Podcasts about SolarWinds

  • 1,130PODCASTS
  • 2,906EPISODES
  • 43mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Jul 27, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about SolarWinds

Show all podcasts related to solarwinds

Latest podcast episodes about SolarWinds

The CyberWire
The world's least private hackers.

The CyberWire

Play Episode Listen Later Jul 27, 2026 27:24


Hackers target Thailand's Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

The Cyber Threat Perspective
Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

The Cyber Threat Perspective

Play Episode Listen Later Jul 24, 2026 27:41


Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you.Brad and Jordan cover both sides of supply chain risk: the trusted third-party applications you deploy (SolarWinds being the case that put this category on the map) and the open-source components you pull into your own code without always knowing what's inside. They explain why AI and vibe coding are accelerating the problem, why jQuery is the modern-day Flash, and why "just upgrade the package" is rarely that simple.From there it gets practical:What a Software Bill of Materials (SBOM) is and why you need oneTransitive dependencies — the packages hiding beneath your packagesBuilding security checks into your CI/CD pipeline and shifting leftWhy a flaw caught in static analysis can cost ~$200, while the same flaw found in a pen test can cost $20,000+Why a pen test should validate your controls, not be your first line of defenseHow SecurIT360's Project Lantern and ChainGarde automate SBOM analysis against known and actively-exploited vulnerabilitiesA playbook for vetting vendors, writing accountability into contracts, and holding third parties responsible for actually fixing findingsThe takeaway: whether you're writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have.Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaYPart 2 — Security Misconfigurations: https://youtu.be/Po8H140BijENeed a web app pen test? SecurIT360 | Cybersecurity From Every Angle More content: https://offsec.blogBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

The CyberWire
The AI has entered the chat.

The CyberWire

Play Episode Listen Later Jul 22, 2026 29:52


GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can't resist bending the rules. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Jimmy McNary, Deputy Federal CTO at Semperis, discussing how Purple Knight now delivers comprehensive identity security assessments for Microsoft GCC high environment. Selected Reading OpenAI Claims Its AI Models Went Rogue and Hacked Another Company (Infosecurity Magazine) SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root (GB Hackers) CISA orders urgent action on actively exploited Langflow RCE flaw (Bleeping Computer) Paidwork breach exposes data of 23 million users: Check if you're affected (Malwarebytes) Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks (SecurityWeek) Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates (SecurityWeek) Chairman Carr Proposes to Expand Direct-to-Device Satellite Broadband Connectivity to Unlicensed Wireless Devices (FCC) LG to Ban Residential Proxies from Smart TV Apps (Krebs on Security) Police dismantle Kratos phishing platform, arrest developer (Bleeping Computer) AI's cheatin' heart will make you weep (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 22, 2026 5:30


Captive Portal Detection https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172 Critical SolarWinds Serv-U Update https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm Zimbra Update with Critical Security Fixes https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/ Apple Fixed Hide My E-Mail Leak https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Navigating the Customer Experience
276 : Pricing AI: Why the First Price Is Always Wrong and What Smart SaaS Leaders Do About It with Dan Balcauski

Navigating the Customer Experience

Play Episode Listen Later Jul 14, 2026 22:28 Transcription Available


Send us Fan MailPricing AI is the hardest pricing problem in software right now, and most SaaS leaders are getting it wrong on the first try. In this episode of Navigating the Customer Experience, host Yanique Grant sits down with Dan Balcauski, founder of Product Tranquility, to unpack why the first AI price a company sets is always wrong, how to set usage caps when you have no historical data, and what smart B2B SaaS leaders do differently to turn pricing from a liability into a strategic advantage.Dan has spent more than 20 years in software, starting as an engineer before moving into product management and discovering that how a company captures value matters far more than how it builds the product. Today he advises B2B SaaS CEOs on the AI pricing and packaging decisions that keep them up at night, and in this conversation he shares the frameworks, the mistakes to avoid, and the practical playbook he uses with real companies.WHAT YOU WILL LEARN IN THIS EPISODEWhy the first AI price is always wrong, and why that has nothing to do with how smart your team or your consultants are. Dan explains the fundamental economic shift underway in software, where both sides of the pricing equation are moving at once. On the cost side, he points to a benchmark showing the cost per task for a top model dropping by roughly 390 times in a single year, a change no normal business ever absorbs in its cost of goods sold. On the value side, models keep getting more capable, handling this month what they could not handle last month. His research shows that every application layer software company he studied that released AI capabilities revised its pricing and packaging within 18 months. The lesson is not to price perfectly on day one. It is to build for change.How to set usage caps and pricing tiers with zero historical data. Dan frames the real problem plainly. You know what a token costs, but you have no idea what customers will actually do with a new AI feature. Products are full of features that barely got adopted, and AI features do not get to skip that step of the innovation cycle. On top of that, a small group of power users, often around 5 to 10 percent, can drive the overwhelming majority of usage and cost. That makes the tempting shortcuts unreliable. Using dashboard views as a proxy breaks down because good AI gets used far more than the dashboards it replaces, and a beta group rarely matches the usage profile of the full market.The early access playbook that sits between beta and general availability. Dan recommends a stage where companies announce their limits, put a price on the feature, and communicate it clearly, but do not enforce or meter it yet for a defined window that can run anywhere from six weeks to 18 months. This eases customer anxiety about surprise bills, encourages real adoption, and lets the company gather genuine usage patterns instead of guessing from proxies that break down.Why you should separate ordinary plan limits from fair use limits. Even when you are not metering usage, Dan explains, you can reserve the right to throttle or downgrade the rare customer using a capability a hundred or a thousand times more than the average, much like companies already do with API request limits. Those levers let teams keep experimenting during early access without the finance team panicking when the bill arrives.Why communication is where pricing changes succeed or fail. As Dan puts it, most pricing blowups come not from the change itself but from the fact that it was communicated poorly or not at all. Agility beats certainty, and reviewing pricing on a quarterly cadence beats the old annual or five year rhythm.This episode is essential listening for SaaS founders, product leaders, pricing strategists, and customer experience professionals who want to understand how AI is reshaping the economics of software and what to do about it before the market forces the decision for them.ABOUT DAN BALCAUSKIDan Balcauski is the founder of Product Tranquility, where he helps B2B SaaS CEOs turn pricing from a confusing liability into a strategic advantage. With more than 20 years in software, Dan began his career as an engineer before moving into product management and discovering that how companies capture value matters far more than how they build it. His work now centers on one of the most pressing questions in software today: how to price AI. Before founding Product Tranquility, Dan was a principal product strategist at SolarWinds and head of product at LawnStarter. He holds a BSc in computer engineering from Iowa State University and an MBA from the Kellogg School of Management at Northwestern, where he also helps teach executive education courses on product strategy. He is the host of the SaaS Scaling Secrets podcast.QUESTIONS YANIQUE ASKEDCould you share a little about your journey and how you got from where you were to where you are today? You have said the first AI price is always wrong. Why is that, and what should a SaaS company do differently knowing they are going to get it wrong the first time? So many companies are trying to set usage caps and pricing tiers for AI with zero historical data. How would you advise a CEO to make that decision when they are essentially flying blind? What is the one online resource, tool, website, or application that you absolutely cannot live without in your business? Can you share one or two books that have had a positive impact on you, professionally or personally? What is one thing going on in your life right now that you are really excited about? Do you have a quote or saying that keeps you on track during times of adversity? Where can listeners find and connect with you online?KEY TAKEAWAYSThe first AI price is always wrong, and that is not a failure of intelligence. It reflects a fundamental economic shift where both cost and value are moving fast. Every application layer company Dan studied revised its AI pricing and packaging within 18 months. Plan for revision, not perfection. Agility beats certainty. Review pricing on a quarterly cadence rather than annually or every five years. Communication is where pricing changes succeed or fail. Most blowups come from poor communication, not the change itself. Usage proxies break down. Dashboard views and beta groups rarely predict how customers will actually use an AI feature. A small group of power users can drive the majority of usage and cost, so average user assumptions are dangerous. Early access is the smart middle stage. Announce and price the limits, communicate them, but do not meter yet while you gather real data. Separate plan limits from fair use limits. Reserve the right to throttle extreme usage even when you are not metering everyone. Do not borrow problems from the future. Anxiety about what has not happened yet only adds problems to the present. AI is making custom, personal business software economically viable for the first time, opening the door to tools built exactly the way you work.CHAPTERS 00:00 Introduction and Guest Bio 01:51 Dan's Journey: From Engineer to Pricing Strategist 04:03 Learning That Pricing Is Different in Every Industry 04:49 Why the First AI Price Is Always Wrong 05:36 The 390x Cost Shift and the Moving Value Equation 06:49 Agility, Faster Pricing Reviews, and Communication 09:28 Setting Usage Caps With No Historical Data 11:32 Why Dashboard Proxies and Beta Groups Break Down 12:59 The Early Access Playbook Between Beta and GA 13:20 Plan Limits vs. Fair Use Limits 17:04 The One Tool Dan Cannot Live Without: Claude Code 17:38 Book Recommendation: Monetizing Innovation 18:31 Building Custom Business Software With AI 19:55 How to Connect With Dan Online 20:27 Dan's Guiding Quote: Don't Borrow Problems From the FutureFEATURED RESOURCESBook mentioned: Monetizing Innovation by Madhavan Ramanujam and Georg TackeTool mentioned: Claude Code, Dan's work surface and the engine behind his custom business softwareCONNECT WITH DANLinkedIn: Search Dan Balcauski on LinkedIn, and mention that you heard him on the podcast so he can separate you from the spamWebsite: producttranquility.comPodcast: SaaS Scaling Secrets, wherever podcasts are foundDAN'S GUIDING QUOTE"Don't borrow problems from the future." Dan BalcauskiDan explains that most of our anxiety is about things that have not happened yet. Worrying about a future scenario pulls that problem into the present before it ever arrives, giving you more to carry now for no reason. Like debt, it is borrowing against your future self. His practice is to stay focused on what is real and in front of him, which keeps him grounded when challenges or uncertainty threaten to pull him off track.ABOUT N

The Meditation Conversation Podcast
603. ZaZar Reveals: Why 3D Structures Are Collapsing & What Replaces Them - Marilyn Gewacke

