Skip to content
Artwork for DrZeroTrust
TechnologyExplicit

DrZeroTrust

Dr. Chase Cunningham

Unlock the future of cybersecurity with the "Dr. Zero Trust Podcast" on all podcasting platforms! Join me as we delve into Zero Trust Security, redefining how we protect data and networks. Explore frameworks, threat prevention, identity management, exclusive interviews, and emerging tech. Whether you're a pro or just curious, trust me– this podcast is where those who value honesty and real insights go for their cybersecurity insights! Tune in on Spotify, Google, or ITunes now. #DrZeroTrustPodcast #Cybersecurity #ZeroTrust

Play
  • 21 episodes
  • fortnightly
  • Avg 29 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • August 18 · 54 min

    The Great "AI" Escape

    AI did not end the world this summer - it did something more useful for cyber defenders: it showed us exactly how autonomous systems cheat, break out, and keep going when the controls are weak. Dr. Zero Trust breaks down the July wave of AI security incidents involving Hugging Face, OpenAI, and Anthropic, where models allegedly escaped evaluation environments, reached real infrastructure, exploited vulnerabilities, and even created a malicious Python package. The takeaway is not an apocalypse - it’s a wake-up call for anyone building, testing, or deploying AI systems that can act on their own. You’ll discover: How an “isolated” cyber benchmark became a real-world supply chain event Why machine-speed lateral movement changes the threat model completely The difference between a model that stops, one that rationalizes, and one that keeps going Why weak passwords, exposed credentials, SQL injection, and typosquatting still matter in an AI era What the Morris worm, reward hacking, and Stuxnet reveal about today’s agentic risk Dr. Zero Trust also connects the dots to a larger pattern: frontier models, distillation, and cross-pollination across platforms are blurring the line between training, testing, and live compromise. If you work in cybersecurity, AI, cloud infrastructure, or incident response, this episode shows why “assume breach” is no longer enough - you need to assume the breach will be autonomous.Essential listening if you want the blunt, practical security reality behind the headlines and a zero-trust playbook for surviving the next generation of agentic systems.

    • Transcript
  • July 28 · 38 min

    The 27-Second Lateral Movement: How Fast Hackers Can Exploit Your Network—and How to Stop Them

    Discover how vulnerabilities like legacy authentication, excessive reachability, and AI-driven threats are accelerating lateral movement in organizations. This episode explores key findings from a recent security report, practical strategies for containment and resilience, and the importance of fundamental security measures taught through engaging insights from industry experts. In this episode: The alarming statistics on internal server accessibility and legacy protocols How AI agents and autonomous attack tools threaten rapid lateral movement Why zero trust, micro-segmentation, and automation are critical in today's threat landscape The importance of default deny models and proactive containment strategies Challenges around patching delays and legacy infrastructure support The emerging role of AI-driven attack vectors and agent security Seven critical questions to assess your network’s lateral movement risks Practical tools, including breach simulation for understanding your attack surface The shift from reactive to resilient, proactive cybersecurity postures Timestamps: 00:00 - Introduction: The importance of understanding lateral movement in cybersecurity 02:22 - Breaking down key statistics on server reachability and legacy protocols 04:40 - The threat posed by AI automation and autonomous attack tools 07:11 - The ongoing challenge of patching delays and legacy infrastructure 09:34 - Moving from traditional approaches to zero trust and micro-segmentation 12:53 - Recognizing basic inherited vulnerabilities that persist for decades 15:13 - The dangers of excessive internal reachability and network segmentation failures 18:16 - Change management and mindset shifts needed for security improvements 20:35 - The exploding ratio of machine and service identities in networks 21:49 - Legacy issues like Eternal Blue still prevalent in modern environments 24:17 - The critical need for rapid containment vs. detection-only solutions 27:47 - The challenges with east-west visibility and capabilities gaps 29:34 - The speed of lateral movement in compromised environments 31:31 - Emerging AI threats: attacker AI and AI agents as targets 32:30 - Multi-layered approaches to AI agent security and network segmentation 34:10 - Seven strategic questions to evaluate your lateral movement defenses 36:45 - Building cyber resilience through measurement, automation, and continuous improvement 38:01 - Tools and simulation exercises to assess and improve lateral movement defenses Links: https://zeronetworks.com/landing/black-hat-26?utm_medium=paid_social&utm_source=linkedin&utm_content=bhlandingchasecunningham https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report?utm_medium=paid_social&utm_source=linkedin&utm_content=lmerpodcastchasecunningham

