Artwork for Decipher Security Podcast
Technology

Decipher Security Podcast

Decipher

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.

  • 370 episodes
  • Updated Friday

Episodes370

  • Friday · 35 min

    The OpenAI and Hugging Face Intrusion Wasn't Enough, So Now Anthropic Wants In

    This week we talk about the OpenAI-Hugging Face incident and what it means for those companies and the way that AI models are tested, and then we discuss Anthropic's entry into the race with its own admission that some of its models escaped the playground and attacked outside organizations. LinksOpenAI-Hugging Face intrusion: https://decipher.sc/2026/07/29/openai...Anthropic blog: https://www.anthropic.com/news/invest...Ringer piece on the Hugging Face incident: https://www.theringer.com/2026/07/24/...

  • Wednesday · 48 min

    Project Hail Mary is a Hacker Movie. Amaze Amaze Amaze.

    Project Hail Mary is many things: an instant classic, a heartwarming buddy movie, a brilliant scientific tale. And it's also a pure hacker movie. Wendy Nather and David Mortman join Dennis and Lindsey to talk about Ryland Grace's hacker ethos and why he and Rocky typify the can-do attitude of hackers everywhere. It's time go!

  • July 27 · 48 min

    How Cybercrime Groups Have Become APTs | Michael Sweeney

    Cybercrime has become professionalized and industrialized to the point that these groups are essentially at the level of state-backed APTs. Mike Sweeney of Silent Push joins Dennis Fisher to talk about this evolution, how AI is enabling this shift, and how defenders and vendors are working to take incremental bites out of their ecosystem.

  • July 20 · 26 min

    JADEPUFFER: The Era of Agentic Ransomware Has Begun | Michael Clark

    Michael Clark, director of Threat Research at Sysdig, talks about a recent LLM-driven extortion campaign dubbed JADEPUFFER, touching on how the team discovered it, how attackers’ “intent is now legible,” and what that means for defenders. LinkSysdig research: https://www.sysdig.com/blog/jadepuffe...

  • July 14 · 36 min

    Industrial Cybersecurity and Malware Archaeology with Lesley Carhart

    Old malware like Conficker never really dies, and in industrial control and SCADA environments it can live forever undisturbed. Lesley Carhart of Dragos joins Dennis Fisher to talk about the myriad challenges of incident response in ICS networks, how ancient malware can cause trouble for years on end, and why we need more ICS security engineers desperately.

  • July 7 · 23 min

    Our AI Coding Future with Jack Cable

    Jack Cable, co-founder and CEO of Corridor and a former senior technical advisor at CISA, discusses AI's impact on cybersecurity, vulnerability discovery, and coding practices.

  • June 29 · 57 min

    The (Bug) Disclosure Day Conundrum and How AI is Changing the Game with Katie Moussouris

    Hacker and legendary vulnerability disclosure expert Katie Moussouris of Luta Security joins Dennis to talk about the Fable 5 munitions classification controversy, the recent re-emergence of the disclosure debate, how AI-assisted bug hunting is reshaping the defensive landscape, and what the future holds for attackers and defenders.

  • June 26 · 31 min

    The Gaslight macOS Backdoor, Cisco Zero Day Exploit, and Operation Endgame

    It's a non-AI podcast! This week we dig into the new Gaslight macOS implant that tries to trick security researchers with some anti-forensics techniques, then we discuss the Operation Endgame takedown of some malware infrastructure, and finally we discuss a Cisco Catalyst SD-WAN bug that was exploited as a zero day.

  • June 16 · 41 min

    How Much Do Data Breaches Really Cost? | Alex Pinto

    Alex Pinto, one of the lead authors of the Verizon Data Breach Investigations Report, joins Dennis to talk about his organization's newest publication, the Breach Impact Study, which digs into the real world cost of breaches, both in dollars and in organizational impact. Spoiler: Breaches are expensive. Verizon BIS: https://www.verizon.com/business/resources/reports/2026-breach-impact-study-dbir.pdf

  • June 12 · 32 min

    The Shrinking Exploit Window, Patch Schedule Changes, and the Vulnpocalypse

    This week was blessedly free of any major supply chain compromises, so we start by talking about new research from Anthropic on the shrinking window between bug disclosure and exploitation, then we discuss the changing patch schedule for Cisco and how all of this is changing the prioritization process for security teams, and finally we discuss some upcoming episodes and our latest hacker movie podcast on The Conversation. Links Anthropic research: https://decipher.sc/2026/06/10/anthropic-warns-of-llms-impact-on-already-shrinking-n-day-exploit-gap/ Cisco patch change: https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery The Vulnpocalypse: https://thevulnpocalypse.com/