The Meditation Conversation Podcast

Play Episode Listen Later Jun 25, 2026 80:24


ZaZar on Humanity's Ascension: Unified Consciousness, Light Spiral Downloads & DNA Activation with Marilyn Gewacke Kara Goodwin was thrilled to welcome back clinical psychologist and channel Marilyn Gewacke, who shares teachings from ZaZar about accelerating "winds of change" linked to solar/galactic energies that both dismantle unstable 3D structures and fuel manifestation and ascension. They discuss growing readiness for awakening, disclosure narratives and fear, and the importance of building a coherent unified field of heart-based consciousness through retreats, meditation, and kindness.  ZaZar explains a unique nighttime experience Kara had as a visitation involving "light spiral downloads," increased receptivity corridors within her consciousness, and multidimensional contact, emphasizing free will and conscious awareness of vibrational experience.  He describes the unified field rapidly strengthening toward access to "zero point" energy, light codes, and DNA shifts that support healing, longevity, and integration of light and physical bodies, aided by "cosmic humans." Marilyn shares upcoming retreats and online "Epic News" and Q&A events. Tune into the first episode with Marilyn and ZaZar: https://www.soulelevationpodcast.com/zazar-marilyn-gewacke Explore Marilyn and ZaZar's upcoming events: https://www.theshift.rocks  Subscribe for more great episodes of Soul Elevation: https://www.soulelevationpodcast.com/follow 

CISSP Cyber Training Podcast - CISSP Training Program
CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jun 15, 2026 32:09 Transcription Available


Send us Fan MailSomeone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryption that protects it. I dig into the “Harvest Now, Decrypt Later” strategy, why it matters most for long-term confidentiality, and how security leaders can talk about it as a present-day risk instead of science fiction.From there, I get practical with post-quantum planning: what the NIST post-quantum cryptography standards signal, why quantum key distribution is still niche for most organisations, and the big architectural idea to remember for the CISSP and for real enterprise security programs: crypto agility. We walk through concrete steps like building a cryptographic inventory, mapping where RSA and elliptic curve crypto live, identifying data with 10 to 20 year secrecy needs, and pushing vendors for a clear PQC roadmap.Then we pivot into CISSP Domain 1 supply chain risk management (SCRM and CSCRM). I explain why supply chains are a prime target, how modern supply chain attacks can ride in through poisoned open source packages, and what SolarWinds showed the world about scale and impact. We close with the nuts and bolts that actually reduce third-party risk: lifecycle supplier management, meaningful assessments (on-site when it matters), document and policy review, audits, and minimum security requirements baked into contracts and SLAs.If you want more training, check out CISSP Cyber Training, subscribe for weekly updates, share this with a friend who owns risk, and leave a quick review so more CISSP candidates can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Paul's Security Weekly
Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland... - SWN #588

Paul's Security Weekly

Play Episode Listen Later Jun 9, 2026 28:18


Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-588

Paul's Security Weekly TV
Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland... - SWN #588

Paul's Security Weekly TV

Play Episode Listen Later Jun 9, 2026 28:18


Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland, and More on the Security Weekly News. Show Notes: https://securityweekly.com/swn-588

Hack Naked News (Audio)
Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland... - SWN #588

Hack Naked News (Audio)

Play Episode Listen Later Jun 9, 2026 28:18


Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-588

Hack Naked News (Video)
Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland... - SWN #588

Hack Naked News (Video)

Play Episode Listen Later Jun 9, 2026 28:18


Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland, and More on the Security Weekly News. Show Notes: https://securityweekly.com/swn-588

Identity At The Center
#427 - Identiverse 2026 Preview with Heather Flanagan and Andi Hindle

Identity At The Center

Play Episode Listen Later Jun 8, 2026 73:49


Jeff and Jim are joined by Heather Flanagan, Content Chair, and Andi Hindle, Conference Chair, for a full preview of Identiverse 2026 at Mandalay Bay in Las Vegas. They cover the 2026 theme of trust and change, why AI was removed as a standalone track and redistributed across all content areas, the provocative argument that non-human access now dramatically outpaces human access and is reshaping identity system design, whether authentication is truly solved, authorization as the harder unsolved problem, CFP surprises, networking events including Women at Identiverse, and predictions for 2027. Save 30% with code IDV26-IDAC30%. New IDPro members save $25 at idpro.org/idac.Connect with Heather: https://www.linkedin.com/in/hlflanagan/Connect with Andi: https://www.linkedin.com/in/ahindle/Identiverse 2026: https://events.identiverse.com/2026/begin?code=IDV26-IDAC30%25Heather's IAM Conference List: https://github.com/fedidcg/meetings/wiki/2026-List-of-Identity-and-Related-Conferences-and-Standards-Development-EventsConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTIMESTAMPS00:00:00 Introduction and SolarWinds breach banter00:03:27 Identiverse preview and discount codes00:06:10 Guest introductions00:06:52 Role of Content Chair00:08:46 Role of Conference Chair00:11:16 2026 conference theme00:15:00 AI as context, not a standalone track00:16:32 Control plane vs enablement plane debate00:22:19 What the industry is underestimating00:24:00 Non-human access outpaces human access00:26:52 Is authentication solved? Passkeys00:30:31 Authorization: far from solved00:36:04 Extensibility in standards and deployments00:38:22 CFP surprises: fraud and identity proofing00:41:48 Usability and UX gaps00:43:18 Agentic AI: identity or governance?00:47:55 Networking and newcomer programming00:51:45 Women at Identiverse00:52:46 AI-generated CFP submissions00:55:00 Predictions for Identiverse 202700:58:04 Theme songs for Identiverse 202601:02:58 Heather's identity conference list on GitHub01:04:47 Swag culture at identity conferences01:12:25 Wrap-upKEYWORDSIdentiverse 2026, Heather Flanagan, Andi Hindle, identity conference, NHI, non-human identity, agentic AI, passkeys, authentication, authorization, IAM, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, digital identity, continuous identity architecture, zero standing privilege, verifiable credentials, identity governance

Cyber Security Headlines
CISA Palantir Director, EU tech sovereignty, SolarWinds Serv-U flaw

Cyber Security Headlines

Play Episode Listen Later Jun 8, 2026 8:14


Palantir executive considered for CISA leadership EU unveils tech sovereignty package to cut reliance on U.S., Chinese suppliers Hackers now exploit SolarWinds Serv-U flaw to crash servers  Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-palantir-director-eu-tech-sovereignty-solarwinds-serv-u-flaw/ Thanks to our episode sponsor, Doppel Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call.   But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception.   We fight relentlessly to protect your business, brand, and people.   Doppel. Outpacing what's next in social engineering.   Learn more at doppel.com.

Sales Game Changers | Tip-Filled  Conversations with Sales Leaders About Their Successful Careers
Channel Leader Barb Huelskamp's Trip to Italy Taught Her These Five Leadership Lessons

Sales Game Changers | Tip-Filled Conversations with Sales Leaders About Their Successful Careers

Play Episode Listen Later Jun 4, 2026 29:41


This is episode 847. Read the complete transcription on the Sales Game Changers Podcast website. Watch the video of this podcast on YouTube here. The Sales Game Changers Podcast was recognized by YesWare as the top sales podcast. Read the announcement here. FeedSpot named the Sales Game Changers Podcast at a top 20 Sales Podcast and top 8 Sales Leadership Podcast! Subscribe to the Sales Game Changers Podcast now on Apple Podcasts! Purchase Fred Diamond's best-sellers Love, Hope, Lyme: What Family Members, Partners, and Friends Who Love a Chronic Lyme Survivor Need to Know and Insights for Sales Game Changers now! Today's show featured an interview with Barb Huelskamp, Global Vice President of Channels and Alliances at SolarWinds. Find Barb on LinkedIn.  BARB'S TIP: "Stomp out imposter syndrome. Stomp out fear. I took some fearless leaps early on that I think at this point in my career I would be a little scared to, but I did, and they paid off."

The Daily Scoop Podcast
OMB update federal cyber logging tactics

The Daily Scoop Podcast

Play Episode Listen Later May 27, 2026 7:29


Federal agencies will shift to a priority and risk-based method of logging cybersecurity events under a Friday memo from the Office of Management and Budget aimed at cutting “red tape” and costs. The memo from OMB Director Russell Vought rescinds and replaces a previous directive from the Biden administration issued after the 2020 SolarWinds breach that affected both the public and private sectors. While the previous policy “improved foundational capabilities across agencies,” OMB said the amount of data agencies were required to retain was costly and operationally difficult. In its place, the Trump directive outlines “a risk-based, prioritized logging approach” to logging. OMB's policy comes amid concern about the use of artificial intelligence and automation to fuel cyberattacks. That technology can speed up the process of gaining access to a system and help covertly maintain that access for a long time. It's also increasingly being used by threat actors, the memo said. Anthropic's Mythos large language model is the talk of federal tech and cyber practitioners across the Beltway, and for good reason. According to the company, its month-old Project Glasswing initiative, which allows select researchers to get their hands on the Mythos model, has uncovered more than 10,000 high- or critical-severity software vulnerabilities across systemically important code, a finding that Anthropic says has shifted the central problem in cybersecurity from discovering flaws to verifying and patching them. The findings, drawn from partner reports and independent evaluations, mark one of the first large-scale accountings of what a frontier AI model can do when pointed at widely used code, and of the bottlenecks that emerge once it does. Several partners reported that their rates of bug discovery had increased more than tenfold. The Daily Scoop Podcast is available every Monday-Friday afternoon. If you want to hear more of the latest from Washington, subscribe to The Daily Scoop Podcast  on Apple Podcasts, Soundcloud, Spotify and YouTube.

