Skip to content
Artwork for Phillip Wylie Show

Phillip Wylie Show

Phillip Wylie

The Phillip Wylie Show is a premier cybersecurity podcast and media source for offensive security professionals. Hosted by Phillip Wylie, globally recognized ethical hacking expert, keynote speaker, and co-author of The Pentester Blueprint, the show features elite red team operators, penetration testers, and security leaders sharing real-world tradecraft, advanced tactics, career strategy, and insights on AI-driven cyber threats.

Play
  • 22 episodes
  • weekly
  • Avg 32 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S4 · E38
    Yesterday · 31 min

    Drones, RF, and the Hacker Mindset with Luke Canfield

    Luke Canfield came up the way a lot of hardware hackers do, the geeky kid in high school everyone came to when the school's computers broke, tinkering with Windows XP and war driving with homemade Yagi antennas built out of Pringles cans. That fascination with the hardware side never left him, and today he runs Reconnaissance Drone Consulting, teaching people about a threat surface most of the security world still isn't looking at. Phillip and Luke met at KernelCon, and this conversation is a wide tour through the corners of security that live outside the usual enterprise conversation. They get into the resurgence of war driving and how a headless Kali Pi has replaced a car full of gear, why AI is reshaping RF and CTF competitions and what that means for people who still want to learn things manually, and Luke's real focus, drones as a multi-domain problem spanning the cyber, operational, and physical. From there it opens up into the stuff that makes you rethink physical security entirely, the six-week drone iteration cycle coming out of Ukraine and how much of it ends up freely available online, why the cartels have run in-house drone design teams for over a decade, prison contraband as the biggest domestic misuse case, and the simple reason nobody looks up - as Luke puts it, humans evolved to avoid being eaten by big cats, not big birds. He also shares his current build, an open source unmanned ground vehicle named Tortuga, made from two donated power wheelchairs, that's headed into Texas cattle pastures to spot parasite outbreaks with thermal imaging. ========================= Connect with Luke Canfield:LinkedIn: https://www.linkedin.com/in/luke-a-canfield/ ========================= Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie

  • S4 · E37
    September 22 · 31 min

    From Law Degree to AI Cyber Defense with Zack Korman

    Zack Korman came into cybersecurity from about as far outside the field as you can get, a UK law degree and a master's in law and finance, and he now spends his days on the AI defense problems most of the industry is still catching up to. His outsider path is exactly what makes his take on the current AI moment worth hearing. Based in Norway, Zack got into code to win an argument with a professor, worked his way up to running a media company's tech department, then spent four and a half years as CTO of an Oslo cybersecurity startup building AI phishing simulations and AI insider threat detection. That work pulled him deep into the defensive side of security and into a conviction that detection is one of the most underserved areas of the field. Phillip and Zack get into why the "thousand crap alerts" model of detection is broken, the blind spots that let obvious insider threats slip past a SOC that was never even receiving the data, and Zack's work on AI agent security, including the malicious MCP server he built to prove how completely an agent can exfiltrate a company. From there the conversation turns to the thing Zack has become known for online, pushing back on inflated AI risk claims, the fallout from the Hugging Face incident, and why so many of the loudest warnings about AI in cybersecurity are coming from people who have never worked in security. They also cover frontier versus local models, why smaller models could reshape defensive work, model guardrails and offensive testing, and Zack's straightforward advice for anyone trying to fold AI into their day to day. ========================= Connect with Zack Korman: LinkedIn: https://www.linkedin.com/in/zacharyakorman/ X: https://x.com/ZackKorman ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with Suzu Labs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E36
    September 15 · 42 min