  • June 8 · 58 min

    How The Conversation Predicted Our Surveillance Society 50 Years Ago

    Perhaps no film captures the paranoia and anxiety of the 1970s better than The Conversation, Francis Ford Copolla's masterpiece about reclusive surveillance expert Harry Caul, a man who it's safe to say has some demons. Decades before we all agreed to carry tracking and recording devices in our pockets, The Conversation shows us just how invasive and damaging technology can be.

  • June 5 · 36 min

    Shai Hulud Returns, How Attackers are Using AI, and More Weird MSRC Behavior

    We regret to inform you that there are more npm supply chain attacks this week, and a new variant of the Shai Hulud worm is involved. We also talk about the new analysis from Anthropic on a year of data relating to how attackers are using AI in their operations, and the continuing adventures of Microsoft's relationship with security researchers.

  • May 29 · 45 min

    Microsoft Has Forgotten Its Vulnerability Disclosure History

    The recent Nightmare-Eclipse zero day drop and attendant drama has stirred up all kinds of trouble and unfortunately spurred Microsoft to publish a post scolding security researchers for not using the "proper channels" to disclose bugs, threatening legal action, and generally dredging up every hobby horse from the threadbare disclosure debate. Links MSRC post: https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure Decipher story: https://decipher.sc/2026/05/28/the-past-is-always-present-in-vulnerability-disclosure/ Expel event: https://info.expel.com/event-mythos-unhappy-hour.html

  • May 25 · 1 hr 18 min

    Lessons in Resilience, Perseverance, and Leadership With Matt Eversmann

    After being caught in one of the more notorious battles in modern American history, Matt Eversmann's military career has become the stuff of legend. The Battle of Mogadishu, immortalized in the book and movie Black Hawk Down, was a pivotal event in U.S. history and in the lives of Matt and his fellow soldiers. Now retired from the army and focusing on training the next generation of leaders, Matt joins Dennis Fisher to talk about his career, what he's learned from his failures and successes, and how vital resilience and perseverance are for success in any field. Matt's biography: https://thayerleadership.com/team-member/first-sergeant-matt-eversmann/

  • May 22 · 22 min

    Chain Chain Chain of Compromises

    In the spring, a young attacker's fancy turns to supply chain compromises, and this season's crop includes the GitHub breach and the Grafana intrusion, which are connected and trace back to the TanStack supply chain attack and...TeamPCP. Links Grafana attack: https://decipher.sc/2026/05/17/grafana-investigating-token-compromise-and-extortion-attempt/ GitHub breach: https://decipher.sc/2026/05/20/github-confirms-internal-breach/

  • May 19 · 43 min

    What the Data Tells Us About Claude Mythos and Bug Exploitability | Jay Jacobs and Michael Roytman

    Finding a huge pile of bugs with Claude Mythos is great, but the logical next step is figuring out how many of those vulnerabilities are likely to be exploited in the near future. Jay Jacobs and Michael Roytman of Empirical Security join Dennis to talk about how the Exploit Prediction Scoring System can help teams make informed decisions and prioritize patching the most important vulnerabilities. Jay and Michael are pioneers in the data-driven security field and help steer the EPSS effort.

  • May 15 · 53 min

    Solving Hard Security Problems With an Outsider's Perspective | Sravish Sridhar

    Unlike a lot of founders in the industry, Sravish Sridhar hasn't spent his career in the security world. He comes from a background in distributed computing and advanced math, and is a successful entrepreneur who's now bringing that experience to bear at TrustCloud, where he's helping CISOs automate and streamline their compliance programs.

  • May 13 · 38 min

    AI Has a Security Measurement Problem | Gary McGraw

    Few people (if any) have spent more time thinking about and working on the hard problems in security and software than Gary McGraw, and he also happens to have a PhD in cognitive science and computer science and has been studying neural nets and AI systems for 30+ years. Gary joins Dennis to talk about his team's new research into AI security benchmarks, measurement, and bringing a software security approach to LLMs and AI systems. Links BIML report: https://berryvilleiml.com/results/no-security-meter-ai.pdf