Artwork for Decipher Security Podcast
Technology

Decipher Security Podcast

Decipher

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.

  • 370 episodes
  • Updated Friday

Episodes370

  • May 11 · 34 min

    Inside the $285M Drift Protocol Heist | Ari Redbord

    Ari Redbord, Global Head of Policy at TRM Labs, talks about the insane background behind the $285 million Drift Protocol crypto heist, how law enforcement agencies are investigating ransomware-linked cryptocurrency wallets, and how effective sanctions are on cybercrime.

  • May 8 · 41 min

    The Canvas Attack, Ivanti and Palo Alto Exploits, and Dirty Frag

    If we needed any more evidence that the internet was a mistake, this week provided it. We kick things off with a discussion of the Canvas breach that has affected thousands of schools worldwide, then we dig into the disclosure of two new vulnerabilities in Ivanti and Palo Alto Networks products that are actively exploited, and then we talk about a new branded Linux bug called Dirty Frag. Finally, we wrap up with some comic relief from the Everything App. Links Ivanti bug: https://decipher.sc/2026/05/07/ivanti-warns-of-exploited-epmm-flaw-cve-2026-6973/ Palo Alto bug: https://decipher.sc/2026/05/06/845/ Dirty Frag: https://decipher.sc/2026/05/07/new-dirty-frag-linux-bug-emerges/ The viral tweet: https://x.com/DennisF/status/2050682024587845690

  • May 6 · 44 min

    Fighting Cybercrime With Global Intelligence | Will Dixon

    Will Dixon has seen the evolution of cybercrime as both a GCHQ intelligence officer and a private sector executive and analyst, and has seen the way these groups operate up close. He joins Dennis to talk about the ongoing threat from ransomware gangs, how organizations are managing their responses, and what he expects to come next.

  • May 4 · 1 hr 8 min

    The fast16 Mystery, Stuxnet, and the History of Cyber Espionage | Juan Andres Guerrero-Saade

    JAGS joins Dennis Fisher to unpack the complex history of fast16, a highly targeted cyber espionage platform that goes back as far as 2005, many years before Stuxnet, and was deployed against targets in Iran. JAGS has been in the APT hunting game for a long time, and brings his historical perspective and context around the Shadow Brokers leak, Stuxnet ties, and how this discovery changes what we know about the use of these tools. LinksSentinelLabs report: https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/

  • May 1 · 42 min

    cPanel Exploits, Copy Fail, and the History of Branded Bugs

    The security news was out of hand this week, so we had to pick our spots. We start with the nasty cPanel/WHM vulnerability that affects tens of millions of domains in shared hosting environments, then we discuss the Copy Fail Linux bug and its effects before seguing into the delightful history of branded bugs, logos, and parodies. Links Branded bugs and logos: https://io.netgarage.org/logo/

  • April 28 · 50 min

    Defeating Online Scams and Disrupting the Cybercrime Chain | Ariana Mirian

    Ariana Mirian, cofounder of startup Beesafe, joins Dennis to talk about the mechanics of online romance and finance scams, how the scammers draw in victims over weeks or months, and why user awareness isn't the complete solution to the problem. LinksBeesafe AI: https://beesafe.ai/

  • April 24 · 39 min

    The Vercel Intrusion and What is Happening at CISA

    This week we dig deep into the Vercel intrusion that emerged last weekend, how it happened, what the response was, and what the downstream effects may be for defenders. Then we talk about CISA's bizarre delayed response to the Axios npm compromise and what it signals about the agency's capabilities going forward.

  • April 17 · 32 min

    Claude Mythos, Automated Bug Hunting, and AI Eating Everything

    It's been A WEEK. Security news never sleeps, and neither does AI, so Dennis and Lindsey dive into all of the storylines coming from the Claude Mythos and Project Glasswing announcements, how organizations will deal with the coming flood of CVEs and patches, NIST's decision to only enrich specific CVEs going forward, and what could possibly be next on the horizon.

  • April 13 · 55 min

    The Era of AI-Led Vulnerability Research With Tom Ptacek

    Dennis sits down with Tom Ptacek of Fly.io, a veteran security researcher, founder, and observer of the vulnerability landscape, to talk about the recent wave of AI-assisted vulnerability discovery and exploit development, specifically from the use of frontier models such as Claude Mythos. Tom has strong opinions on what's coming and how human researchers and defenders need to respond. Tom's post: https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/

  • April 7 · 33 min

    Mapping the Cybercrime Ecosystem With Andrew Northern of Censys

    The internet is dark and full of terrors, but thanks to folks such as Andrew Northern, a principal security researcher at internet-mapping pioneer Censys, it doesn't have to be, Andrew joins Dennis to talk about the cybercrime ecosystem, getting his start in security on a tiny team with huge responsibilities, and the value of a strong mentor.