    Cloud Security, Shadow IT, and Breaking Into the Field with rekdt

    Most advice about breaking into cybersecurity tells you to follow the path. rekdt makes the opposite case: the path is exactly what makes you look like everyone else. In this episode he shares a candid, sometimes contrarian view of the field, shaped by nearly two decades in it. rekdt runs a cloud security tower for a large enterprise operating across multiple clouds, and he came up through the professional cloud world during his time at AWS. He is also a longtime fixture in the hacker community, volunteering with the DEF CON Social Engineering Community and helping out at Red Team Village. His start in tech goes back to a teenage fascination with dial-up, the piracy and IRC scene, and picking apart malicious code on early MySpace pages, before a winding route through bartending and help desk work led him into engineering and eventually security. In this episode, rekdt and Phillip get into why the most interesting security conversations happen at cloud and developer conferences rather than security echo chambers, how cloud and containers upended traditional defenses, and why shadow IT and vibe coding are making things harder. rekdt explains why cybersecurity is really a people problem, what actually makes a candidate stand out when everyone has the same resume, and why he sometimes asks people why they want to get into security at all. He closes with honest, practical advice on building a career with an actual plan instead of just chasing the title. ========================= Connect with rekdt: https://x.com/rekdt ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with Suzu Labs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E35
    September 8 · 33 min

    From Cyber Warfare to AI-Powered Defense with Dave Kennedy

    Dave Kennedy was a skeptic. After 28 years in the field, he had heard every claim about the next technology that was going to change cybersecurity, and he assumed AI was more of the same. Then it changed his mind, and now he is building some of the most advanced defensive AI in the industry. Dave is the founder of TrustedSec and Binary Defense. He got his start on the military intelligence side as a U.S. Marine in cyber warfare. He is a well-known name in the cybersecurity community through his work on BackTrack Linux, the Social-Engineer Toolkit, and Metasploit. Dave is also, by his own description, obsessed with cybersecurity as both a career and a hobby - he can't get enough of it. In this episode, Dave breaks down how AI has re-energized his work and, in his words, made this feel like the early 2000s all over again. He walks through Night Beacon, the AI system his team built to transform the security operations center, and explains why they train their own models instead of relying on frontier models, how they keep a human in the loop for every final determination, and why his teams now ship more than a million lines of code a week. Phillip and Dave get into what AI means for offensive work at TrustedSec and Binary Defense, concerns about autonomous hacking and cheaper zero days, and why Dave believes AI will create more work in cybersecurity rather than eliminate it. ========================= Connect with Dave Kennedy: https://www.linkedin.com/in/davidkennedy4 https://x.com/HackingDave https://binarydefense.com https://trustedsec.com ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with Suzu Labs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E34
    September 1 · 35 min

    Vulnerability Research, AI Slop, and Why Fundamentals Still Win with Stephen Sims

    AI can now hand someone a working Linux kernel privilege escalation exploit, even if that person cannot explain a single line of how it works. Stephen Sims joined the show to talk about what that shift means for offensive security, and why the fundamentals matter more now, not less.Stephen is the curriculum lead for SANS Institute's Offensive Operations program, where he has spent more than 15 years as an author and instructor, and he is a co-founder of Off by One Security. He is a longtime exploit developer and vulnerability researcher who came up through game hacking, network engineering, and years of binary exploitation, reverse engineering, and weaponizing bugs in browsers and the kernel.In this episode, Stephen and Phillip get into how AI is reshaping vulnerability research and exploit development. Stephen explains why human validation is still doing the heavy lifting behind the big vulnerability-count headlines, how AI tends to overstate or understate severity, and why so many submissions are now AI slop or duplicates. He makes the case that logic bugs remain the hardest thing for AI to find, walks through his roadmap for anyone serious about learning exploit development, and shares why he tells students to do the work manually before letting AI do it for them. Stephen also offers grounded advice for breaking into the field, from building a real technology foundation first to staying curious and paying your dues, and gives his honest read on where the opportunity is heading. ========================= Connect with Stephen Sims: LinkedIn: https://www.linkedin.com/in/stephen-sims-2788091/ X: https://x.com/Steph3nSims Off by One Security: https://offbyonesecurity.com/ YouTube: https://www.youtube.com/@OffByOneSecurity ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with Suzu Labs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E33
    August 25 · 29 min

    Purple Teaming with Sarah Hume: Turning Threat Intelligence Into Actionable Testing