The Segment: A Zero Trust Leadership Podcast
Cybersecurity Has Hit a Brick Wall — Andrew Rubin on What Comes Next

The Segment: A Zero Trust Leadership Podcast

Play Episode Listen Later May 20, 2026 48:23


In this episode, Raghu Nandakumara sits down with Andrew Rubin, Founder & CEO of Illumio, for a candid conversation about the next phase of AI-driven cybersecurity risk. Just weeks after a major AI breakthrough sparked shockwaves across the security industry, Andrew shares his immediate reaction — from the sobering implications of machine-speed vulnerability discovery to a frank assessment of why the cybersecurity industry's fundamental model may already be broken. The conversation explores what actually changes in an era where vulnerabilities could be discovered and exploited faster than any human-driven operation could manage. Andrew argues that while segmentation as a concept is decades old, its role as a critical backstop has never been more urgent. If attackers begin operating at machine speed, defenders must rethink not just their tools, but their entire operating model — from how they assess risk to how quickly they can respond. Raghu and Andrew discuss: Why the cybersecurity industry has spent more every year while outcomes have gotten worse How AI creates an asymmetric threat unlike anything defenders have faced before Why patching alone won't solve the problem — and the COVID vaccine analogy that explains why The shift from prevention to resilience as the new security north star What the SolarWinds story reveals about how organizations miscalculate tail risk Why segmentation becomes one of the few reliable backstops in a model-driven world How the era of 12-month RFPs and POCs may be coming to a swift and necessary end Stay Connected with our host, Raghu on LinkedIn: https://www.linkedin.com/in/raghunandakumara/ For more information about Illumio, check out our website at illumio.com    Resources Mentioned: Hard Truths in Cybersecurity: Fear, Liability, and the Industry's Biggest Lies | RSAC 2026 Panel:  https://www.youtube.com/watch?v=88XjfZBYIw0

The CyberWire
CyberWire Daily at 10: The evolution of geopolitics and warfare. [Special Edition]

The CyberWire

Play Episode Listen Later May 10, 2026 27:58


In this special edition of CyberWire Daily's 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss cybersecurity geopolitics and warfare that have been in the news over the past 10 years. We begin our conversation around the supply chain malware from the destructive NotPetya campaign out of Russia, then Maria and Dave highlight: Olympic Destroyer disrupting the Pyeongchang Games, CozyBear's SolarWinds espionage campaign, the Colonial Pipeline ransomware disruption, Russia's full invasion of Ukraine paired with Viasat hack, Iranian hackers attacking ICS devices at water treatment plants in Israel, and China's VoltTyphoon and SaltTyphoon intrusions in critical sectors. Join us as we reflect on the escalation from election interference and disruption, to espionage and ransomware as national security crises, to integration in kinetic war,and now expansion into space, with AI-driven defenses and NATO codifying cyber as a collective defense domain. Learn more about your ad choices. Visit megaphone.fm/adchoices

The POZCAST: Career & Life Journeys with Adam Posner
David Hanrahan: Global Benefits, Local Needs: SolarWinds' CPO on Managing People Across 6 Countries (LIVE @ Transform 2026)

The POZCAST: Career & Life Journeys with Adam Posner

Play Episode Listen Later May 6, 2026 17:13


These episodes of #thePOZcast, live from Transform 2026 in Las Vegas, are proudly brought to you by our friends at Overalls What if your employees had one central hub to handle real life? Meet Overalls. A smarter way to support your team, combining expert human LifeConcierges™ with AI to solve everyday challenges across healthcare, caregiving, benefits, insurance, finances, life admin, and more. From start to finish, Overalls handles the details — using existing benefits where they fit, and filling in the gaps where they don't. So employees save time, reduce stress, and stay focused at work, while employers boost engagement and get more value from their benefits. Overalls is redefining how work supports life, helping employee teams from Reddit, Patreon, BeatBox, and more cross pesky to-dos off their lists every day. Learn more at https://getoveralls.com/?utm_source=podcast&utm_medium=podcast&utm_campaign=pozcast Thanks for listening, and please follow us on Insta @NHPTalent and www.youtube.com/thePOZcast For all episodes, please check out www.thePOZcast.com TAKEAWAYS: 1. Global Benefits Require Local Listening There is no universal benefits playbook. What matters to an employee in Bangalore — where the daily commute can be a two-hour ordeal — is fundamentally different from what matters to someone in Austin or Cork. Companies with global teams need to engage local employees to understand what's actually meaningful, rather than exporting the US benefits model everywhere. 2. Transportation Is an Underrated Global Benefit In cities like Bangalore and Manila, commuter benefits can have a more meaningful daily impact than gym memberships or wellness stipends. Dave's team is actively exploring cab subsidies and transportation allowances as targeted benefits for teams in markets where commuting is genuinely burdensome. 3. Mental Health Benefits Only Work If Confidentiality Is Real and Communicated On-demand therapy platforms drive adoption when employees genuinely believe their sessions are private. People leaders need to actively and repeatedly communicate that they have zero access to individual usage data — because the fear that HR is watching is a real barrier to utilization, even for platforms that are genuinely confidential. 4. Aggregate Mental Health Data Is a Strategic Signal Even without individual visibility, the top themes surfaced by a mental health platform — stress, burnout, anxiety — give people leaders actionable intelligence about where the organization needs to go deeper. That's qualitative data that should be feeding benefits strategy and manager training. 5. What Candidates Care About Depends on Where They Are in Life Junior employees ask about food and gym benefits. Senior employees want to know about 401(k) match and parental leave. But across every level and every geography, candidates are asking to see the benefits package — and those conversations are happening on par with base salary discussions. 6. Elder Care Is the Next Major Benefits Frontier — and It's Personal for Dave Dave went through the elder care journey for both parents with nothing from his employer to help navigate it. That experience led him to advise an elder care platform and made him one of the most vocal advocates for this benefit category. His message: companies that don't build something here in the next few years will lose the sandwich generation employees who need it most. 7. The Elderly Population Is About to Eclipse the Child Population in the US The demographic shift is imminent. The sandwich generation — employees simultaneously raising children and caring for aging parents — is about to become the dominant workforce cohort. People leaders who are not designing benefits for this reality are already behind. 8. Concierge Benefits Address the Real Cost of Being Away The most relatable benefit Dave wishes he had: someone to handle real-life logistics when you're traveling for work. A fallen tree, a lawn that needs cutting, a home emergency — the mental load of worrying about what's happening at home while you're on the road is a real productivity drain that concierge services can address. 9. HR Needs a Purposeful AI Design — Not a Default One Dave's key insight from Transform 2026: the most important AI conversation in HR isn't about what AI can do — it's about what you want it to do. Mapping capabilities and making deliberate decisions about where AI takes over and where human judgment is protected is the strategic work that separates thoughtful people organizations from reactive ones. CHAPTERS: 00:00 – Introduction Adam welcomes Dave Hanrahan from SolarWinds, fresh off a panel session, and sets up a conversation about global people leadership and benefits. 02:00 – Meet SolarWinds & Dave's Role Dave describes SolarWinds — a B2B IT observability platform — and his role as SVP of People, including joining two weeks before an acquisition and managing a team spanning six countries. 04:30 – Managing a Global Workforce Up Close Why Dave prioritizes getting out to international offices in person, and what you can only understand about site culture when you're actually there. 07:00 – How Benefits Work Around the World A rarely discussed topic: how benefits are structured differently by country, why one-size-fits-all doesn't work globally, and what SolarWinds is learning about meeting employees where they are in each market. 10:00 – Transportation Benefits in Bangalore & Manila The standout benefit conversation: why commuter subsidies matter more than gym memberships for teams in some of the world's most congested cities — and how SolarWinds is working with local teams to figure out the right solution. 13:00 – Mental Health Benefits & the Confidentiality Challenge How SolarWinds approaches global on-demand therapy benefits, why anonymity is the key to adoption, and what aggregate data from the platform tells Dave as a people leader about workforce stress trends. 16:30 – How Benefits Are Priced & Structured A practical breakdown: per-employee session allotments, how utilization is tracked, when the company raises session limits, and how group sessions expand access across the organization. 19:00 – What Candidates Actually Ask About in Total Comp Dave's generational breakdown: junior employees ask about food and gym benefits; senior employees go straight to 401(k) match and parental leave. And across the board, every candidate asks to see the benefits flyer. 22:00 – The Elder Care Gap — Dave's Personal Story Dave's most personal moment in the episode: going through elder care for both parents with zero company support, becoming an advisor to an elder care benefits platform, and why he believes this is the next major benefits frontier. 26:00 – The Sandwich Generation Is Here The data point that stops the conversation: the US elderly population is about to eclipse the child population. Dave and Adam get real about what that means for employees caught in the middle — raising kids while caring for aging parents. 29:30 – Concierge Benefits & the Value of Peace of Mind What Dave wishes he had as an employee traveling for work: concierge services that handle real-life logistics — the lawn, the fallen tree, the home emergency — so employees can focus on the job. 32:00 – Mapping AI to HR: What to Automate, What to Protect Dave's aha moment from Transform 2026: the importance of purposefully mapping which HR functions should become agentic versus where human judgment — on hiring, promotions, compensation, feedback — must be retained. 35:00 – Keeping the Human at the Center Dave's words of optimism: at this conference, HR leaders are pushing back on the narrative that AI should replace human judgment. The energy at Transform is about keeping people at the heart of the most important decisions.

The Tech Trek
How AI Is Changing the Way Engineering Teams Work

The Tech Trek

Play Episode Listen Later May 6, 2026 29:13


Krishna Sai, CTO at SolarWinds, joins The Tech Trek to talk about one of the biggest shifts happening inside IT and engineering teams: AI is moving people from operators to orchestrators.The conversation goes beyond faster code and automation. Krishna explains why AI is changing how teams think about systems, governance, validation, observability, and the skills technical leaders will need as work moves from manual execution to higher level oversight.Key Takeaways• AI is raising the level of abstraction for IT and engineering teams. The work is shifting from operating systems manually to designing systems that can increasingly run, adapt, and respond on their own.• AI does not automatically reduce workload. In many teams, it changes the type of work by moving effort from execution into validation, judgment, risk management, and governance.• Code generation is only one part of the delivery system. Without testing, security review, observability, and strong engineering process, faster code can create more problems faster.• The best AI outcomes depend on strong foundations. Clean data, connected systems, clear ownership, and resilient architecture matter more as AI becomes part of core workflows.• Technical professionals will need stronger systems thinking, business context, adaptability, and domain understanding as AI changes the shape of day to day work.Timestamped Highlights00:00Krishna Sai joins the show and sets the stage for a conversation about AI, IT responsibility, skill gaps, and the latest SolarWinds IT Trends Report.02:14Why IT is moving from operator to orchestrator, and what that means for teams that used to spend most of their time responding to tickets and manually managing systems.04:54Krishna explains why AI feels different from prior technology shifts. This is not just infrastructure change. It touches individual workflows, jobs, and decision making.08:56The messy middle of AI adoption. Teams are getting faster at some tasks, but the workload has not disappeared. It has moved into validation, review, and oversight.14:46How AI may force teams to rethink the software delivery cycle, sprint structure, feedback loops, and the speed at which customer issues can be resolved24:27Krishna shares how principles from distributed systems, including loose coupling and high cohesion, can help leaders build AI systems that can change without breaking everything around them.Standout Moment“AI is a multiplier. It does not magically fix all your problems. It multiplies your current state.”Pro Tips• Do not measure AI success only by how much faster a team can generate code or complete a task.• Look at the full system around the work, including testing, review, security, observability, and ownership.• Build AI workflows with enough flexibility to swap tools, models, and processes as the technology changes.• Invest in systems thinking and domain knowledge. Those skills become more valuable as execution becomes easier to automate.Call to ActionSubscribe to The Tech Trek for more conversations with technology leaders on how AI, data, engineering, and modern systems are changing the way companies build.