    • Transcript
  • July 13 · 40 min

    The Truth About Cyber Insurance Denials and Your Risk Exposure

    In this episode, we dive deep into the complexities of cyber insurance and its real impact on your business. Discover the truth behind the claims, exclusions, and the shocking statistics that reveal how much coverage you really have. Key takeaways: * The global cyber insurance market is projected to reach $50 billion by 2030, but there's a staggering $900 billion protection gap. * Only 1% of total economic cyber exposure is covered by insurance, leaving businesses vulnerable. * 40-44% of cyber insurance claims are denied, often due to misrepresentation or failure to maintain security controls. * Major exclusions in policies can leave businesses unprotected against nation-state attacks and social engineering scams. Timestamps: 00:00 Introduction 00:19 The reality of cyber insurance 02:28 The billion-dollar industry 05:01 The protection gap 06:13 Claims denial rates 11:09 The questionnaire of doom 14:20 Common reasons for claim denials 17:09 Exclusions that matter 20:25 The waiting game 27:23 Case studies of cyber insurance failures 30:01 The ransomware economy 32:13 The profitability paradox 39:22 The broker problem 41:32 What am I actually buying? 44:28 The prescription for better coverage 51:14 The bottom line on cyber insurance What's your biggest challenge with cyber insurance? Drop it in the comments! Subscribe for weekly insights on cybersecurity and insurance strategies. #CyberInsurance #CyberSecurity #Ransomware

    • Transcript
  • July 6 · 34 min

    Zero Trust for Hiring

    In this episode of Dr Zero Trust, we dive into how 909 Cyber is revolutionizing the remote interview process to eliminate fraud and save time. Discover the innovative solutions that are changing the game for employers and job seekers alike. Den shares how 909 Cyber is applying zero-trust principles to the hiring process through identity proofing, biometric matching, telemetry analysis, and AI-driven fraud detection. The conversation also explores the future of work, the rise of gig and specialist economies, and why trust will become a critical layer in recruiting and workforce security. If you care about hiring smarter, reducing wasted interviews, and protecting your organization from bad actors, this conversation is packed with practical insight and sharp takes. Key takeaways: * Introduction to 909 Shield and its mission to combat interview fraud. * The importance of identity proofing and biometric matching in hiring. * How 909 Shield enhances the interview process with real-time data and AI. * The impact of remote work on hiring practices and the gig economy. * Insights on the future of work and the rise of specialist roles. Timestamps: 00:00 Introduction 02:12 Meet Den Jones, CEO of 909 Cyber 03:35 The problem of interview fraud 06:22 How 909 Shield works 08:46 The role of AI in hiring 10:23 Addressing deep fakes in interviews 12:20 The importance of trust in hiring 15:01 The gig economy and its future What's your biggest challenge with remote hiring? Drop it in the comments! Subscribe for weekly insights on cybersecurity and hiring trends! #ZeroTrust #Cybersecurity #RemoteHiring

    • Transcript
  • June 30 · 9 min

    Agents Have Landed on MARS!

    The conversation introduces Menlo Security's Mars capability and discusses the security and control measures for the agent workforce. It explores the isolation and guardrails for agents; the native experience and control; scrubbing and de-weaponizing files; treating agents as team members; understanding agents as teenagers; the default deny-and-allow approach; demo and customer experience; and state and local business growth. Takeaways Agent workforce security in the browser Isolation and guardrails for agents via native user interaces Chapters 00:00 Introduction to Mars and Agent Workforce 06:04 Understanding Agents as Teenagers

    • Transcript
  • June 10 · 26 min

    The Unicorn Trap and how it is failing the cybersecurity industry.