    Penetration testing tells you where the vulnerabilities and misconfigurations are. Purple teaming asks a different question: when an attacker is actually operating inside your environment, what can your tools see, and what slips right past them? Sarah Hume has built her career around that second question. Sarah leads the Purple Team program at Security Risk Advisors. Her path into cybersecurity started with a single week at a summer camp at Dakota State University, which her dad talked her into against her wishes and which ended up changing everything. She went on to study cybersecurity at Penn State and began her career in network, physical, and OT/ICS penetration testing before moving into purple teaming as a red operator and eventually leading the practice. In this episode, Sarah breaks down how her team runs purple teams at scale, roughly 200 a year, working through TTPs across the full attack chain alongside a client's blue team. She explains why she favors smart automation over fully automated testing, how her team builds detections that hold up instead of breaking on a single command string or file hash, and why remediation only matters if it is actionable. She also covers living off the land binaries, her grounded take on AI in offensive testing, and real advice for breaking into the field, from home labs and certifications to taking down imposter syndrome and building the communication skills that separate a good tester from a useful one. ========================= Connect with Sarah Hume: LinkedIn: https://www.linkedin.com/in/sarah-hume1 ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with @Suzulabs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E32
    August 18 · 41 min

    From English Teacher to OSINT Investigator: Lindsey Yagi-Hatake on Breaking Into Cybersecurity

    In under a year, Lindsey Yagi-Hatake went from teaching English in a public school classroom to working as a professional OSINT investigator. Her path into cybersecurity did not start with a certification or a computer science degree. It started with survival. Lindsey spent six years as a public school English teacher and holds a master's degree in education administration along with certifications in teaching English as a second language, where she specialized in helping immigrant students adjust to life in a new country. That background in language, culture, and patient instruction shapes how she approaches her work today as an OSINT investigator and privacy manager at Decisive Resources, where she works alongside Mishaal Khan. In this episode, Lindsey shares the full story of how she broke into the field. After becoming a survivor of domestic violence in 2024, she found herself being digitally stalked and geolocated, and when the systems meant to protect her fell short, she taught herself open source intelligence to document what was happening. She talks about the gatekeeping she ran into early on, the moment she spent her last $500 on a DEF CON badge, and how the community at Noob Village and mentors like Mishaal Khan and Chadd Watson changed everything. She also shares hard-won advice for anyone trying to break in today. This is a conversation about grit, community, digital safety advocacy, and what it really takes to get into cybersecurity in today's job market. ========================= Connect with Lindsey Yagi-Hatake: LinkedIn: https://www.linkedin.com/in/lindseyhatake/ ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with Suzu Labs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E31
    August 11 · 23 min

    AI, Automation, and the Future of Penetration Testing with Herman Zubenko

    How is AI changing penetration testing, bug bounty hunting, and offensive security? In this episode of The Phillip Wylie Show, Phillip sits down with Herman Zubenko to explore how artificial intelligence and automation are transforming the way security professionals discover and validate vulnerabilities. Herman shares his unconventional journey from quality assurance and software development into cybersecurity, including how having one of his own accounts compromised led him to investigate the incident with AI and eventually begin using AI for bug bounty research. Phillip and Herman discuss AI-assisted penetration testing, continuous security testing, open and local models, the importance of keeping humans in the loop, and why AI is more likely to enhance penetration testers than replace them. They also discuss how aspiring cybersecurity professionals can use AI to accelerate their learning while still developing the technical fundamentals needed to understand how systems, applications, and vulnerabilities actually work. ========================= Connect with Herman Zubenko: LinkedIn: https://www.linkedin.com/in/herman-zubenko/ Syntetisk Tech Limited website: https://syntetisk.tech/ ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with @Suzulabs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E30
    August 4 · 27 min

    From First-Generation Graduate to DEF CON Speaker: Moo's Cybersecurity Journey

    In this episode of The Phillip Wylie Show, Phillip welcomes cybersecurity community member Moo for an inspiring conversation about breaking into cybersecurity, building a career through persistence, and giving back to others along the way. Moo shares his unconventional hacker origin story, from being inspired by *The Matrix* and DEF CON videos as a teenager to eventually speaking at DEF CON and earning his first National Cyber League challenge coin. Along the way, he discusses the value of internships, apprenticeships, mentorship, and exploring different areas of cybersecurity before settling on a career path. Phillip and Moo also discuss the importance of community, continuous learning, and why cybersecurity conferences like DEF CON can be life-changing for newcomers. Whether you're a student, career changer, or experienced security professional, this episode offers practical advice and plenty of encouragement for anyone looking to grow in cybersecurity. ========================= Connect with Moo: LinkedIn: https://www.linkedin.com/in/munirmuhammad/ ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with @SuzuLabs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/ ========================= Podcast Music by Syntax976 ========================= LinkedIn: https://www.linkedin.com/in/brandon-prince-27a0ab51/ X: https://x.com/syntax976