Business of Tech
When Agents Can Buy and Provision: The Shift from Automation to Enforced Governance

Business of Tech

Play Episode Listen Later May 5, 2026 13:28


The dominant structural shift identified is the emergence of agentic AI as a direct operator within multi-system business environments, triggering a governance and accountability gap. Vendors and cloud platforms—including AWS, Stripe, and Cloudflare—are enabling AI agents not only to recommend actions but also to directly access payment rails, provision infrastructure, and execute transactions. This movement turns automation into an operating model issue rather than a feature deployment, as the identity, authority, and accountability of non-human actors become central operational questions. Primary evidence is drawn from a range of industry signals. According to an AMD-commissioned IDC report, 81% of enterprises are engaged in AI PC adoption and 61% are embedding AI into workflows. AWS has expanded managed agent packaging for AI deployments, Stripe has launched the Link wallet allowing AI agents to process payments on users' behalf with controls on payment credentials, and Cloudflare has demonstrated agents autonomously provisioning cloud resources with enforced monthly spend limits. While these statistics carry vendor-driven optimism, the combined actions of these companies confirm a shift from advisory AI to operational AI. Related developments reinforce this trajectory. The SolarWinds survey reported by Computer Weekly finds 71% of IT workers experiencing higher demands due to AI, with only 19% noting reduced cognitive load, reflecting operational burdens rather than efficiencies. Similarly, Forrester data cited by The Register highlights a change in CIO responsibilities from system building to outcome governance as agentic AI exposes gaps in decision rights and process completeness. Security risks are elevated, as the Kela report counts 2.86 billion stolen credentials in a year, indicating that agent-driven credentials can trigger machine-speed purchases and changes, compounding the challenge of oversight and recovery. Operational implications for MSPs are significant. Without explicit governance, spend limits, approval paths, and audit trails, MSPs face increased liability and support burden when AI agents initiate actions across client systems. The episode underscores that automation is not just a technical project but a contract and service design issue; if accountability is not clearly defined, MSPs bear the risk and cost of unauthorized transactions and exception handling. To mitigate exposure, there is a need to formalize agent governance as a priced, intentional service encompassing identity management, financial controls, and documented operational guardrails before agentic AI is deployed in client environments. 00:00 Agents Take Over 04:39 Who's Accountable? 06:48 Who Owns This? 09:58 Why Do We Care?    Supported by:  NerdioScalePad    Upcoming event:  The Pivotal Point of IT: Building Services for the AI-First Era Date: May 13 at 1p.m. EDT Register: https://go.acronis.com/davesobelaiera

We Talk Cyber
How a CISO Survived The SEC Lawsuit, Nation-State Cyber Attack and SolarWinds Breach | ft. Tim Brown

We Talk Cyber

Play Episode Listen Later Apr 28, 2026 101:13


The SEC charged a CISO personally for a cyberattack. Not the company. The individual, Tim Brown. Tim fought back, and won. In the age of AI, every security and business leader needs to ask: Am I next?When the SolarWinds supply chain attack hit in 2020, Tim Brown became one of the first CISOs in history to face personal SEC charges. That case changed the conversation around CISO accountability permanently. With AI inside your enterprise, making decisions, generating outputs and influencing risk, the accountability question has not gone away. It has grown. With that, so has the personal liability exposure for every security leader expanded.In this episode, Monica Verma sits down with Tim Brown, Former CISO of SolarWinds, to talk about what it actually means to be held personally accountable, how he navigated the charges, and what every CISO, security architect, and risk leader needs to understand before their organisation deploys AI at scale.This is not a theoretical conversation. It already happened to one of us.Looking to go from chaos and unpredictability to resilience in the world of AI? Start here with The Predictability Factor newsletter at The Monica Talks Cyber (https://www.monicatalkscyber.com).

SpaceTime with Stuart Gary | Astronomy, Space & Science News
Young Stars Dim Quicker, Surprising Solar Winds, and Dream Chaser's Milestone

SpaceTime with Stuart Gary | Astronomy, Space & Science News

Play Episode Listen Later Apr 22, 2026 25:01


Sponsor Link:This episode is brought to you by NordVPN. For the best online protection and a great price check out our special deal: Click HereSpaceTime Series 29 Episode 48 *Finding that young Sun like stars dim quickly is good news for life A new study has discovered that young Sun like stars settle down and start to dim more quickly than previously thought, potentially benefiting orbiting planets and the prospects of life. *A surprisingly speedy solar wind found in inner corona A new study has found that the solar wind is travelling up to four times faster than expected in the Sun's inner corona. *Dream Chaser passes another critical milestone The Sierra Space Dream Chaser space plane Tenacity has just completed launch acoustic testing at NASA's Space Systems Processing Facility. *The Science Report Long-term HIV remission achieved following a stem cell transplant. How to save Venice from rising sea levels. Half of all answers to health and medical questions by AI found to be problematic. Alex on Tech: The 6G countdown has begun.Become a supporter of this podcast: https://www.spreaker.com/podcast/spacetime-with-stuart-gary--2458531/support.

The Daily Scoop Podcast
OMB's AI risk management deadline hits federal agencies, but not all were ready

The Daily Scoop Podcast

Play Episode Listen Later Apr 10, 2026 5:19


The deadline for federal agencies to implement risk management practices for high-impact AI use cases — or terminate them — has come and gone, but a handful of departments are still working to complete their requirements. FedScoop reached out to 28 federal agencies to inquire about the steps they have taken to ensure compliance within the April 3 timeframe. Some agencies fulfilled the requirements, like the Labor Department, NASA, the VA, State, GSA, and the EPA, while others reclassified use cases or still have a couple boxes to check. A few appear to have missed the deadline entirely. As outlined by an Office of Management and Budget memorandum, uses considered high-impact are required to comply with minimum risk management practices, which include pre-deployment testing, impact assessments, adverse impact monitoring, adequate human training and assessments, appropriate fail-safes that minimize harm, consistent appeal processes, and options for end users to submit feedback. The Department of Justice is asking Congress for a major boost in fiscal 2027 to the fund it uses to support IT modernization and enterprise cybersecurity, with the entire increase going directly to the agency's zero-trust cybersecurity architecture. DOJ has requested $149 million for its Justice Information Sharing Technology fund as part of the Trump administration's fiscal 2027 budget request. Congress appropriated $38.5 million for the program in the past two fiscal years. The primary difference between this request and the funding enacted in the most recent years prior is the $110.3 million that DOJ says it needs to support its migration to a zero-trust architecture for its unclassified and national security systems. To put that into perspective, Justice requested a more meager $11.8 million increase to the JIST fund's topline in fiscal 2026 for “cybersecurity posture enhancement,” which it did not get. In its congressional budget justification for 2027, Justice explains that despite an industrywide shift to zero trust as the cybersecurity model of choice in response to the SolarWinds attack on federal agencies in 2020, its funding for cyber was cut by $108 million in fiscal 2024 and remained essentially flat since then. “Enacted funding levels over the past three years are below the level required to cover DOJ's over 275,000 endpoints and approximately 160,000 users,” the budget document states, adding that “the current funding levels impact the Department's current defenses and constrain its ability to adapt to evolving threats.” The Daily Scoop Podcast is available every Monday-Friday afternoon. If you want to hear more of the latest from Washington, subscribe to The Daily Scoop Podcast  on Apple Podcasts, Soundcloud, Spotify and YouTube.

CERIAS Security Seminar Podcast
Brian Peretti, Symposium Closing Keynote: AI, Cybersecurity, and the Path Forward

CERIAS Security Seminar Podcast

Play Episode Listen Later Apr 8, 2026 73:37


Annual Security Symposium. Visit: https://ceri.as/2026 Artificial intelligence is rapidly transforming both the opportunities and risks within cybersecurity, creating a new landscape that today's students and researchers will soon inherit and shape. This keynote explores how AI is evolving from a supporting tool to a decision-making system, fundamentally changing how cyber threats are created, detected, and managed. It will examine emerging risks such as deepfakes, model manipulation, and systemic dependencies on shared technologies, while also addressing the growing role of regulation and the challenges of governing systems that are powerful yet often opaque. Most importantly, the session will highlight where the greatest opportunities lie—at the intersection of AI, cybersecurity, and policy—and how the next generation of professionals can play a defining role in building secure, resilient, and trustworthy systems for the future.  About the speaker: Brian J. Peretti is a career member of the Senior Executive Service at the United States Department of the Treasury. In his final position, he served as Treasury's Chief Technology Officer and Deputy Chief Artificial Intelligence (AI) Officer in the Office of Chief Information Officer.As Treasury's Chief Technology Officer, Mr. Peretti establishes, leads, and manages a comprehensive, multi-year strategic and long-range planning process that promotes the vision for IT and ensures consistent progress toward accomplishing the CIO's vision, while identifying and leveraging common technology solutions to support business processes and work methods and/or to improve effectiveness of current technologies while also developing appropriate policy for emerging technology such as Artificial Intelligence, Machine Learning, Biometrics and Quantum Computing. As Treasury's Deputy Chief AI Officer, Mr. Peretti supported Treasury's Chief AI Officer in advancing the Department's deployment of this emerging technology. In this capacity, he oversaw the publication of Treasury's report, Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector, and directed the subsequent lines of effort. Additionally, serving in this position has seen him designated as the Executive Officer for the Department's AI Governance Board as well as the Department's representative to the Office of the Director of National Intelligence's CAIO Council. In addition, Mr. Peretti leads the development of domestic and international operational resilience policy, including cyber, as part of Treasury's Sector Risk Management Agency responsibility for the financial services sector. In this role, he spearheads Treasury's efforts to increase multi-directional sharing of cyber threat and vulnerability information. He also serves as the United States's designated subject matter expert at the Group of 7 Cyber Expert Group (G-7 CEG). Mr. Peretti has served at the Treasury for over 22 years with increasing levels of responsibility, including being named the Senior Career Official Executing the Duties of the Assistant Secretary for Financial Institutions during the transition from the Obama to the Trump Administration. Based on his expertise in critical infrastructure protection and operational resilience, he was detailed to the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency's National Risk Management Center during the intial response to the COVID-19 pandemic and served as the first Senior Advisor for Security and the Economy. He also speadheaded DHS response to the SolarWinds cyber incident. A sought-after speaker and presenter, Mr. Peretti has been the recipient of numerous awards and honors throughout his career. Most recently, he received the 12th Annual Billington CyberSecurity Leadership Award at the 2023 Annual Billington CyberSecurity Summit. Prior to joining the Treasury, Mr. Peretti was an associate in Shook, Hardy & Bacon's Corporate Banking and Finance Section in Washington, D.C., and was the General Counsel for the Wright Patman Congressional Federal Credit Union. He has authored numerous publications related to financial sector operations, including payment systems. Mr. Peretti received his bachelor's degree from Rider University (cum laude) in 1989, and his law degree from American University's Washington College of Law (cum laude) in 1992.