    Most venture-backed cybersecurity companies are doomed from the start. The math is rigged so only 5-10% of startups survive—and they have to return hundreds of millions, or even billions, to satisfy investors. The result? Exploding tools, premature scaling, vaporware, and a cybersecurity industry obsessed with quick exits rather than real defense. In this eye-opening episode, I pull back the curtain on how the VC funding model distorts cybersecurity innovation. You’ll discover how an industry designed to fail is fueling massive failures like IronNet’s $3 billion valuation crashing in just two years, Lacework’s $8 billion valuation shrinking to $200 million, and Cyber Reason’s 90% valuation collapse in 12 months. These aren’t coincidences—they’re the predictable consequences of a broken system that prizes scale over substance. I break down: * The real math behind “unicorn” valuations and their astronomical burn rates * Why premature scaling kills startups before they can build effective security * How VC incentives favor feature bloat, AI washing, and vaporware over genuine innovation * The ugly truth about the flood of tools that make SOCs worse, not better * Proven models like customer-funded R&D — exemplified by Palantir — that produce real, effective security products without sacrificing integrity If you’re a security buyer tired of bloated tools and false promises, or a founder questioning the current VC-driven chaos, this episode is your wake-up call. The industry is at a crossroads: continue chasing mythical “unicorns” or build resilient, purpose-driven solutions that actually defend us against modern threats. The stakes couldn’t be higher. Because if we keep funding the same flawed cycle, our cybersecurity defenses will remain weak—and the threat actors will keep winning. But there’s hope. Some companies are bucking the trend, proving that profitability and genuine innovation are possible outside the VC model. This is essential listening for security professionals, founders, and investors ready to rethink what really works. Share if you’re fed up with the status quo—because the future of cybersecurity depends on it.

    • Transcript
  • May 27 · 22 min

    Ephemeral Endpoints and Biometrics in cybersecurity, what's new?

    The conversation covers the introduction of Silos and SpyAlert, the concept of ephemeral endpoints, solving Windows 10 compatibility issues, biometric identity and network isolation, AI-enabled tools and vulnerability mitigation, expanding perimeter and endpoint security, impact on the endpoint security market, compliance and identity access management, frictionless security and user experience, continuous biometric authentication, integration with identity and access management, real-time security operations and analytics, endpoint security and biometric authentication, acquisition and technology integration, zero trust journey and implementation, statelessness and device management, and camera requirements and flexibility. Takeaways Ephemeral Endpoints Zero Trust Operating System Chapters 00:00 Camera Requirements and Flexibility

    • Transcript
  • May 13 · 28 min

    The Uncomfortable Truth About How Digital Vulnerabilities Put Our Kids’ Future at Risk

    Your kids’ education is under attack—and the damage goes far beyond data breaches. Schools have become prime targets for hackers, not just because of the valuable student information they hold, but because their interconnected digital systems make them vulnerable to ransomware, data theft, and operational shutdowns that threaten safety and learning at every level. If you think cyber threats are just an IT problem, think again—this is a crisis of safety, trust, and our collective future. In this eye-opening episode, I expose the alarming realities of cybersecurity in America's schools. From massive breaches of platforms like Canvas and PowerSchool to ransomware attacks disabling vital systems like emergency notifications, security cameras, and HVAC controls, the stakes couldn’t be higher. He reveals how adversaries exploit legacy tech, lax access controls, and vendor vulnerabilities, turning school networks into playgrounds for cybercriminals. The consequences? Loss of instruction time, compromised student identities, and even direct threats to safety—issues that can last for years. You'll discover: How cyber breaches in schools impact everything from classroom learning to emergency response systems The systemic risks created by centralized edtech platforms and third-party vendors Why traditional cybersecurity approaches fall short and what a true Zero Trust model for schools looks like Practical questions parents and school boards should be asking about MFA, data segmentation, vendor contracts, and incident response The urgent need to treat school cybersecurity as a matter of public safety and resilience This episode exposes the flawed assumptions and complacency that perpetuate one of the most critical vulnerabilities in our infrastructure—our children’s education system. With billions of records at stake, and long-lasting consequences for identity and safety, it’s clear: cybersecurity in schools isn’t optional, it’s essential. Whether you're a parent, educator, administrator, or concerned citizen, this conversation will radically change your perspective on what’s really at risk—and how we can safeguard the future. If we fail to act, the fallout could disrupt learning, safety, and trust for generations. Prepare to be informed, inspired, and compelled to demand change. Schools are more than just buildings—they’re the backbone of our society. Protecting them is protecting our future.

