be nervous if I was looking at this and saw Software one coming in with NTT and watching these things take place if I were able to see this back in September, October and work with these companies. [00:10:38] Jay McBain: That’s where kind of Microsoft came into the picture. And this never hit Microsoft’s pipeline. No Microsoft salesperson ever worked on it, but millions of dollars came to Microsoft. Yeah. Uh, out of this deal. So there are examples of where Microsoft gets touched and AWS wins the deal. So this isn’t meant to say that it happens in every case, but it’s meant to say data rules the future, and agent ai, the ability to plumb in these boxes. [00:11:00] Jay McBain: Working with Informa tech, target people that can plumb in the boxes for you with third party data, helping you with the light blue boxes. We gotta be obsessed over these light blue boxes. [00:11:11] Vince Menzione: It’s incredible. The Ultimate Partner Winter Retreat is gonna be here in the Boca Studio. This is the third year that we’re gonna be here in Boca. [00:11:21] Vince Menzione: This is always a favorite of our community members, our executive members, our sponsors and speakers. We’ll all be here in the studio, which is a really intimate setting. We can see upwards of 40, 50 people. Uh, we’ll be hosting an incredible dinner at the Boca Resort overlooking the golf course. That’s an incredible property and, uh, we’d love to have you join us. [00:11:45] Vince Menzione: Thank you for being part of the ultimate Partner community, and I hope to see you this year at one of our events. Thank you.

One Heat Minute
THE DECADE PROJECT: BLACKHAT (2015) w/Brandon Streussnig

One Heat Minute

Play Episode Listen Later Feb 3, 2026 59:06


The Decade Project is an ongoing One Heat Minute Productions Patreon exclusive podcast looking back at the films released ten years ago to reflect on what continues to resonate and what's ripe for rediscovery. The third year being released on the main podcast feed is the films of 2015. To hear a fantastic chorus of guests and I unpack the films of 2016 in 2026, subscribe to our Patreon here for as little as $1 a month. In the latest episode, the beautiful film mind and MIAMI VICE champion Brandon Streussnig, and I discuss the initially misunderstood and now frothily reclaimed BLACKHAT. Viva la SOY BOYZ.Brandon StreussnigBylines with Vulture, Fangoria, GQ UK, Inverse, Polygon, The Playlist, Secret Handshake Cinema, Film Combat SyndicateLinks: Twitter, ClippingsOne Heat Minute ProductionsWEBSITE: oneheatminute.comTWITTER: @OneBlakeMinute & @OHMPodsMERCH: https://www.teepublic.com/en-au/stores/one-heat-minute-productionsSupport this podcast at — https://redcircle.com/one-heat-minute-productions/exclusive-contentAdvertising Inquiries: https://redcircle.com/brandsPrivacy & Opt-Out: https://redcircle.com/privacy