Skip to content
Artwork for Secure AF - A Cybersecurity Podcast
TechnologyBusinessEducation

Secure AF - A Cybersecurity Podcast

Alias Cybersecurity

Think like a hacker. Defend like a pro.

Welcome to the Secure AF Cybersecurity Podcast — your tactical edge in the ever-evolving cyber battlefield. Hosted by industry veterans including Donovan Farrow and Jonathan Kimmitt, this podcast dives deep into real-world infosec challenges, red team tactics, blue team strategies, and the latest tools shaping the cybersecurity landscape.


Whether you're a seasoned pentester, a SOC analyst, or just breaking into the field, you'll find actionable insights, expert interviews, and unfiltered discussions with Alias team members and top-tier guests from across the cybersecurity spectrum.


Stay sharp. Stay informed. Stay Secure AF.

Play
  • 22 episodes
  • weekly
  • Avg 18 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Tuesday · 54 min

    Defcon 2026

    Got a question or comment? Message us here! A recap of DEFCON 2026 featuring the Latest in cybersecurity, hacking, AI, and digital defense. Don't miss the highlights from one of the world's most influential security conferences. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • August 20 · 5 min

    Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders

    Got a question or comment? Message us here! Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • July 8 · 4 min

    Windows BlueHammer Flaw Now Actively Exploited by Ransomware Gangs

    Got a question or comment? Message us here! Ransomware operators are leveraging the BlueHammer privilege escalation flaw to gain SYSTEM-level access and disable security controls. Get the latest insights and response recommendations. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • July 1 · 4 min

    FortiBleed Attacks: Turning Fortinet Firewalls into Credential Stealers

    Got a question or comment? Message us here! FortiBleed is turning perimeter defenses into attack infrastructure. In this episode, we unpack how adversaries exploit FortiOS vulnerabilities, harvest credentials directly from firewalls, and pivot deeper into networks, plus detection strategies, threat hunting tips, and mitigation guidance for SOC teams. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 24 · 5 min

    Arch Linux AUR Compromise – Supply Chain Risks in the Open Source World

    Got a question or comment? Message us here! This #SOCBrief episode explores a recent Arch Linux AUR supply chain compromise, where malicious community packages were used to steal credentials and gain persistence. It highlights the risks of third-party repositories and offers key detection and mitigation strategies for security teams to better protect against similar attacks. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 17 · 4 min

    Qilin Ransomware Exploiting VPN Zero-Days: What SOCs Need to Do Now

    Got a question or comment? Message us here! A single unpatched VPN could be all it takes. Qilin ransomware is actively exploiting VPN zero-days to breach networks and accelerate ransomware deployment. We walk through the tactics, the real risk to your organization, and actionable SOC strategies to stay ahead. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 16 · 43 min

    You're Probably Not Hacked, You're Being Tracked

    Got a question or comment? Message us here! You probably haven’t been hacked, you’ve been tracked. This episode breaks down how ad tech, mobile apps, and data brokers create massive behavioral profiles without ever touching your phone’s security. Learn how tracking really works, why it matters, and what you can actually do about it. 📱👁️📡 Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 10 · 13 min

    The SOC Brief Turns One 🎂 Insights, Stories & Lessons Learned

    Got a question or comment? Message us here! It’s our 1-year anniversary! 🎂 From bite-sized cyber insights to growing a passionate listener base, this episode reflects on the journey, the challenges, and the wins along the way. Expect laughs, lessons, and behind-the-scenes stories you won’t want to miss. 🚀 Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 3 · 5 min

    Kali365 Phishing-as-a-Service: FBI Warns of New M365 Credential Theft Tool

    Got a question or comment? Message us here! The FBI is warning about Kali365, a new phishing‑as‑a‑service tool designed to steal Microsoft 365 credentials and enable account takeovers at scale. In this episode, we break down how it works, why it’s so effective, and what your SOC can do right now to detect and defend against it. 🎧 Tune in now at secureafpodcast.com Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 2 · 37 min

    Incident Response 101: What to Do When You’re Under Attack

    Got a question or comment? Message us here! What actually happens when a company gets hacked? In this episode, we break down real-world incident response, from initial access and ransomware tactics to forensic investigation and common mistakes that make things worse. If your organization had an incident tomorrow, would you know what to do? Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 27 · 4 min

    First Known AI-Powered Zero-Day Exploit: What SOCs Need to Know 🤖

    Got a question or comment? Message us here! In this episode of the #SOCBrief, we dive into the first confirmed case of an AI-powered zero-day exploit. With attackers leveraging AI to discover vulnerabilities, generate exploit code, and bypass defenses faster than ever, this marks a major shift in how threats are developed and deployed. We break down how the attack worked, what made the exploit unique, and the key detection and defense strategies SOC teams need to start adopting now to keep pace with AI-driven adversaries. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 20 · 5 min