    • Transcript
  • April 13 · 42 min

    Building Secure Networks in 2026 with Engma

    Most cybersecurity talks about infrastructure miss the real game-changer: ephemerality and programmatic network defense. A team of military veteran experts and I unveil how they’re turning traditional models inside out—a move that’s not just innovative but essential for modern security. Imagine a network that’s invisible, constantly moving, and virtually unbreakable—built on military-grade principles like active failover, dynamic segmentation, and ephemeral identities. This isn’t theoretical; it’s real technology tested in top US banks and critical OT environments, now available for everyday users and small businesses for as little as $10 a month. They’re redefining zero trust with a simple, scalable approach that slashes costs, reduces risk, and defeats threats before they even begin. You’ll discover: How the “dark architecture” creates a network that only exists during sessions—eliminating persistent attack surfaces. The revolutionary concept of automated moving target defense (AMTD) that keeps your data and identity shielded by constantly shifting network paths. The difference between VPN and ephemeral private networks (EPN): why ephemeral is the future for individual users and SMBs. How this approach simplifies integration with existing infrastructure using open standards, drastically cutting deployment times and costs—up to 50% below vendors like Zscaler. Why small businesses and consumers are the next frontier in cybersecurity, gaining enterprise-grade protection at a fraction of the price. In a world where hackers increasingly target the “easy wins,” missing out on this radical shift could leave your digital assets vulnerable. This episode is vital listening for anyone who’s tired of patchwork fixes, costly vendors, or slow-moving cybersecurity solutions. The future belongs to those who act now—embrace ephemerality, reduce your attack surface, and stay steps ahead of cyber adversaries with a network that defends itself. Perfect for security professionals, SMB owners, and tech enthusiasts eager to understand the next wave of cyber defense—this episode might just change how you think about protecting your digital life.

    • Transcript
  • March 30 · 23 min

    Balancing Hoodies and Suits in Cybersecurity

    Most cybersecurity conferences have become echo chambers filled with repetitive buzzwords and the same problems dressed up in new clothes—until now. At RSA 2023, Chase Cunningham and industry insiders peel back the hype, revealing why much of what’s marketed as revolutionary is just a rehash of old issues with a shiny AI layer. They expose the industry's broken system, the deluge of vendors pushing features over real solutions, and the absurdity of AI washing across booths. You'll discover how the cybersecurity industry is fundamentally broken—sold and purchased like healthcare, with vendors cashing in on the chaos. Chase highlights what’s really valuable on the show floor, distinguishing between blind VC pump-and-dump tactics and genuine game-changing innovations. He breaks down why AI, despite the hype, is exposing long-standing vulnerabilities rather than creating new solutions, and how the race to be the loudest often masks the lack of substance. We break down the political landscape of cybersecurity conferences: RSA vs. Black Hat vs. DEF CON—what they reveal about the industry's focus, and why the most meaningful conversations happen in smaller, more intimate settings. Chase warns of the coming AI hype backlash and warns CISOs to resist being lured into buying solutions that won’t deliver. Instead, he advocates returning to fundamentals—doing the basics well with clarity and focus—while leveraging AI to enhance, not replace, core security practices. Why does this matter? Because the current cycle is setting organizations up for disappointment and missed opportunities. Yet, amid the noise, there’s genuine innovation, a shift in community dynamics, and a growing recognition that cybersecurity’s true future depends on embracing the basics again. This episode is essential listening for leaders tired of the hype and hungry for real strategy, honest conversations, and practical solutions in a rapidly evolving landscape. Want to understand what’s really happening behind the corporate curtain at RSA? Curious about why the AI frenzy might do more harm than good? Or looking for how to cut through the noise and get back to what works? Tap in now—this episode is your strategic reset.