  • April 3 · 51 min

    The Rapid Rise of AI Exploit Development and More Axios Compromise Effects

    It's been quite a week in security news, and Dennis and Lindsey dig into the continued effects of the axios supply chain attack, the incredibly fast adoption of AI tools for vulnerability research and what that means for software makers and defenders, and what the future holds for vulnerability research and exploit development. Security Theater in Austin: https://material.security/theater-2026#theater-live-event

  • March 31 · 25 min

    Axios NPM Supply Chain Attack

    Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer's account, the window of exposure for the malicious packages, the behavior of the RAT that's installed on victims' machines, and what the downstream effects may be. Links Huntress post: https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package Socket analysis: https://socket.dev/blog/axios-npm-package-compromised

  • March 27 · 51 min

    RSA Recap: Dancing Robots, AI Everywhere, and the Future of Security

    Fresh off the plane from RSA, Dennis fills Lindsey in on everything she missed (and didn't miss) at this year's conference (0:23), from the insanity of the expo floor (4:06) to the appearance of a line of synchronized robots or spacemen or something (8:18), to some very interesting conversations about the hyper speed of AI malware development and what's coming next for defenders (27:25).

  • March 20 · 43 min

    RSA 2026 Preview

    With the RSA Conference on the horizon, Dennis and Lindsey are here with a preview of the conference's more interesting sessions and keynotes, a discussion of the recent and ancient history of the conference, and a quick game: Is this a security vendor or a prescription drug name?

  • March 18 · 52 min

    Mark Watney Is a Space Hacker in The Martian

    Sure, space pirate is a cool title, but what about space hacker? Way cooler! With the imminent release of Project Hail Mary, Wendy Nather joins Dennis Fisher to dig into the nutrient-rich narrative soil that produced a modern classic that truly epitomizes the hacker ethos. We are the greatest podcasters on Mars!

  • March 13 · 15 min

    Fancy Tools From Fancy Bear, Another Proxy Network Takedown, and A Look Ahead

    This week's news includes a reappearance by an old favorite, APT28, aka Fancy Bear, which is back with some nasty new implants and tools it is deploying against targets in Ukraine (2:10), and we also have another law enforcement disruption of a residential proxy network, this one known as SocksEscort, which had victims all over the globe (7:45). Lastly, we talk about some of the upcoming episodes, including a new hacker movie podcast and our RSA preview that's coming next week. Links APT28 reappears: https://decipher.sc/2026/03/10/apt28-reemerges-with-modern-espionage-arsenal-code-tied-to-2010s-operations/ SocksEscort takedown: https://decipher.sc/2026/03/12/us-europol-crack-down-on-socksescort-residential-proxy-network/

  • March 10 · 46 min

    The Wild, Wild World of Exploits With Caitlin Condon

    The process of developing and deploying exploits is a complex and controversial one and it's often a black box to outside observers. To help shine a light on how this all works, Caitlin Condon of VulnCheck joins Dennis Fisher for a deep dive into the zero day exploit landscape, what goes into exploit development, and what actually qualifies as a functional exploit.

  • March 6 · 19 min

    The Zero Day Landscape, Tycoon 2FA Disruption, and KEVology

    Every day is zero day, and this week we talked about the new Google Threat Intelligence Group report on the zero day exploit landscape in 2025 (2:22) and who's exploiting what, then we discuss Microsoft's disruption of the Tycoon 2FA cybercrime operation (9:51), and finally we talk about the KEVology report from runZero and our new podcast with Tod Beardsley (13:25).

  • March 2 · 47 min

    We Need to Talk About KEV With Tod Beardsley

    Tod Beardsley, VP of security research at runZero and former KEV section chief at CISA, joins Dennis Fisher to talk about the evolution of the Known Exploited Vulnerabilities catalog, how much value defenders should place on a specific bug being in the KEV, and his new KEVology report that breaks down all of the data in the KEV and sifts through it for specific insights for defenders.

  • February 27 · 31 min

    Cisco SD-WAN Zero Day, Google Disrupts Chinese Campaign, and More Cyber on The Pitt

    This week Lindsey rejoins Dennis to talk about the attacks targeting a zero day in Cisco's Catalyst SD-WAN Controller (2:17), Google's disruption of a China-linked cyber espionage campaign targeting telecom infrastructure (6:30), and the new cyber developments on everyone's favorite tech show, The Pitt (13:13)!