    ShinyHunters Breach of Instructure Canvas LMS 📚✏️: Lessons for SOCs on Third-Party Vendor Risks

    Got a question or comment? Message us here! In this episode of the #SOCBrief, we break down the ShinyHunters breach of Instructure’s Canvas LMS and what it means for security teams everywhere. From exploiting a lesser-monitored service to exfiltrating millions of records, this attack highlights the growing risk of third-party vendors and supply chain exposure. We walk through how the breach unfolded, key indicators of compromise, and the practical steps SOC teams can take to detect, monitor, and reduce vendor-related risk before it becomes a crisis. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 19 · 55 min

    Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS Risk

    Got a question or comment? Message us here! When the Canvas LMS went down, thousands of institutions came to a halt, right in the middle of finals. In this episode, we break down what really happened, what data may have been exposed, and why this incident is a wake-up call for every organization relying on SaaS platforms. From vendor risk and contract blind spots to business continuity failures, we unpack the real lessons security leaders need to hear, and what you should be doing right now to prepare for the next breach. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 13 · 5 min

    MuddyWater’s Ransomware Decoy: Iranian APTs Hiding Espionage in Plain Sight

    Got a question or comment? Message us here! MuddyWater is blurring the line between ransomware and espionage... using Chaos ransomware as a decoy to distract defenders while quietly stealing data and maintaining persistence. In this episode, we break down how this tactic works, what SOC teams should watch for, and how to detect the hidden activity beneath the noise. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 6 · 6 min

    Qilin Ransomware’s EDR Killer DLL – How Attackers Are Subverting Defenses

    Got a question or comment? Message us here! Qilin ransomware is deploying a malicious DLL to disable EDR tools before encryption begins. In this #SOCBrief, we break down how the attack works, what to look for, and how defenders can respond. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 5 · 49 min

    AI’s Inflection Point: From Productivity Tool to Existential Risk

    Got a question or comment? Message us here! Artificial intelligence is evolving faster than most organizations, and regulators, are prepared for. In this episode of the #SecureAFPodcast, we sit down with Chris Hood, a veteran technologist and financial industry leader, to explore how AI has evolved from early computing to today’s large language models and agentic systems. We discuss real‑world AI use in highly regulated environments, the benefits and risks of agentic AI, growing concerns around AI security and alignment, and why some experts believe general, and eventually superintelligence, may be closer than many expect, even if we’re not there yet. Along the way, the conversation takes a few intentional detours, as two seasoned technologists reflect on decades of computing history and how past technology shifts help frame today’s AI inflection point. From practical productivity gains to long‑term implications for security, jobs, and society, this conversation goes beyond hype to ask the hard questions security leaders should already be considering. This is Part 1 of a deeper discussion on AI, risk, and the future of human‑machine collaboration. Dive in here: secureafpodcast.com Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • April 29 · 4 min

    Axios NPM Supply Chain Compromise – Lessons for SOCs on Third-Party Risks

    Got a question or comment? Message us here! A malicious Axios NPM package highlights how quickly supply chain compromises can spread through trusted dependencies. In this #SOCBrief, we break down what happened, the risks to downstream applications, and what SOC teams should be monitoring to catch similar attacks early. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • April 22 · 5 min

    Black Shrantac Ransomware – LOTL Tactics and Double Extortion on the Rise

    Got a question or comment? Message us here! A new ransomware group is blending in with legitimate tools. This #SOCBrief breaks down Black Shrantac and how to detect it early. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • April 21 · 39 min

    Think Fast or Get Pwned: How Esports Is Forging Elite Cyber Defenders

    Got a question or comment? Message us here! Cybersecurity success increasingly hinges on cognitive readiness, the ability to spot patterns fast, make the right calls under pressure, and perform amid chaos. On this episode of the SECURE AF PODCAST, Will Arnett sits down with Jessica Gulick, Founder and Commissioner of the U.S. Cyber Games, to discuss why cognitive training is critical, how esports players develop these skills instinctively, and why esports represents an untapped pipeline for elite cyber talent. They also dive into how AI elevates the importance of human cognition—and how security leaders can strengthen SOC morale by leading more like coaches. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • April 15 · 6 min

    Iranian APTs Targeting U.S. PLCs: OT Wake-Up Call for SOCs

    Got a question or comment? Message us here! Iranian-affiliated APT actors are actively targeting U.S. critical infrastructure, specifically PLCs powering essential operations across water, energy, and manufacturing. This #SOCBrief breaks down the latest CISA alert, how attackers are exploiting OT environments, and what security teams need to be watching for right now. From key indicators to practical defense strategies, this is your wake-up call to treat OT as a high-value target. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
Showing 1–20 of 22 episodes