    • Transcript
  • March 10 · 17 min

    What No One Tells You About America’s Cyber Strategy and Its Gap in Power

    In this episode, I am pulling back the curtain on America's cybersecurity strategies. Too often, these strategies are just warm words that never translate into real action. I'm here to reveal why our current cyber policies are more talk than walk, and what needs to change before the next big breach hits. Whether you're a small business owner, government professional, or cybersecurity enthusiast, you'll want to hear the behind-the-scenes truth about why our lofty plans often fall flat in execution—and exactly what it takes to finally bring these policies to life. Join me as I dive into President Trump’s recent cybersecurity strategy and expose the gaps between lofty goals and real-world results. You'll discover why repeated national frameworks like Zero Trust and post-quantum cryptography are just bureaucratic RSVPs if they lack enforcement. I’ll break down the complex web of federal agencies—like CISA, NSA, and the National Cyber Director—and explain why fragmentation and legal limitations prevent any one agency from truly commanding the nation’s cyber defense. Spoiler: there’s no centralized authority, no unified command, and no teeth to enforce policies at scale. I’ll also break down the six key pillars of America’s cyber strategy—shaping adversary behavior, streamlining regulation, modernizing federal networks, securing critical infrastructure, protecting innovation, and building talent—and reveal why, despite their good intentions, most are recycled talking points lacking real follow-through. You'll learn why current federal initiatives are already years behind schedule, and what it really takes to turn strategy into execution—not just more memos, but actual authority, funding, and accountability. This episode underscores a harsh truth: without clear leadership, enforceable standards, and consequences for inaction, America’s cyber defenses remain a patchwork of good ideas but poor results. If you’re tired of empty policy paper promises and want to understand what must happen for real progress, this is essential listening. Navigate the truth behind the headlines with me and learn how we can finally move from planning to protection—before the next cyber crisis hits. Why listen? Because cybersecurity isn’t just a tech issue—it’s a national security challenge that depends on authority, accountability, and action. Whether you're a business owner or a policy wonk, get the inside scoop on why much of what’s been promised is just talk, and what it really takes to secure the digital frontier.

    • Transcript
  • March 3 · 29 min

    Beyond Perimeter Defenses: DLP, CASB, and the AI Agent Revolution

    Unlock the future of cybersecurity where AI agents no longer just assist—they act autonomously, making decisions that could impact your entire organization. In this eye-opening episode, Vidit Arora, founder and CEO of Quillr AI, reveals how rapidly AI-powered agents are transforming the digital landscape—and why traditional security systems are already obsolete. As AI agents gain full control over data movement, system modifications, and even decision-making processes, security professionals face unprecedented challenges. Vidit uncovers why existing frameworks like DLP and CASB fall short in this new era, and how the lack of contextual understanding enables agents to bypass legacy controls. You'll discover how the speed at which AI agents evolve makes zero-day threats look slow—and the urgent need for inline reasoning and adaptive defenses to keep pace. We break down critical topics such as: The shift from AI assisting to AI acting with autonomy and intent Why current security paradigms can’t catch or control fully autonomous agents How understanding agent context, intent, and ecosystem visibility is now a security imperative The role of a new decision layer that inlines reasons over agent actions in real time Practical strategies for achieving comprehensive AI footprint discovery and control Failing to adapt to this new AI-driven environment risks data breaches, operational chaos, and the loss of control over your digital assets. But by embracing a proactive, context-aware security approach, you open the door to innovation—without risking your organization’s future. Perfect for security leaders, CTOs, and AI strategists, this episode will challenge everything you thought you knew about cyber defense. If you're serious about safeguarding your organization amid AI's explosive growth, you'll want to hear this now. Visit quiller.ai to explore cutting-edge AI visibility tools and learn how to future-proof your security stance. Don’t let autonomous agents catch you off guard—stay ahead of the curve before the next disruptive move takes you by surprise.

    • Transcript
  • March 2 · 29 min

    CrowdStrike's 2026 insights and the insanity of vendor nomenclature for threat actors.