  • S4 · E29
    July 28 · 27 min

    Casey Smith (SubTee): Living Off the Land, Deception Technology, and the Evolution of Offensive Security

    In this episode of The Phillip Wylie Show, Phillip Wylie sits down with offensive security researcher, educator, and entrepreneur Casey Smith (SubTee) to discuss his journey into cybersecurity, the evolution of offensive tradecraft, and why deception technology is becoming one of the most effective defensive strategies in today's threat landscape. Casey shares how he transitioned from systems administration into security through application testing and enterprise security projects before becoming widely recognized for his pioneering research into Living Off the Land Binaries (LOLBins). The conversation also explores how Windows security has evolved over the years, the impact of application whitelisting, and why modern defenders should be thinking differently about detection. The discussion wraps up with Casey's latest venture, where he is helping organizations leverage deception technologies while mentoring the next generation of cybersecurity professionals. ========================= Connect with Casey Smith: X: https://x.com/_subTee GitHub: https://github.com/AlloySecureGroup ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with @SuzuLabs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/ ========================= Podcast Music by Syntax976 ========================= LinkedIn: https://www.linkedin.com/in/brandon-prince-27a0ab51/ X: https://x.com/syntax976

  • S4 · E28
    July 22 · 27 min

    The Future of Detection Engineering with Alex Hurtado

    Detection engineering doesn't always get the attention it deserves, but it's one of the most important parts of a mature security program. In this episode of The Phillip Wylie Show, Phillip Wylie is joined by detection engineer and content creator Alex Hurtado to discuss why this growing specialty is becoming essential for modern security teams. Alex shares how she went from monitoring enterprise networks early in her career to helping organizations improve their detection capabilities, tune SIEM platforms, and build stronger security operations. She also explains what detection engineering actually involves, why it's much more than writing detection rules, and how AI is changing the way defenders work. Phillip and Alex also discuss the importance of collaboration between offensive and defensive security teams, why custom detections outperform out-of-the-box rules, and how sharing knowledge through content creation benefits both individuals and the cybersecurity community. Whether you're interested in blue team operations, offensive security, or simply exploring different cybersecurity career paths, this episode offers practical advice and a behind-the-scenes look at one of the industry's fastest-growing roles. ========================= Connect with Alex Hurtado:LinkedIn: https://www.linkedin.com/in/hurtadoalexandra/YouTube: https://www.youtube.com/@DetectionDispatch_AlexsVersion========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with @suzulabs https://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/ ========================= Podcast Music by Syntax976 ========================= LinkedIn: https://www.linkedin.com/in/brandon-prince-27a0ab51/ X: https://x.com/syntax976

  • S4 · E27
    July 15 · 30 min

    From Curiosity to Zero Days: Milton Valencia (wetw0rk) on Exploit Development, Research, and Giving Back

    In this episode of The Phillip Wylie Show, Phillip Wylie sits down with offensive security researcher Milton Valencia, better known in the cybersecurity community as wetw0rk. Known for his exploit development research, educational content, and commitment to mentoring others, Milton shares the remarkable journey that took him from a curious student fascinated by hacking to discovering zero-day vulnerabilities and working on elite offensive security teams. Milton discusses overcoming adversity, breaking into the industry without a traditional path, earning certifications like the OSCP, finding his first security roles, and ultimately building a career centered around vulnerability research and exploit development. Along the way, he emphasizes the importance of curiosity, persistence, and helping others succeed. The conversation also explores the future of offensive security, the growing role of AI in reverse engineering, why exploit development remains a valuable specialty, and how aspiring researchers can get started today. If you enjoyed this episode, check out Milton on Season 3 Episode 19 of Simply Offensive @Suzulabs. ========================= Planning to attend Black Hat USA 2026? Use my code PHILLIPWYLIE to receive $200 off a Briefings Pass or $100 off a Business Pass. Register here: https://blackhat.com/us-26/registration.html?_mc=sm_social_phillipwylie Black Hat invited me to attend this year's event and sponsored my conference pass. ========================= Connect with Milton Valencia: LinkedIn: https://www.linkedin.com/in/milton-wetw0rk/ Blog: https://wetw0rk.github.io/ YouTube: https://www.youtube.com/@wetw0rk7 ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= Sponsored by Suzu Labs ========================= All the ways to connect with @Suzulabs https://suzulabs.com https://x.com/suzulabs https://www.linkedin.com/company/suzu-labs/