The CyberWire
CyberWire Daily at 10: The breaches we still talk about. [Special Edition]

The CyberWire

Play Episode Listen Later Mar 29, 2026 28:21


In this special edition of CyberWire Daily's 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss the biggest breaches over the past 10 years. The foundational 2014 Sony hack kicks off our conversation, then Maria and Dave highlight: the 2015 OPM breach, which exposed sensitive security-clearance data and was attributed to long-term access by China amid outdated government systems and security 2017's WannaCry and NotPetya's global disruption and Equifax's ongoing fallout the 2020 SolarWinds breach underscored supply-chain risks and raised concerns about potential personal criminal liability for CISOs. The conversation illustrates two main threat-actor categories—nation-state espionage and financially motivated criminals—and the increasingly blurred lines between them. Join us as we reflect on how the industry and cybercrime have evolved over the past decade. Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
Oops, those were the FBI files.

The CyberWire

Play Episode Listen Later Mar 12, 2026 28:15


Iran threatens tech firms as hackers strike Stryker. The EU advances efforts toward digital sovereignty. A foreign hacker stumbles upon the FBI's Epstein files. DOGE used ChatGPT to cull humanities grants. Meta claims increased efforts against scams. A Wisconsin ambulance provider discloses a data breach. CISA shortens the patch deadline for a critical SolarWinds vulnerability. We preview this year's RSAC 2026 Innovation Sandbox with Cecilia Marinier and Paul Kocher. Dangerous digital diets miss the mark.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we share a RSAC 2026 Conference innovation preview with Cecilia Marinier and Innovation Sandbox judge Paul Kocher talking about this year's Top 10 Finalists. Selected Reading Iran-linked hackers claim responsibility for attack on US medical device maker Stryker (Reuters) 'Legitimate targets': Iran issues warning to US tech firms including Google, Amazon, Microsoft, Nvidia (The Times of India) Iranian trolls are flooding social media with pro-Tehran, anti-war propaganda (MS Now) Commission announces €75 million EURO-3C Project to build a federated Telco-Edge-Cloud infrastructure for digital sovereignty (European Commission) Hacker broke into FBI and compromised Epstein files, report says (TechCrunch) When DOGE Unleashed ChatGPT on the Humanities (The New York Times) Meta says it culled millions of scam ads amid accusations that it profits from them (The Record) Bell Ambulance Ransomware Attack Impacts Over 237,000 Individuals (Beyond Machines) CISA Mandates Emergency Patching for SolarWinds Web Help Desk Vulnerabilities (Beyond Machines) AI Chatbots Are Giving Teens Absolutely Terrible Diet Advice, Study Warns (Gizmodo) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

SolarWinds TechPod
Unlocking the Power of SolarWinds Through Training

SolarWinds TechPod

Play Episode Listen Later Mar 10, 2026 42:51


In this SolarWinds TechPod episode, hosts Chrystal Taylor and Sean Sebring talk with Cheryl Nomanson, a SolarWinds Academy trainer with 14 years at the company. They discuss the importance of technical education for complex software and networks, exploring SolarWinds' comprehensive training offerings including the SolarWinds Academy with its on-demand courses, instructor-led virtual classes, and office hours format. Cheryl explains the SolarWinds Certified Professional (SCP) certification program and the newer SolarWinds Certified Instructor (SCI) program for training partners globally. The conversation covers different learning formats, comparing virtual versus in-person instruction challenges and benefits, the importance of customer feedback in developing training content, and best practices for internal employee education. They emphasize how proper training helps customers realize the full value of SolarWinds products by providing not just functional knowledge but strategic understanding of why features work the way they do.

The CyberWire
Multiple root-level risks resolved.

The CyberWire

Play Episode Listen Later Feb 24, 2026 28:12


SolarWinds patches four critical remote code execution vulnerabilities. A ransomware attack on Conduant puts the data of over 25 million Americans at risk. RoguePilot enables Github repository takeovers. ZeroDayRat targets Android and iOS devices. North Korea's Lazarus group deploy Medusa ransomware against organizations in the U.S. and the Middle East. Attackers' breakout times drop to under half an hour.  CISA maintains its mission despite staffing challenges. Russian satellites draw fresh scrutiny. Two South Korean teenagers are charged with breaching Seoul's public bike service. Krishna Sai, CTO at SolarWinds, discusses why leaders should focus less on speculating about an AI bubble, and more on how to quantify AI's tangible contributions. The Pope pushes prayerful priests past predictable programs.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing why leaders should focus less on speculating about an AI bubble, and more on how to quantify AI's tangible contributions. Selected Reading Critical SolarWinds Serv-U flaws offer root access to servers (Bleeping Computer) Massive Conduent Data Breach Exfiltrates 8 TB Affects Over 25 Million Americans (GB Hackers) GitHub Issues Abused in Copilot Attack Leading to Repository Takeover (SecurityWeek) New ZeroDayRAT Malware Claims Full Monitoring of Android and iOS Devices (Hackread) North Korean state hackers seen using Medusa ransomware in attacks on US, Middle East (The Record) CrowdStrike says attackers are moving through networks in under 30 minutes (CyberScoop) Shutdown at D.H.S. Extends to Cyber Agency, Adding to Setbacks (The New York Times) From Cold War interceptors to Ukraine: how Russia came to park spy satellites next to the West's most sensitive tech in orbit (Meduza) Korean cops charge two teens over Seoul bike hire breach (The Register) Pope tells priests to use their brains, not AI, to write homilies (EWTN News) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show.  Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

JavaScript – Software Engineering Daily
Engineering AI Systems for Autonomy and Resilience with Krishna Sai

JavaScript – Software Engineering Daily

Play Episode Listen Later Feb 24, 2026 53:15


Enterprise IT systems have grown into sprawling, highly distributed environments spanning cloud infrastructure, applications, data platforms, and increasingly AI-driven workloads. Observability tools have made it easier to collect metrics, logs, and traces, but understanding why systems fail and responding quickly remains a persistent challenge. As complexity continues to rise, the industry is looking beyond dashboards and alerts toward agentic AI systems that can reason about operational data, reduce toil, and take action when things go wrong. SolarWinds offers solutions to monitor, understand, and remediate issues across complex, distributed systems. The company began as a leader in network and infrastructure monitoring, and has evolved to support modern applications, cloud environments, containers, and AI workloads, with a growing focus on reducing operational toil. Krishna Sai is the Chief Technology Officer at SolarWinds. He joins the show with Sean Falconer to discuss how SolarWinds is rethinking observability in the age of AI, what it means to design agentic systems for mission-critical environments, how AI-assisted programming is reshaping engineering workflows, and why the future of operations depends on building platforms where humans and autonomous agents work together. Full Disclosure: This episode is sponsored by SolarWinds. Sean’s been an academic, startup founder, and Googler. He has published works covering a wide range of topics from AI to quantum computing. Currently, Sean is an AI Entrepreneur in Residence at Confluent where he works on AI strategy and thought leadership. You can connect with Sean on LinkedIn. Please click here to see the transcript of this episode. Sponsorship inquiries: sponsor@softwareengineeringdaily.com The post Engineering AI Systems for Autonomy and Resilience with Krishna Sai appeared first on Software Engineering Daily.

Open Source – Software Engineering Daily
Engineering AI Systems for Autonomy and Resilience with Krishna Sai

Open Source – Software Engineering Daily

Play Episode Listen Later Feb 24, 2026 53:15


Enterprise IT systems have grown into sprawling, highly distributed environments spanning cloud infrastructure, applications, data platforms, and increasingly AI-driven workloads. Observability tools have made it easier to collect metrics, logs, and traces, but understanding why systems fail and responding quickly remains a persistent challenge. As complexity continues to rise, the industry is looking beyond dashboards and alerts toward agentic AI systems that can reason about operational data, reduce toil, and take action when things go wrong. SolarWinds offers solutions to monitor, understand, and remediate issues across complex, distributed systems. The company began as a leader in network and infrastructure monitoring, and has evolved to support modern applications, cloud environments, containers, and AI workloads, with a growing focus on reducing operational toil. Krishna Sai is the Chief Technology Officer at SolarWinds. He joins the show with Sean Falconer to discuss how SolarWinds is rethinking observability in the age of AI, what it means to design agentic systems for mission-critical environments, how AI-assisted programming is reshaping engineering workflows, and why the future of operations depends on building platforms where humans and autonomous agents work together. Full Disclosure: This episode is sponsored by SolarWinds. Sean’s been an academic, startup founder, and Googler. He has published works covering a wide range of topics from AI to quantum computing. Currently, Sean is an AI Entrepreneur in Residence at Confluent where he works on AI strategy and thought leadership. You can connect with Sean on LinkedIn. Please click here to see the transcript of this episode. Sponsorship inquiries: sponsor@softwareengineeringdaily.com The post Engineering AI Systems for Autonomy and Resilience with Krishna Sai appeared first on Software Engineering Daily.