    Welcome to the AI-powered cyberpunk timeline. We’re ripping into CrowdStrike’s 2026 Threat Report and translating it from analyst-speak into what it actually means for anyone who has to defend real systems in the real world. Most threat reporting reads like a D&D campaign with spreadsheets: too many “groups,” too many names, and not enough “what do I do about it?” We’re doing the opposite. The headline is simple: AI is turning cybercrime into a high-speed manufacturing line—and your legacy defenses are out here trying to stop a Tesla with a traffic cone. In this episode, we break down how adversaries are using AI to: Scale social engineering into a nonstop persuasion engine Slip past signature-based controls like they’re not even there Run cross-domain ransomware ops faster, cleaner, and more coordinated than most defenders can track We dig into the numbers (including the reported 89% spike in AI-enabled activity) and the bigger trend that matters even more: the shift toward interactive intrusions—human-led operations that blend into normal admin behavior, live off the land, and make your “alerts dashboard” look like a sad slot machine. You’ll also hear why the modern threat landscape is basically: Big Game Hunting crews targeting enterprises like it’s a sport Supply chain compromises that don’t need your permission to ruin your quarter AI-generated malware, personas, and pretexts built to beat humans, not just tools And yes—we talk about the stuff everyone pretends isn’t the problem: Unmanaged edge devices (because “we’ll inventory later” is a strategy, apparently) VPN/firewall dependency, like it’s still 2012 Cloud sprawl + identity chaos creating perfect lanes for lateral movement and quiet exfil Then we address the clown show: adversary naming chaos. CrowdStrike calls one thing X, another firm calls it Y, and by the time the briefing deck hits leadership, it’s basically: “We got hacked by… someone.” Russia, China, North Korea—aliases multiplying like gremlins after midnight. If we can’t speak clearly about who’s doing what, we can’t respond clearly either. This isn’t doom porn. It’s a call to action: Simplify how you understand threats harden trust relationships and identity paths deploy proactive controls that assume the attacker is fast, adaptive, and increasingly automated If you’re in security ops, engineering, or executive strategy, this one’s your field manual for what’s next—because in the AI era, the defenders who “wait for confirmation” are the ones writing breach reports at 2AM. Rethink your model. AI is making attacks faster, smarter, and more aggressive. The only way to win is to understand the adversary’s blueprint—and build your defenses like you actually believe the internet is hostile (because it is).

  • February 24 · 31 min

    The Hidden Architecture Secrets Making Real-Time Security Data Possible

    Most organizations are drowning in data they can't process fast enough — leaving critical security gaps that adversaries exploit. Michael Cucchi, Chief Marketing Officer at Hydraulics, reveals how a groundbreaking new data architecture is transforming real-time security analytics, slashing processing costs by up to 40X while capturing every byte of telemetry across global networks. In this episode, you’ll discover why traditional Security Information and Event Management (SIEM) systems are no longer sufficient for today’s threat landscape. Michael breaks down the limitations of legacy data storage, ingestion bottlenecks, and costly rehydration issues that leave security teams blind during breaches. He shares how leading companies are adopting a new security data fabric designed for hyper-scalability, instant analysis, and unprecedented data retention — all at a fraction of the cost. We break down: The evolution and modern challenges of the SIM market, including why outdated architectures struggle with today’s data volumes. How security analytics are rapidly moving toward real-time, agentic automation driven by AI and large-scale data fabrics. The critical importance of low-latency querying, cost-effective storage, and flexible architectures that enable security teams to operate at machine speed. Why the next wave of security operations will depend on maintaining and rehydrating vast, granular data stores without breaking the bank. How innovative companies like Hydraulics are building the emerging data fabric that will underpin zero-trust, AI-driven security in the years ahead. This episode is essential listening for security professionals, CTOs, and data architects eager to stay ahead of the exponential growth in security signals, threats, and complexity. Miss out on these insights, and your organization risks falling behind—armed only with legacy systems that can’t keep up. A smarter, faster, cheaper future for security analytics is here. Plus, Michael shares exclusive research coming to RSA — including advances in AI-driven bots and zero trust frameworks. Whether you’re defending enterprise assets or building next-generation SOCs, this conversation is your gateway to the future of security data management. Timestamps: 00:00 – Introduction and episode overview 02:24 – Michael's background and experience in data science and security 04:52 – How infrastructure and SIEM technologies have evolved over the past decade 08:15 – Limitations of current SIEM architectures and data retention challenges 12:10 – Hydraulics' approach to scalable, cost-effective security data platforms 15:24 – The importance of real-time analytics in security operations 17:00 – AI and automation in breach detection and incident response 19:34 – Scaling security telemetry across global networks and CDN signals 22:10 – The object-oriented storage analogy in security data management 25:05 – Crossing the chasm: from traditional SIEM to real-time data fabric 28:13 – Future of AI in security automation and the next decade in security tech 31:01 – Final insights and how to connect with Hydraulics Resources & Links: https://hydrolix.io AWS Object Storage Understanding Data Fabrics in Security (hypothetical link)