  • S4 · E26
    July 7 · 32 min

    From BBS to Mastering Red Team Operations with Mike Ortiz

    Mike Ortiz joins Phillip Wylie to discuss his journey from the early BBS and IRC days to the U.S. Marine Corps, global defense contracting, and ultimately becoming a red team operator specializing in adversary emulation and red team engineering. Along the way, Mike shares how his background in networking and enterprise infrastructure helped shape his approach to offensive security and why understanding both attack and defense is critical for today's cybersecurity professionals. The conversation explores the differences between penetration testing and red teaming, why "assume breach" exercises provide greater value for mature organizations, and how modern threat actors operate with patience, stealth, and persistence. Mike also explains how cloud automation has transformed red team infrastructure and introduces Red Stack, his open-source project that simplifies deploying professional red team environments for training and research. ========================= Connect with Mike Ortiz: LinkedIn - https://www.linkedin.com/in/mike-ortiz-redsec Red Stack: https://github.com/BaddKharma/redStack ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie

  • S4 · E25
    July 2 · 44 min

    From Phone Phreaking to Cloud Security: Jason Faulhefer's Cyber Journey

    In this episode, Jason Faulhefer shares his hacker origin story, discusses his innovative threat intelligence platform Threat Spire, and explores the evolution of cybersecurity from early phone hacking to modern cloud and OT security. ========================= Connect with Jason Faulhefer: LinkedIn - https://linkedin.com/in/jasonfaulhefer X - https://x.com/jasonfaulhefer ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie ========================= I'm excited to share that I'll be attending Black Hat USA 2026 this August in Las Vegas. Every year, Black Hat brings together some of the best security researchers, practitioners, vendors, and industry leaders. It's one of my favorite events because there's always something new to learn, whether it's cutting-edge research, emerging attack techniques, AI security, offensive security, or conversations with people pushing our industry forward. I'm looking forward to: - Attending Briefings and learning from leading researchers Catching up with friends and colleagues across the security community - Meeting new people who are passionate about cybersecurity - Seeing the latest innovations from vendors and startups If you've been considering attending, now is a great time. Use my code PHILLIPWYLIE to receive $200 Off a Briefings Pass or $100 Off a Business Pass. Register here: https://blackhat.com/us-26/registration.html?_mc=sm_social_phillipwylie Thanks to @BlackHat for inviting me to attend this year's event and sponsoring my pass. I hope to see you there!

  • S4 · E24
    June 23 · 58 min

    Ridge Security in the Real World: An Offensive Security Practitioner's Perspective

