Skip to content
Artwork for Breach Please
TechnologyNewsTech NewsNews Commentary

Breach Please

Breach Please Team

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m.

Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about.

Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both.

No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud.

Breach? Please. Pull up a chair.

Play
  • 25 episodes
  • daily
  • Avg 37 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #4
    July 28 · 23 min

    S0E4 - Google indexes AI chats (again) and dump of PoC exploits

    In this episode of Breach Please, Jake and Jess talk about how the story (again) about AI chats being indexed by search engines isn't really an AI story. This is a data security problem and a misalignment with enterprise tooling. We then talk about a relatively new GitHub repo with lots of zero day exploits. We agree it's academically interesting, but doesn't change anything for how we do enterprise security.

  • #3
    July 27 · 40 min

    S0E3 - OpenAI Lost Control of its Agents

    In this episode, we talk a lot (too much, we went over on time) about the reports that OpenAI lost control of its agents and apparently only realized it after Hugging Face posted and someone said "yeah, that sounds a bit like us." Reuters article: https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/ Jake mentioned training. Here's an upcoming one-day seminar on MCP security: https://learning.antisyphontraining.com/courses/assessing-ai-security-model-context-protocol Here's Jake's two-day class covering AI security risk assessment: https://www.antisyphontraining.com/product/hands-on-ai-security-risk-assessment-with-jake-williams/

  • #2
    July 24 · 22 min

    S0E2 SNow vs researchers and destructive cyberattacks.

    In this episode, Jake and Jess talk about lessons we can take away from the alleged exploitation of ServiceNow (likely CVE-2026-6875) and the destructive attack on Romania's Land Registry Database. Join us as we discuss the stories, but more importantly what they mean for you and your security team.

  • #1
    July 23 · 32 min

    S0E1 OpenAI hacked Hugging Face? Oh noes!

    Jake and Jess talk through the story (and there's a LOT missing here) where OpenAI's agent allegedly hacked Hugging Face. There's so much meat missing in OpenAI's account of what happened that their PR people are clearly advocating we go vegetarian...

  • July 22 · 19 min

    S0E0 - Is This Thing On?

    In this episode, we discuss our mission statement. What are we even doing with Breach Please? What can you expect? Does the industry even need more talking heads? We think so - but only if they tell it like it is...

Showing 21–25 of 25 episodes