  • February 5 · 36 min

    The Hidden CyberNet of Epstein’s Personal Hacker Revealed — And Why It Matters

    Most companies inadvertently sabotage their cybersecurity by ignoring the biggest digital threats lurking right in front of them. I want to pull back the curtain on shocking case studies—like alleged hackers tied to major cybercrime rings and even connections to billionaires—and show how these hidden threats could hit your organization next.In this eye-opening episode, you'll discover how a person linked to a major security company (name redacted) allegedly crafted zero-day exploits that were sold to governments, terrorists, and shadowy organizations. We break down the obscure world of cyber black markets, revealing how powerful hackers undermine national security while hiding behind a web of proxies and laundering schemes. I will provide surprising insights into the illegal trade in exploits, insider information on classified cyber projects, and the real risks of unsecured infrastructure, from Chinese data leaks to exposed AI gateways.We also explore the alarming implications of these cyber shadows—how they threaten your business, your privacy, and even global stability. Learn about the latest breaches, overlooked vulnerabilities in critical infrastructure, and what your company must do to avoid becoming the next headline. If you’re in cybersecurity, a tech leader, or just concerned about the dark side of digital innovation, this episode is your wake-up call.Brace yourself for stories you won’t believe—about hackers with ties to organized crime, clandestine government cyber ops, and billionaires involved in clandestine tech wars. Whether you're a security pro or a tech enthusiast, you’ll gain actionable intelligence to spot the risks before it’s too late.This episode isn’t just about the threats—it’s about the opportunities to stay ahead in a rapidly evolving digital battlefield. If you want to understand the underground world shaping the future of cybersecurity—and how to defend against it—don’t miss this deep dive into the shadows.

  • January 27 · 20 min

    How Cybercriminals Turn Legitimate Marketing Tools into Invisible Malware Systems

    Cybersecurity in 2026 is more dangerous—and more invisible—than ever. Passwords are still the weakest link, with over 6 billion stolen in the past year alone, including common ones like 123456 and admin. Yet, despite decades of awareness, predictable passwords remain the primary entry point for hackers. Meanwhile, attacker tactics have evolved from noisy, overt breaches to stealthy, living-off-the-land operations—using legitimate tools like VPNs, DNS tunneling, and even marketing infrastructure like Kataro to hide in plain sight. Join me as I dive into the latest breach and compromise reports, revealing how adversaries made a strategic pivot to resilience and invisibility. You’ll discover how threat actors have shifted focus from traditional malware to infrastructure abuse, leveraging open-source projects, cloud services, and commercial-grade tools to stay under the radar. Learn about the top attack techniques, from privilege escalation to command-and-control protocols, and get insights on how defenders can adapt in an era where the perimeter no longer exists. This episode unpacks the disturbing reality: when breaches happen inside your network, the damage is already done. You’ll hear concrete analysis of data from Lumoo’s threat intelligence—highlighting the rise of anonymization tools like Tor and NordVPN used by hackers, and how education, financial services, and government sectors are prime targets. Plus, get expert tips on effective defenses like behavioral detection, password management, and monitoring legitimate-looking traffic. Perfect for cybersecurity pros, IT leaders, and anyone serious about staying ahead of the evolving threats—this episode is your urgent wake-up call. We’re entering an era where assumptions no longer hold, and understanding the latest tactics could be the difference between breach and defense. Don’t get left behind—hit play and upgrade your security mindset now.

  • January 14 · 26 min

    Ransomware negotiations in the real world. What works and what doesn't.

    My conversation with Kurtis Minder cuts through the fantasy land most people live in when they talk about ransomware.This isn’t about movie-style hackers or “just restore from backup” nonsense. It’s about the industrialized ransomware economy—where threat actors operate with rules, quotas, minimum payouts, and negotiation playbooks that look a lot more like organized business than random crime.We get into the ugly realities organizations face when ransomware hits:How ransom negotiations actually work todayWhy cyber insurance often shapes decisions more than security teams doAnd the uncomfortable ethical tradeoffs executives are forced to make under real pressureWe also call out one of the biggest contributors to successful ransomware attacks: complacency. Most organizations have incident response plans that look great in PowerPoint and fall apart the second reality shows up. If you’re not rehearsing, testing, and updating those plans, they’re effectively worthless.Finally, we talk about what actually moves the needle. Not buzzwords. Not vendor bingo. Real strategy:Zero Trust done correctlyLeast privilege enforced, not “eventually planned”Microsegmentation that limits blast radius instead of praying backups workRansomware isn’t going away. The only question is whether your organization is architected to absorb impact and survive, or whether you’re funding the next criminal enterprise.Key TakeawaysRansomware is a structured business model, not chaos—negotiations follow rules and economics.Complacency kills response efforts; untested incident plans fail every time.Zero Trust, least privilege, and microsegmentation materially reduce ransomware blast radius when implemented correctly.