    ## How AI-Powered Penetration Testing Is Transforming Security Validation with Andy Simpson**Sponsored by Ridge Security**In this sponsored episode of The Phillip Wylie Show, Phillip Wylie welcomes Andy Simpson, founder of Cipher Security, for an in-depth discussion about the future of penetration testing, continuous security validation, API security, and the growing role of AI in offensive security.What makes this conversation unique is that Andy is not a Ridge Security employee. As a cybersecurity consultant and penetration testing practitioner, he evaluated multiple automated security testing platforms before selecting Ridge Security to help scale and enhance his team's testing capabilities.Drawing on decades of experience in IT, infrastructure, executive leadership, and offensive security, Andy shares his journey from working at IBM to building a successful offensive security consultancy serving organizations throughout Australia and New Zealand.The conversation explores the challenges facing modern security teams, including expanding attack surfaces, API security risks, infostealer-driven attacks, limited security resources, and the need to continuously validate security controls. Andy also demonstrates how automation and AI-driven testing are changing the way organizations identify and validate risk.## Topics Covered* Andy Simpson's cybersecurity origin story* From IBM engineer to offensive security consultant* The evolution of penetration testing* Common shortcomings in traditional API assessments* Continuous Threat Exposure Management (CTEM)* Vulnerability validation versus vulnerability identification* Automated penetration testing at scale* Attack surface management## Key Takeaways* Annual penetration testing is often insufficient for today's threat landscape.* Organizations need continuous validation of their attack surface and security controls.* API security remains one of the most overlooked areas of cybersecurity.* Security teams must focus on validating risk rather than simply identifying vulnerabilities.* Automation helps security teams scale without sacrificing visibility.* Generative AI is enabling deeper testing of business logic and application workflows.* Human expertise remains critical, but AI-powered testing is becoming an important force multiplier.* Attackers are increasingly leveraging stolen credentials and authenticated access paths, making continuous testing more important than ever.Connect with Andy Simpson:Andy's LinkedIn: https://www.linkedin.com/in/andy-simpson-nz/Cipher Security website: https://ciphersecurity.co.nz/## Episode SponsorThis episode is sponsored by Ridge Security.Connect with Ridge Security:Ridge Security website: https://ridgesecurity.aiGet a free RidgeBot Demo: https://ridgesecurity.ai/demo-request/ Ridge Security LinkedIn: https://www.linkedin.com/company/ridge-security/posts/?feedView=allRidge Security provides automated penetration testing and security validation solutions that help organizations continuously identify, validate, and prioritize security risks across networks, web applications, APIs, and cloud environments. During this episode, Andy shares his firsthand experience using Ridge Security's platform as part of his offensive security practice. ## Connect with Andy SimpsonConnect with Andy on LinkedIn to learn more about offensive security, API testing, threat exposure management, and the future of AI-powered security testing.## Listen, Subscribe, and ShareEnjoyed the episode? Subscribe to The Phillip Wylie Show, leave a review, and share this episode with your network to help others learn about the future of penetration testing and security validation.#ThePhillipWylieShow #Cybersecurity #PenTesting #OffensiveSecurity #APISecurity #AI #ArtificialIntelligence #CTEM #ThreatExposureManagement #RidgeSecurity #SecurityTesting #EthicalHacking #CyberDefense #InfoSec #CyberRisk

  • S4 · E23
    June 17 · 30 min

    From Hacker to Medical Device Pentester: Sean Satterlee on Securing Life-Critical Technology

    What happens when hacking moves beyond computers and into devices that can keep people alive? In this episode of The Phillip Wylie Show, Phillip Wylie welcomes Sean Satterlee to discuss the rapidly growing field of medical device security. Sean explains how security researchers evaluate connected healthcare technology, the skills needed to transition into hardware hacking, and why traditional pentesting knowledge is still incredibly valuable in the world of embedded systems. From Wireshark and wireless protocols to JTAG, UART, and hardware analysis, this conversation provides a practical roadmap for cybersecurity professionals interested in expanding their offensive security skillset. ========================= Connect with Sean Satterlee: LinkedIn: https://www.linkedin.com/in/seansatterlee/ ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie

  • S4 · E22
    June 9 · 23 min

    From Mischief to Mastery: Christian Gonzalez's Cybersecurity Journey

    In this episode of The Phillip Wylie Show, Phillip sits down with longtime friend, former student, and offensive security professional Christian Gonzalez. Christian shares his journey from curious teenager and network engineer to penetration tester, mobile application security specialist, and AI security researcher. The conversation explores career growth, certifications, AI security, and how aspiring pentesters can stay relevant in an increasingly competitive cybersecurity landscape. ========================= Connect with Christian Gonzalez: LinkedIn: https://www.linkedin.com/in/christian-g-672104160/ Educational AI Pentesting Lab: https://www.aipwn.me/ ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie

  • S4 · E21
    June 2 · 32 min

    Creating Content That Matters: Cybersecurity, Authenticity, and Building Your Brand with Eva Benn

    In this episode of The Phillip Wylie Show, Phillip Wylie welcomes back cybersecurity leader, content creator, and self-described "Cybersecurity Bestie," Eva Benn. Eva shares her journey from growing up in rural Bulgaria with no access to technology to becoming a cybersecurity leader, red team professional, and influential content creator. The conversation explores how cybersecurity professionals can leverage content creation to educate others, grow their careers, and make a meaningful impact on the community. Rather than focusing on followers or personal branding, Eva discusses why successful content creation starts with helping others. She offers practical advice for aspiring creators, explains how she built her Security Mondays series, shares lessons learned from producing cybersecurity content, and discusses the importance of authenticity in an AI-driven world. ========================= Connect with Eva Benn: LinkedIn: https://www.linkedin.com/in/evabenn/ YouTube: https://www.youtube.com/@evabennofficial Instagram: https://www.instagram.com/evabennofficial/ ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie

  • S4 · E20
    May 26 · 27 min

    Jeremiah Grossman: The Future of Vulnerability Management

    In this episode of The Phillip Wylie Show, Phillip Wylie sits down with legendary application security pioneer and entrepreneur Jeremiah Grossman to discuss the evolution of web security, vulnerability management, cyber insurance, AI-driven software development, and the future of offensive security.Jeremiah shares his hacker origin story, from hacking his ISP as a teenager to discovering vulnerabilities in Yahoo Mail during the early days of the web. That experience eventually led him to Yahoo and later to founding WhiteHat Security, one of the first SaaS-based web application security companies.The conversation dives deep into how application security evolved from manual testing and early vulnerability scanners into scalable AppSec programs, as well as why modern vulnerability management is still fundamentally broken. Jeremiah explains why only a tiny percentage of CVEs ever lead to real financial loss and how his latest company is approaching vulnerability prioritization differently. ========================= Connect with Jeremiah Grossman: LinkedIn: https://www.linkedin.com/in/grossmanjeremiah Website: https://www.jeremiahgrossman.com Root Evidence: https://www.rootevidence.com ========================= Connect with your host, Phillip Wylie: https://linkedin.com/in/phillipwylieX https://x.com/PhillipWylieInstagram https://www.instagram.com/phillipwylie Chapters 00:00 Introduction to Content Creation Journey 02:15 Eva's Hacker Origin Story 05:03 Career Advice for Aspiring Cybersecurity Professionals 06:19 The Importance of Skills Over Certifications 07:44 Motivation Behind Content Creation 10:00 Navigating Misinformation in Cybersecurity Education 12:57 The Role of AI in Content Creation 13:41 Mindset Shifts for New Content Creators 16:38 Types of Content and Finding Your Niche 18:20 The Importance of Experience in Content Creation 20:41 Balancing Structure and Authenticity in Content 24:44 Equipment Recommendations for Beginners 28:18 Final Thoughts on Content Creation 31:44 Phillip Wylie Show Outro

  • S4 · E19
    May 19 · 32 min

    Hacking Then and Now: Ed Skoudis on AI, Pen Testing, and the Future of Cybersecurity

    In this episode of The Phillip Wylie Show, Phillip Wylie sits down with legendary security expert Ed Skoudis to discuss his hacker origin story, the evolution of penetration testing, and how AI is transforming offensive security. Ed shares how he got started hacking on early home computers like the Commodore VIC-20 and Timex Sinclair 1000, his journey into professional penetration testing, and the early days of DEF CON and the cybersecurity industry. The conversation also dives deep into AI-assisted penetration testing, vulnerability discovery, the future of CTFs, certifications, home labs, and what aspiring hackers should focus on to succeed in today’s rapidly changing landscape. From classic hacking stories to cutting-edge AI research, this episode is packed with insights for anyone interested in ethical hacking, red teaming, and the future of cybersecurity. ========================= Connect with Ed Skoudis: LinkedIn: https://www.linkedin.com/in/edskoudis Website: https://www.counterhack.com/ SANS Holiday Hack Challenge: https://www.sans.org/cyber-ranges/holiday-hack-challenge ========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylie X: https://x.com/PhillipWylie Instagram: https://www.instagram.com/phillipwylie

Showing 1–20 of 22 episodes