Cloud Engineering – Software Engineering Daily
Engineering AI Systems for Autonomy and Resilience with Krishna Sai

Cloud Engineering – Software Engineering Daily

Play Episode Listen Later Feb 24, 2026 53:15


Enterprise IT systems have grown into sprawling, highly distributed environments spanning cloud infrastructure, applications, data platforms, and increasingly AI-driven workloads. Observability tools have made it easier to collect metrics, logs, and traces, but understanding why systems fail and responding quickly remains a persistent challenge. As complexity continues to rise, the industry is looking beyond dashboards and alerts toward agentic AI systems that can reason about operational data, reduce toil, and take action when things go wrong. SolarWinds offers solutions to monitor, understand, and remediate issues across complex, distributed systems. The company began as a leader in network and infrastructure monitoring, and has evolved to support modern applications, cloud environments, containers, and AI workloads, with a growing focus on reducing operational toil. Krishna Sai is the Chief Technology Officer at SolarWinds. He joins the show with Sean Falconer to discuss how SolarWinds is rethinking observability in the age of AI, what it means to design agentic systems for mission-critical environments, how AI-assisted programming is reshaping engineering workflows, and why the future of operations depends on building platforms where humans and autonomous agents work together. Full Disclosure: This episode is sponsored by SolarWinds. Sean’s been an academic, startup founder, and Googler. He has published works covering a wide range of topics from AI to quantum computing. Currently, Sean is an AI Entrepreneur in Residence at Confluent where he works on AI strategy and thought leadership. You can connect with Sean on LinkedIn. Please click here to see the transcript of this episode. Sponsorship inquiries: sponsor@softwareengineeringdaily.com The post Engineering AI Systems for Autonomy and Resilience with Krishna Sai appeared first on Software Engineering Daily.

The Audit
Secret Service Agent Reveals Undercover Cyber Ops

The Audit

Play Episode Listen Later Feb 23, 2026 44:26 Transcription Available


What does it take to go undercover with international cybercriminals — with no backup, no safe house, and no script? In this episode of The Audit, Richard LaTulip, Field CISO at Recorded Future and former U.S. Secret Service agent, pulls back the curtain on three years of undercover operations spanning Thailand, Dubai, Macau, and China. From buying stolen credit card data in bulk to handing cheap government-issued laptops to disappointed hackers, Richard shares the raw, unfiltered reality Hollywood never shows you. Co-hosts Joshua J Schmidt, Eric Brown, Nick Mellem, and Jen Lotze dig into the psychology of social engineering, the stark differences between nation-state and financially motivated threat actors, and why your employees are simultaneously your greatest asset and your biggest vulnerability. Richard breaks down how SolarWinds revealed the patience of nation-state operations, why cultural awareness is a cybersecurity weapon, and how organizations can shift security from a cost center to a value driver. 

Risky Business
Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly

Risky Business

Play Episode Listen Later Feb 11, 2026 56:13


On this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: Microsoft reshuffles security leadership. It doesn't spark joy. Russia is hacking the Winter Olympics. Again. But y tho? China-linked groups are keeping busy, hacking telcos in Norway, Singapore and dozens of others Campaigns underway targeting Ivanti, BeyondTrust and SolarWinds products An unknown hero blocks 23/tcp on the US internet backbone And James Wilson pops into talk about Claude's go at a C compiler This week's episode is sponsored by Ent.AI, an AI startup that isn't quite ready to tell us all what they're doing. But nevertheless, founder Brandon Dixon joins to discuss AI's role in security. Where does language-based understanding take us that previous methods couldn't? This episode is also available on Youtube. Show notes Updates in two of our core priorities - The Official Microsoft Blog Strengthening Windows trust and security through User Transparency and Consent | Windows Experience Blog Microsoft prepares to refresh Secure Boot's digital certificate | Cybersecurity Dive Microsoft Patch Tuesday matches last year's zero-day high with six actively exploited vulnerabilities | CyberScoop Microsoft releases urgent Office patch. Russian-state hackers pounce. - Ars Technica Italy blames Russia-linked hackers for cyberattacks ahead of Winter Olympics | The Record from Recorded Future News Researchers uncover vast cyberespionage operation targeting dozens of governments worldwide | The Record from Recorded Future News Germany warns of state-linked phishing campaign targeting journalists, government officials | The Record from Recorded Future News Norwegian intelligence discloses country hit by Salt Typhoon campaign | The Record from Recorded Future News Singapore says China-linked hackers targeted telecom providers in major spying campaign | The Record from Recorded Future News Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore's Telecommunications Sector | Cyber Security Agency of Singapore How Intel and Google Collaborate to Strengthen Intel® TDX Strengthening the Foundation: A Joint Security Review of Intel TDX 1.5 - Google Bug Hunters Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399) | Huntress EU, Dutch government announce hacks following Ivanti zero-days | The Record from Recorded Future News North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam | The Record from Recorded Future News BeyondTrust warns of critical RCE flaw in remote support software Rapid7 Analysis of CVE-2026-1731 Building a C compiler with a team of parallel Claudes Anthropic (1) Post by @ryiron.bsky.social — Bluesky What AI Security Research Looks Like When It Works | AISLE South Korean crypto exchange races to recover $40bn of bitcoin sent to customers by mistake | South Korea | The Guardian White House to meet with GOP lawmakers on FISA Section 702 renewal | The Record from Recorded Future News

Cyber Security Headlines
Ukraine tightens controls on Starlink terminals, VMware ESXi flaw now exploited, SolarWinds Web Help Desk bug under attack

Cyber Security Headlines

Play Episode Listen Later Feb 5, 2026 6:52


Ukraine tightens controls on Starlink terminals VMware ESXi flaw now exploited SolarWinds Web Help Desk bug under attack Get the show notes here: https://cisoseries.com/cybersecurity-news-ukraine-tightens-controls-on-starlink-terminals-vmware-esxi-flaw-now-exploited-solarwinds-web-help-desk-bug-under-attack/ Huge thanks to our sponsor, Strike48 Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, maximizing log visibility without blowing your budget. Find threats your siloed tools miss. Get started today with pre-built AI agents and workflows that investigate, detect, and respond 24/7 or build your own at strike48.com/security.

The Peel
How Duo Security went Zero to $1B ARR in Ann Arbor | Dug Song, Jon Oberheide

The Peel

Play Episode Listen Later Feb 5, 2026 128:32


Dug Song and Jon Oberheide are the co-founders of Duo Security.If you've never heard of Duo, it might be one of the most underrated software stories of all-time.Starting in 2010, they burned only $14 million to hit $100m in ARR, were acquired by Cisco for $2.35 billion in 2018, and now rumored to be doing over $1 billion in ARR inside Cisco 16 years later.We talk about how they built one of the most capital efficient SaaS companies ever from Ann Arbor, Michigan, and how their focus on the customer and company culture helped them win in a crowded cybersecurity market.We talk growing up in the early hacking culture of the 90s, why most security tools are painful to use, sizing their market, solving for non-consumption of a product, and how Duo flipped the model by designing for end users instead of security teams.We talk about staying in Michigan instead of moving to Silicon Valley, and why staying out of the tech bubble helped them execute.We break down the mechanics of scaling from zero to $100 million in ARR, everything they learned integrating with Cisco, and why more founders should build outside of San Francisco. A quick thank you ex-Duo employees Zack Urlocker, Ash Devata, and Katie Kilroy for their help brainstorming topics for the conversation.Try Numeral, the end-to-end platform for sales tax and compliance: [https://www.numeral.com](https://www.numeral.com/)Sign-up for Flex Elite with code TURNER, get $1,000: https://form.typeform.com/to/Rx9rTjFzTimestamps:(4:49) Meeting from Dug's Wi-Fi honeypot(7:33) 90's hacking culture and cybersecurity's wild west(14:49) How the internet was born in Ann Arbor(18:58) Staying in Michigan instead of moving to Silicon Valley(31:20) Philosophy on leadership and team building(39:48) What makes a good engineering leader(44:01) Starting Duo to make security easier(45:22) Why most security products suck(48:36) How fixing account takeover became a $1B ARR company(59:10) TAM, competition, fixing the non-consumption of security(1:04:04) Being a radical advocate for the customer(1:08:35) Duo's pizza sales play(1:12:45) Branding lessons from Anthropic, Tesla, Cliff Bar(1:17:47) When to say no to customers(1:21:27) Importance of culture when scaling(1:27:56) Duo's role in uncovering the SolarWinds breach(1:31:29) Scaling to $100M ARR on $14M burned(1:39:30) Inside the $2.35B Cisco acquisition(1:44:02) What big companies get wrong about customers(1:51:53) Building Michigan's startup ecosystemReferencedDuo Security: [https://duo.com](https://duo.com/)Cisco: [https://www.cisco.com](https://www.cisco.com/)University of Michigan: [https://umich.edu](https://umich.edu/)Follow DugTwitter: https://x.com/dugsongLinkedIn: https://www.linkedin.com/in/dugsongFollow JonTwitter: https://x.com/jonoberheideLinkedIn: https://www.linkedin.com/in/jonoFollow TurnerTwitter: https://twitter.com/TurnerNovakLinkedIn: https://www.linkedin.com/in/turnernovakSubscribe to my newsletter to get every episode + the transcript in your inbox every week: https://www.thespl.it/

Risky Business
Risky Business #823 -- Humans impersonate clawdbots impersonating humans

Risky Business

Play Episode Listen Later Feb 4, 2026 56:09


Patrick Gray and Adam Boileau are joined by the newest guy on the Risky Business Media team, James WIlson. They discuss the week's cybersecurity news, including: Notepad++ update supply chain attack has been attributed to China The AI agent future is even more stupid than expected; behold the OpenClaw/Clawdbot/Moltbook mess The Epstein files claim he had a personal hacker? Microsoft is finally getting ready to (think about starting to begin to) disable NTLM by default The usual bugs in the usual things! Ivanti, Fortinet, and Solarwinds. Again. Telco hides a free trip in its privacy policy, someone actually reads it and wins! This weeks's episode is sponsored by opensource IDP platform Authentik. CEO Fletcher Heisler talks to Pat about their new endpoint agent that can enforce device posture policies during login. This episode is also available on Youtube. Show notes The Chrysalis Backdoor: A Deep Dive into Lotus Blossom's toolkit Notepad++ Hijacked by State-Sponsored Hackers | Notepad++ Notepad++ v8.8.3 - Self-signed Certificate: Certified by Code, Not Corporations | Notepad++ Hacking Moltbook: AI Social Network Reveals 1.5M API Keys | Wiz Blog lcamtuf on X: "Moltbook debate in a nutshell" / X Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site AndrewMohawk on X: "How exactly did an attacker send a message to your bot since you need to approve all the channels and set keys etc" / X Signal president warns AI agents are making encryption irrelevant Massive AI Chat App Leaked Millions of Users Private Conversations Runa Sandvik on X: New court record from the FBI details the state of the devices seized from Washington Post reporter Hannah Natanson EFTA01683874.pdf Disrupting the World's Largest Residential Proxy Network | Google Cloud Blog Nobel Committee says Peace Prize winner likely revealed early by digital spying | Reuters County pays $600,000 to pentesters it arrested for assessing courthouse security - Ars Technica Advancing Windows security: Disabling NTLM by default - Windows IT Pro Blog Critical flaws in Ivanti EPMM lead to fast-moving exploitation attempts | Cybersecurity Dive CISA orders federal agencies to patch exploited SolarWinds bug by Friday | The Record from Recorded Future News CISA, security researchers warn FortiCloud SSO flaw is under attack | Cybersecurity Dive Fintech firm Marquis blames hack at firewall provider SonicWall for its data breach | TechCrunch We Hid a Free Trip to Switzerland in Our Privacy Policy. Someone Found It in 2 Weeks. - Cape Between Two Nerds: The internal logic of Russian power grid attacks - YouTube