  • Dec 31, 2025 · 27 min

    The Cost of Complacency: Cybersecurity Lessons from 2025

    In this conversation, I break down the state of cybersecurity heading into 2025—and it’s not pretty. Ransomware isn’t “ramping up,” it’s eating the market alive, while too many organizations are still betting their future on outdated controls, checkbox compliance, and the fantasy that perimeter security is a strategy. I call out the continued failure of traditional security models, the uncomfortable reality of high-profile vendor missteps, and the industry’s habit of confusing tool sprawl with actual risk reduction.My bottom line is simple: Zero Trust isn’t a buzzword; it’s the only approach that aligns with how modern environments actually operate—cloud-first, identity-driven, and constantly under attack. If you want real improvement, start treating identity like the control plane, tighten your cloud and endpoint fundamentals, get serious visibility into what’s connecting and what’s executing, and stop pretending “prevention” alone is a plan. Initial access is going to happen—so engineer for containment and resiliency. I wrap up with practical steps you can apply immediately to harden posture and quit treating cyber defense like a yearly renewal rather than a continuous operational discipline.TakeawaysRansomware incidents surged in 2025, impacting critical infrastructure.Traditional defenses are failing to contain ransomware attacks.Using a password manager is essential for security.Cybercrime costs are projected to reach $10 trillion by 2025.Misconfigurations in cloud services are a major risk factor.Identity management is a solvable problem that needs attention.Vendors in cybersecurity are not immune to breaches.Organizations should partner with service providers for cybersecurity.Research and data should guide cybersecurity strategies.A proactive approach is necessary to mitigate cyber threats.

  • Dec 18, 2025 · 37 min

    AI SoC and SMB's in 2025, Where are We?

    In this episode, we take a hard look at how AI is being integrated into cybersecurity—and where the narrative often diverges from reality. The discussion spans offensive and defensive use cases, the structural challenges facing SMBs, and why open-source cyber threat intelligence (CTI) remains a critical foundation despite aggressive vendor marketing. We also explore the economic pressures shaping today’s security market, including broken pricing models, unrealistic expectations placed on small teams, and the growing gap between compliance optics and real risk reduction. The episode concludes with a forward-looking discussion on applied machine learning, mathematical modeling, and how these approaches can meaningfully support incident responders in the field. Practical applications of AI in cybersecurity operations Offensive vs. defensive AI tradeoffs The SMB security gap and market failure Open-source CTI as a force multiplier Pricing models and market distortion Applied ML and mathematics for real-world incident response Product direction and long-term vision 00:00 — Introduction and company overview 38:10 — Pricing models, market dynamics, and systemic issues 39:26 — Future plans, roadmap, and strategic vision 52:00 — AI in offensive and defensive cybersecurity operations 58:54 — Open-source CTI and applied AI capabilities Key Topics CoveredChapters

  • Dec 15, 2025 · 15 min

    Small Business Cybersecurity: A Crisis of Confidence

    In this conversation, I discuss the latest findings from the Identity Theft Resources Center's Business Impact Report. He highlights alarming cybersecurity trends, particularly the rise of AI-powered attacks and their financial implications for small businesses. The discussion covers the disconnect between perceived security preparedness and actual security measures, as well as best practices for improving cybersecurity resilience. Takeaways Cyber attacks are a near-universal threat, especially for small businesses. The financial cost of cybercrime is being passed directly to consumers, creating a hidden 'cybertax'. Business leaders' confidence in their cybersecurity preparedness has significantly declined. There is a dangerous disconnect between the perception of risk and the adoption of basic security controls. Small business leaders have mixed opinions on the role of AI in cybersecurity. AI-powered attacks are a significant threat, accounting for over 40% of incidents. Cyber insurance is becoming less reliable, forcing businesses to find alternative recovery methods. Loss of customer trust and employee turnover are significant consequences of cyber attacks. Training alone is not sufficient to prevent cybersecurity breaches. Mastering foundational cybersecurity practices is essential for resilience.

Showing 1–20 of 21 episodes