Packet Pushers - Full Podcast Feed
NB560: Microsoft Doubles Down on Custom AI Chip; CrowdStrike Brandishes Big Bucks for Browser Security

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Feb 2, 2026 33:41


Take a Network Break! We’ve got Red Alerts for HPE Juniper Session Smart Routers and SolarWinds. In this week’s news, Microsoft debuts its second-generation AI inferencing chip, Mplify rolls out a new Carrier Ethernet certification for supporting AI workloads, and AWS upgrades its network firewall to spot GenAI application traffic and filter Web categories. Google... Read more »

Packet Pushers - Network Break
NB560: Microsoft Doubles Down on Custom AI Chip; CrowdStrike Brandishes Big Bucks for Browser Security

Packet Pushers - Network Break

Play Episode Listen Later Feb 2, 2026 33:41


Take a Network Break! We’ve got Red Alerts for HPE Juniper Session Smart Routers and SolarWinds. In this week’s news, Microsoft debuts its second-generation AI inferencing chip, Mplify rolls out a new Carrier Ethernet certification for supporting AI workloads, and AWS upgrades its network firewall to spot GenAI application traffic and filter Web categories. Google... Read more »

Packet Pushers - Fat Pipe
NB560: Microsoft Doubles Down on Custom AI Chip; CrowdStrike Brandishes Big Bucks for Browser Security

Packet Pushers - Fat Pipe

Play Episode Listen Later Feb 2, 2026 33:41


Take a Network Break! We’ve got Red Alerts for HPE Juniper Session Smart Routers and SolarWinds. In this week’s news, Microsoft debuts its second-generation AI inferencing chip, Mplify rolls out a new Carrier Ethernet certification for supporting AI workloads, and AWS upgrades its network firewall to spot GenAI application traffic and filter Web categories. Google... Read more »

Cybercrime Magazine Podcast
CISO Confidential. The New Attack Playbook. Tim Brown, SolarWinds & Bobby Ford, Doppel.

Cybercrime Magazine Podcast

Play Episode Listen Later Feb 2, 2026 14:53


Tim Brown is the CISO at SolarWinds. In this episode, he joins host Paul John Spaulding and Bobby Ford, Chief Strategy & Experience Officer at Doppel, to discuss today's threat landscape and what organizations can do to protect themselves in light of new threats such as deepfakes and artificial intelligence. This episode of CISO Confidential is brought to you by Doppel. Learn more about our sponsor at https://doppel.com.

Cyber Briefing
January 30, 2026 - Cyber Briefing

Cyber Briefing

Play Episode Listen Later Jan 30, 2026 7:42


If you like what you hear, please subscribe, leave us a review and tell a friend!

The CyberWire
Proxy wars and open doors.

The CyberWire

Play Episode Listen Later Jan 29, 2026 30:24


Google dismantles a huge residential proxy network. Did the FBI take down the notorious RAMP cybercrime forum? A long running North Korea backed cyber operation has splintered into three specialized threat groups. U.S. military cyber operators carried out a covert operation to disrupt Russian troll networks ahead of the 2024 elections. Phishing campaigns target journalists using the Signal app. SolarWinds patches vulnerabilities in its Web Help Desk product. Amazon found CSAM in its AI training data. Initial access brokers switch up their preferred bot. China executes scam center kingpins. Our guest is Tom Pace, CEO of NetRise, explaining how open-source vulnerabilities are opening doors for nation-states.  An unsecured webcam peers into Pyongyang.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Tom Pace, former DOE cyber analyst and CEO of NetRise, joins the show to explain how open-source vulnerabilities are opening doors for nation-states and why visibility into who maintains code repositories matters. Selected Reading Google Disrupted World's Largest IPIDEA Residential Proxy Network (Cyber Security News) Notorious Russia-based RAMP cybercrime forum apparently seized by FBI (The Record) Long-running North Korea threat group splits into 3 distinct operations (CyberScoop) Secret US cyber operations shielded 2024 election from foreign trolls, but now the Trump admin has gutted protections (CNN Politics) Phishing attack: Numerous journalists targeted in attack via Signal Messenger (Netzpolitik.org) Signal president warns AI agents are making encryption irrelevant (Cyber Insider) SolarWinds Patches Critical Web Help Desk Vulnerabilities (SecurityWeek)  Amazon Found ‘High Volume' Of Child Sex Abuse Material in AI Training Data (Bloomberg) Initial access hackers switch to Tsundere Bot for ransomware attacks (Bleeping Computer) China Executes 11 People Linked to Cyberscam Centers in Myanmar   (Bloomberg) North Korean Hackers' Daily Life Leaked in Video (The Chosun) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, January 29th, 2026: WebLogic AI Slop; Fortinet Patches; WebLogic AI Slop; Fortinet Patches

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jan 29, 2026 6:01


Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop? We are seeing attempts to attack CVE-2026-21962, a recent weblog vulnerability, using a non-working AI slop exploit https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662 Fortinet Patches are Rolling Out Fortinet is starting to roll out patches for the recent SSO vulnerability https://fortiguard.fortinet.com/psirt/FG-IR-26-060 SolarWinds Web Helpdesk Vulnerability Another set of vulnerabilities in SolarWinds Web Helpdesk may result in unauthenticated system access https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

Develpreneur: Become a Better Developer and Entrepreneur
Tiered Pricing in the AI Era: What Actually Works (with Dan Balcauski)

Develpreneur: Become a Better Developer and Entrepreneur

Play Episode Listen Later Jan 22, 2026 24:18


Tiered pricing is becoming the simplest way to sell AI-powered SaaS without turning your pricing page into a technical explanation. In my interview with Dan Balcauski, founder and Chief Pricing Officer at Product Tranquility, we talked about why AI is forcing new pricing decisions earlier than ever—and why "good, better, best" packaging often works because it keeps buying decisions clear while helping companies manage real AI costs.  The AI era is making pricing margin-aware again. Tiered pricing helps you protect margins without forcing buyers to learn your cost structure.  About Dan Balcauski Dan Balcauski is the founder and Chief Pricing Officer at Product Tranquility, where he helps high-volume B2B SaaS CEOs define pricing and packaging for new products. He is a TopTal certified Top 3% Product Management Professional and helps teach Kellogg Executive Education course on Product Strategy. Over the last 15 years, Dan has managed products across the full lifecycle—from concept incubation to launch, platform transitions, maintenance, and end of life—across consumer and B2B companies ranging from startups to publicly traded enterprises. He previously served as Head of Product at LawnStarter and was a Principal Product Strategist at SolarWinds. Why Tiered Pricing Is Winning in the AI Era For years, SaaS companies could price mostly around value because marginal costs were relatively stable. AI changes the math. Dan points out that companies are now cutting meaningful monthly checks to model providers, and leadership teams can't pretend cost-to-serve is irrelevant anymore.  That's a big reason tiered pricing is showing up everywhere right now. It gives teams a way to: Keep the offer simple for buyers Put premium capabilities where they belong Create a natural upgrade path that aligns with value and cost Most importantly, tiered pricing keeps you out of the weeds. The customer conversation stays focused on outcomes, not infrastructure. What Makes Tiered Pricing Actually Work Dan's point isn't "just shove AI into the top tier." Tiered pricing works when plan differences are easy to understand and tied to value drivers customers already recognize.  Here are three practical patterns from the discussion that hold up well in the AI era. 1) Put AI in higher tiers when it boosts a user's output If an AI feature makes a person more effective—faster drafting, better triage, higher quality responses—tiering can be straightforward. The buyer already understands why a "Better" or "Best" plan costs more: it changes the capability of the team.  This is also why seat-based pricing can still make sense for many AI-enhanced tools. If the value driver is still "help my team do better work," then users/seats remain an intuitive anchor.  If AI increases team productivity, tiered pricing can stay aligned to seats—because seats still map to value.  2) Use add-ons when AI changes the value driver Sometimes AI doesn't just "help" the user—it replaces work entirely. When that happens, forcing it into the same tier structure can distort value and create confusion. Dan points to Intercom as a strong example of handling this well: The core support platform stays priced per user (agents), because the value driver is agent effectiveness. Their AI agent ("Fin AI") is priced separately because the agent isn't involved—the value is the number of issues the AI resolves. That's why per-resolution pricing makes sense.  3) Don't make buyers learn token math Dan's strongest warning is about token pricing. Customers don't want to learn what tokens are, and sales teams don't want to explain them—especially when you're selling a business outcome like faster support or better customer experience.  Token-based pricing also shifts the conversation away from value and toward your vendor bill. As Dan puts it, customers don't care about your infrastructure costs, and pushing that complexity into the buying motion adds friction.  If your tiered pricing requires a footnote explaining tokens, you're adding sand in the gears.  A Tiered Pricing Checklist for AI Features Here's a simple way to apply this immediately: Good: Core workflow value, minimal AI (or AI where costs are predictable) Better: AI that boosts team output (speed, quality, throughput) Best: AI that drives outcomes at scale (automation, deflection, resolution) Add-on: Use when AI has a different value driver than the base product (example: per-resolution)  Stay Connected: Join the Developreneur Community We invite you to join our community and share your coding journey with us. Whether you're a seasoned developer or just starting, there's always room to learn and grow together. Contact us at info@develpreneur.com with your questions, feedback, or suggestions for future episodes. Together, let's continue exploring the exciting world of software development. Additional Resources Setting Your Development Pricing Fixed or Hourly Project Pricing A Project Management and Pricing Guide for Success Building Better Foundations Podcast Videos – With Bonus Content

Develpreneur: Become a Better Developer and Entrepreneur
Minimal Viable Pricing: How to Stop Guessing and Start Learning (with Dan Balcauski)

Develpreneur: Become a Better Developer and Entrepreneur

Play Episode Listen Later Jan 20, 2026 30:43


Minimal viable pricing is the fastest way to stop debating what your product should cost and start learning what customers will actually pay for. In my interview with Dan Balcauski, founder and Chief Pricing Officer at Product Tranquility, we talked about how early-stage teams can set pricing that's "good enough" to sell, validate value, and iterate—without getting stuck chasing the perfect number. Pricing can feel risky because it shapes perception, positioning, and revenue. But Dan's message is practical: you don't need perfect pricing to move forward—you need minimal viable pricing that creates clear decisions and real feedback loops. Minimal viable pricing isn't "cheap pricing." It's "clear pricing" that helps you test value and drive decisions. About Dan Balcauski Dan Balcauski is the founder and Chief Pricing Officer at Product Tranquility, where he helps high-volume B2B SaaS CEOs define pricing and packaging for new products. A TopTal-certified Top 3% Product Management Professional, Dan also teaches in Kellogg Executive Education's Product Strategy coursework. Over the last 15 years, he has led products across the full lifecycle—from concept incubation to launch, platform transitions, maintenance, and end-of-life—across both consumer and B2B markets. Before Product Tranquility, he served as Head of Product at LawnStarter and as a Principal Product Strategist at SolarWinds following its $4B acquisition. What "minimal viable pricing" actually means Dan's approach starts with a mindset shift: early-stage companies rarely fail because their initial price was off by 10–20%. They fail because they haven't found a repeatable customer problem, a clear value promise, or a reliable way to acquire customers. Minimal viable pricing means: You set a price you can defend. You package it in a way customers can understand. You use real conversations and real deals to refine it. It's pricing as a learning tool—not a spreadsheet exercise. Minimal viable pricing starts with your "free option" One of the most actionable parts of the discussion was Dan's breakdown of freemium vs free trial—and why it matters so much for minimal viable pricing. A free trial creates urgency. There's a natural deadline, which forces customers to evaluate value and decide. A freemium model can work, but it often creates a huge pool of users who never engage deeply enough to convert. If your goal is to learn quickly, trials often generate clearer signals: Who gets value fast? What feature set drives adoption? What objections stop the purchase? Minimal viable pricing works best when your go-to-market motion creates real decisions—not endless "maybe later." Trial length: don't confuse "short" with "effective" There's a trend toward shorter trials (like 7 days), but Dan's point is simple: a short clock doesn't help if your customer can't realistically experience value in that window. In B2B especially, onboarding delays, competing priorities, and internal approvals can chew up days instantly. A minimal viable pricing approach asks: What's the shortest trial that still allows a motivated customer to succeed? If you're selling to teams, the answer is often longer than you think. Use minimal viable pricing to clarify positioning Dan also shared a framing that sticks: are you selling a Timex or a Rolex? In other words, are you competing on affordability and simplicity—or premium value and outcomes? Minimal viable pricing isn't just about the number. It's also about: The story your pricing tells The kind of customer you attract The expectations you set around results and support You don't need a dozen plans to communicate this. You need clarity. If customers can't tell who your product is for from the pricing page, your "pricing problem" might actually be a positioning problem. The goal: learn faster, not argue longer Minimal viable pricing gives you a way to move forward without pretending you have perfect information. Start with something simple, sell it, listen hard, and iterate. If you want a practical takeaway from Dan's perspective, it's this: pricing is one of your best feedback loops. Use it early. Use it intentionally. And don't let the hunt for "perfect" delay the real work—helping customers win. Stay Connected: Join the Developreneur Community We invite you to join our community and share your coding journey with us. Whether you're a seasoned developer or just starting, there's always room to learn and grow together. Contact us at info@develpreneur.com with your questions, feedback, or suggestions for future episodes. Together, let's continue exploring the exciting world of software development. Additional Resources Defining An MVP Properly for Your Goals Price With Confidence: Estimation Made Simple How to Build a Minimal Viable Product Without Blowing Your Budget Building Better Foundations Podcast Videos – With Bonus Content

SolarWinds TechPod
IT Trends and Predictions for 2026

SolarWinds TechPod

Play Episode Listen Later Jan 13, 2026 61:59


SolarWinds TechPod returns with its annual IT trends and predictions episode — and 2026 is all about Agentic AI. In this episode of SolarWinds TechPod, hosts Sean Sebring and Chrystal Taylor are joined by Sascha Giese (SolarWinds) and Lauren Okruch (SolarWinds Product Marketing) to break down how AI, ITSM, automation, governance, and resilience will shape IT operations in 2026. As a leader in IT management, observability, and IT service management, SolarWinds offers a unique perspective on how Agentic AI is moving IT from automation to autonomous action — and what that means for governance, security, and the evolving role of IT teams. Topics covered in this SolarWinds TechPod episode: What Agentic AI means for modern IT organizations How SolarWinds sees AI evolving beyond traditional automation The rise of shadow AI and shadow IT in enterprise environments Why IT governance and trust are critical in 2026 How ITSM is changing with AI-driven workflows Energy, sustainability, and cost considerations of AI at scale Resilience, multi-cloud strategies, and right-compute decision making Why IT is no longer just a cost center — but an innovation engine This episode is essential listening for SolarWinds users, IT leaders, sysadmins, service desk teams, and technology decision-makers preparing for the next era of AI-powered IT operations. Subscribe to SolarWinds TechPod for expert insights on ITSM, observability, AI in IT, automation, and digital transformation — straight from the SolarWinds community.

Hacking Humans
Poisoned at the source. [OMITB]

Hacking Humans

Play Episode Listen Later Jan 6, 2026 44:45


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠Qintel⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we dive into supply chain attacks through the lens of a massive Android malware campaign that infects devices before they ever reach users, embedding itself in firmware and reseller-installed system images. We connect the dots to other high-impact supply chain incidents—from SolarWinds to the recent F5 breach—and share new intelligence on Android devices compromised during manufacturing and distribution in China. Together, these cases highlight how attacks at the source can quietly scale, persist, and evade traditional defenses.

Risky Business
Risky Business #816 -- Copilot Actions for Windows is extremely dicey

Risky Business

Play Episode Listen Later Nov 26, 2025 58:07


In this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: Salesforce partner Gainsight has customer data stolen Crowdstrike fires insider who gave hackers screenshots of internal systems Australian Parliament turns off wifi and bluetooth in fear of of visiting Chinese bigwigs Shai-Hulud npm/Github worm is back, and rm -rf'ier than ever SEC gives up on Solarwinds lawsuit Dog eats cryptographer's key material This week's episode is sponsored by runZero. HD Moore pops in to talk about how they're integrating runZero with Bloodhound-style graph databases. He also discusses uses for driving runZero's tools with an AI, plus the complexities of shipping AI when the company has a variety of deployment models. This episode is also available on Youtube. Show notes Google says hackers stole data from 200 companies following Gainsight breach Gainsight Status Trust Status CrowdStrike fires 'suspicious insider' who passed information to hackers Salesforce cuts off access to third-party app after discovering ‘unusual activity' Атаки разящей панды: APT31 сегодня Office of Public Affairs | Seven Hackers Associated with Chinese Government Charged with Computer Intrusions Australian federal MPs warned to turn off phones when Chinese delegation visits Parliament House Sha1-Hulud: The Second Coming of the NPM Worm is Digging For Secrets FCC eliminates cybersecurity requirements for telecom companies Trade Associations Cybersecurity Practices Ex Parte SEC voluntarily dismisses SolarWinds lawsuit Record-breaking DDoS attack against Microsoft Azure mitigated The Cloudflare Outage May Be a Security Roadmap – Krebs on Security Critics scoff after Microsoft warns AI feature can infect machines and pilfer data vx-underground on X: "I've had a surprising amount of people ask me about Copilot" Researchers warn command injection flaw in Fortinet FortiWeb is under exploitation Two suspected Scattered Spider hackers plead not guilty over Transport for London cyberattack Russia arrests young cybersecurity entrepreneur on treason charges This campaign aims to tackle persistent security myths in favor of better advice Oops. Cryptographers cancel election results after losing decryption key. Uncovering network attack paths with runZeroHound Model Context Protocol

WSJ Tech News Briefing
TNB Tech Minute: Nokia Pledges $4 Billion U.S. Investment

WSJ Tech News Briefing

Play Episode Listen Later Nov 21, 2025 3:13


Plus: Pony AI will gain global momentum, say analysts. And the SEC drops its landmark cyber case against SolarWinds. Julie Chang hosts. Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
AI meets the chain of command.

The CyberWire

Play Episode Listen Later Nov 21, 2025 27:52


Cyber Command names a new head of AI. The UK introduces its long-delayed Cyber Security and Resilience Bill. Researchers highlight a critical Oracle Identity Manager flaw. Salesforce warns customers of a third-party data breach. Italy's state-owned railway operator leaks sensitive information. SonicWall patches firewalls and email security devices. The US charges four individuals with conspiring to illegally export restricted Nvidia AI chips to China. The SEC drops its lawsuit against SolarWinds. NSO group claims a permanent injunction could cause irreparable and potentially existential harm. Maria Varmazis of the T-Minus Space Daily show sits down with General Daniel Karbler (Ret.) to discuss his consulting work for A House of Dynamite, the newly released Netflix film. Roses are red, violets are blue, this poem just jailbroke your AI too. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Maria Varmazis of the T-Minus Space Daily show sits down with Lt. General Daniel Karbler (Ret.) to discuss his consulting work for A House of Dynamite, the newly released Netflix film. This is an excerpt of T-Minus Deep Space airing tomorrow in all of your favorite podcast app. Selected Reading Cyber Command Taps Reid Novotny as New AI Chief (MeriTalk) UK's New Cybersecurity Bill Takes Aim at Ransomware Gangs and State-Backed Hackers (Fortra) Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day (SecurityWeek) Salesforce alerts customers of data breach traced to a supply chain partner (CXOtoday) Massive data leak hits Italian railway operator Ferrovie dello Stato via Almaviva hack (Security Affairs) SonicWall Patches High-Severity Flaws in Firewalls, Email Security Appliance (SecurityWeek) Four charged with plotting to sneak Nvidia chips into China (The Register) SEC voluntarily dismisses SolarWinds lawsuit (The Record) NSO Group argues WhatsApp injunction threatens existence, future U.S. government work (CyberScoop) Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models (Arxiv) Freesound Music Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices