Artwork for The Cyber Threat Perspective
Technology

The Cyber Threat Perspective

SecurIT360

Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.

brad@securit360.com

  • 20 episodes
  • Updated Friday

Episodes20

  • Friday · 22 min

    Episode 189 | OWASP Top 10 Part 4: Cryptographic Failures

    Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them? In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compromise, why platforms like Security Scorecard and BitSight inflate their severity anyway, and where genuine cryptographic risk actually lives. Jordan also walks through a real penetration test finding: a JSON Web Token signed with HS256, an exposed configuration backup sitting on the web server, and the signing secret that turned a standard user into an administrator. In this episode: - Why A04 dropped on the OWASP Top 10 without becoming less important - The difference between exploitable risk, hygiene risk, and brand reputational risk - An honest take on Security Scorecard and BitSight scores — what they measure, what they miss, and why a perfect score can coexist with a weak password policy and no MFA - The two halves of A04: data in transit (TLS/HTTPS, integrity, tampering) and data at rest (secure storage of credentials, PII, and payment data) - What a JWT actually is, and why pen testers love pulling them apart - Real pen test story: exposed config backup → leaked JWT secret → signature tampering → privilege escalation to admin - Broken server-side signature validation and other improperly implemented cryptography - Why MD5 and SHA-1 still show up for password storage 20 years too late — and what to use instead (Argon2, scrypt, bcrypt) - HSTS, secure renegotiation, and certificate expiration as A04 subcategories - The coffee shop scenario: the full chain of conditions required to exploit SWEET32 — including roughly 250 GB of captured traffic — and why no one has ever documented it happening in the wild - Why a decade-plus-old vulnerability in your environment says more about your vulnerability management program than about your crypto - Quantum computing: how today's theoretical attacks may not stay theoretical The takeaway: classify your data, choose modern algorithms, retire deprecated protocols, and keep a functioning vulnerability management program. Not because a threat actor is sitting in your local coffee shop waiting to derive your session key — but because leaving decade-old findings in place is a signal about everything else you might be missing. Next up: OWASP A05, which Brad promises is way cooler than A04. Blog: https://securit360.com/blog/ Podcast: https://securit360.buzzsprout.com/ YouTube: https://www.youtube.com/@SecurIT360 Contact: https://securit360.com/contact/ Have a topic you want us to cover? Send it our way. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • July 24 · 27 min

    Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

    Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you. Brad and Jordan cover both sides of supply chain risk: the trusted third-party applications you deploy (SolarWinds being the case that put this category on the map) and the open-source components you pull into your own code without always knowing what's inside. They explain why AI and vibe coding are accelerating the problem, why jQuery is the modern-day Flash, and why "just upgrade the package" is rarely that simple. From there it gets practical: What a Software Bill of Materials (SBOM) is and why you need one Transitive dependencies — the packages hiding beneath your packages Building security checks into your CI/CD pipeline and shifting left Why a flaw caught in static analysis can cost ~$200, while the same flaw found in a pen test can cost $20,000+ Why a pen test should validate your controls, not be your first line of defense How SecurIT360's Project Lantern and ChainGarde automate SBOM analysis against known and actively-exploited vulnerabilities A playbook for vetting vendors, writing accountability into contracts, and holding third parties responsible for actually fixing findings The takeaway: whether you're writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have. Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaY Part 2 — Security Misconfigurations: https://youtu.be/Po8H140BijE Need a web app pen test? SecurIT360 | Cybersecurity From Every Angle More content: https://offsec.blog Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • July 17 · 31 min

    Guaranteed way to catch threat actors | Ep 188

    In this episode, Spencer and Tyler discuss why deception is one of the best ways to catch threat actors. Resources Spencer's Cyber Deception Webinar Spencer's X posts on the topic of cyber deception https://thinkst.com/, https://canary.tools/ @_subtee on X, @haroonmeer on X https://tracebit.com/ Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • July 10 · 16 min

    Avoid this cyber leadership trap | Ep 187

    Need a pentest or vCISO? Work with us! https://www.securit360.com/ A major leadership failure in Cybersecurity is l buying tools first then figuring out where they fit and how to use them. That’s super backwards. Here’s what I would do instead. Plan first, buy & implement second. I’m going to cover just the planning part this week. Next week we will talk about buying and implementing. Because honestly, implementation is where a lot of security teams go wrong. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • July 3 · 35 min

    Episode 186: Real Life Active Directory Attack Paths

    In this episode Spencer and Tyler discuss real life Active Directory attack paths, taken from real internal pentest engagements over the last several years. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • June 25 · 33 min

    [Replay] Episode 172: The Biggest Security Blind Spots in Midsized Companies

    Some of the most dangerous security gaps aren't sophisticated — they're the ones hiding in plain sight. In this replay, Brad and Spencer break down the biggest blind spots they see over and over in mid-size companies: poor asset inventory, flat networks, flat identities, overconfidence in security tools, credential reuse, and the emerging risks with AI. If any of these hit home, go to our website, fill out the form, and see if we're a fit for you. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • June 18 · 45 min

    Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

    AI agents can search the web, manipulate files, run commands, make API requests, access cloud platforms, and operate fully autonomously. They are powerful, they are here, and most organizations have no security controls around them whatsoever. In this episode, Brad and Spencer break down the five major AI agent risk categories security teams need to understand right now, using Simon Willison's "lethal trifecta" as a framework and building on it with two additional risk areas they see in the field. In this episode: - What an AI agent actually is and why the definition matters before you can secure it - What AI agents are capable of: files, commands, APIs, memory, cloud access, and autonomous execution - The lethal trifecta: access to private data, exposure to untrusted content, and external communication - Risk category 1: Access to private data - why agents inherit your permissions and why that is dangerous - Risk category 2: Exposure to untrusted content and prompt injection attacks - Risk category 3: External communication and data exfiltration (including a real canary token experiment) - Risk category 4: Privileged access and limiting blast radius with least privilege identities - Risk category 5: Autonomous actions, approval gates, rate limits, and kill switches - Why backups, rollback plans, and recovery playbooks are more important than ever in an AI agent world Resources mentioned: - Simon Willison's lethal trifecta post (June 2025): https://simonwillison.net - Zach Korman's ContinuumCon sandbox escape workshop: https://continuumcon.com/schedule/ - offsec.blog | securit360.com Need a pen test before end of year? Q3 slots are filling up fast. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • June 11 · 28 min

    Episode 184 | Active Directory Isn't Dead. It's Just Undefended.

    Think Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ years. In this episode, Brad and Spencer break down why AD attack paths remain one of the most critical threats in enterprise environments and what defenders can do about it right now. Spencer also previews his ContinuumCon workshop "Killing AD Attack Paths Once and For All" where he demonstrates how authentication policies and silos can eliminate an entire class of lateral movement attacks built into Windows and Active Directory. In this episode: - Why Active Directory is still alive, well, and heavily targeted - What an Active Directory attack path is and how attackers use them - The four prerequisites attackers need to abuse AD attack paths - Real-world examples: Kerberos ticket theft, SCCM abuse, certificate misconfigurations, and misconfigured permissions - Tools defenders should know: Bloodhound, PingCastle, Purple Knight, Locksmith, and ADelegator - How to prioritize remediations based on ease of exploitation vs. impact - Why retesting is the most overlooked step in any remediation cycle Resources mentioned: - Spencer's ContinuumCon Workshop (Fri. June 12, 10:30am PT / 1:30pm ET): https://continuumcon.com/schedule/ - Hybrid Identity Protection Podcast (Semperis): https://www.semperis.com/hybrid-identity-protection-podcast/ - Bloodhound CE: https://github.com/SpecterOps/BloodHound - PingCastle: https://www.pingcastle.com - Purple Knight: https://www.purple-knight.com - Locksmith: https://github.com/TrimarcJake/Locksmith - offsec.blog | securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • June 5 · 28 min

    Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked

    Security misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Natter cover OWASP A05: Security Misconfiguration with real stories from recent engagements and practical takeaways for developers, security teams, and organizations of all sizes. In this episode: Hardcoded Active Directory credentials and API keys discovered in a public GitHub repo during a healthcare pen test Default credentials (admin/1234) found on a clinical research app storing PHI A rogue Apache basic auth panel that survived from dev into production How verbose error handling and stack traces hand attackers a roadmap to your app Why dev-to-production is the most dangerous transition in your app's lifecycle The shift-left mindset and DevSecOps — empowering devs to ship secure code How CIS lockdown guides can dramatically improve your security posture overnight Resources mentioned: OWASP Top 10: OWASP Top Ten Web Application Security Risks | OWASP Foundation CIS Benchmarks: https://www.cisecurity.org/cis-benchmarks Ep. 182 – OWASP Top 10 Part 1: https://youtu.be/BwYJ-kZ3XaY Need a web application pen test? Reach out: Offensive Security - SecurIT360 Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • May 27 · 30 min

    Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR)

    Hosts Brad Causey and Spencer Alessi break down the 2026 Verizon Data Breach Investigations Report, focusing on the findings that actually matter for IT and security teams. The biggest surprise: vulnerability exploitation has overtaken stolen credentials as the top initial access vector, accounting for 31% of attacks, while credential abuse dropped to just 13%. This completely flips the script on years of "identity is the new perimeter" thinking. Topics covered include: Vulnerability explosion and remediation crisis: Why there are too many vulnerabilities and not enough time for patching, with only 26% of CISA KEV vulnerabilities fully remediated (down from 38%) The patching time paradox: Median remediation time increased from 32 days to 43 days despite organizations initially getting faster at patching from 2022-2024 Web application sprawl: How the push to cloud and SaaS has created massive attack surfaces organizations don't own and can't patch The top 4 initial access vectors: Vulnerability exploitation, phishing, credential abuse, and pretexting Ransomware economics shifting: 48% of breaches involved ransomware, but 69% of victims didn't pay and median payments dropped to $139,875 Mobile phishing success: Mobile-centric phishing had 40% higher success rates than email phishing as users get better at spotting email threats Social engineering evolution: The human element appeared in 62% of breaches, with pretexting requiring different countermeasures than traditional phishing Shadow AI explosion: 45% of employees are regular AI users on corporate devices (up from 15%), with 67% using non-corporate accounts AI data exfiltration: Shadow AI is now the third most common non-malicious insider risk, with source code being the top data type leaked MCP and IDE extension risks: Real-world examples including PocketOS having their entire production database deleted by Claude connected to a railway CLI MCP Brad and Spencer emphasize that while the threat landscape is shifting dramatically, the fundamentals still matter. Organizations need to get comfortable with not being able to patch everything and focus on what matters most. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • May 20 · 44 min

    [Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works

    We're re-releasing one of our most practical episodes this week — originally published November 2025, and still one of the best roadmap conversations we've had on the show. Brad and Spencer share no-fluff advice for breaking into cybersecurity, whether you're switching careers, starting from scratch, or leveling up from a general IT role. They cover what employers actually look for, the fastest paths in, and what to skip. If you're exploring a cybersecurity career, or know someone who is, this one's for you. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • May 12 · 41 min

    Episode 181: AI Zero Days (Google Threat Intelligence Report)

    Brad and Spencer break down Google Threat Intelligence Group's latest report on how adversaries are weaponizing AI across the entire attack lifecycle. The big takeaway isn't that AI has magically replaced attackers, but that it's making certain workflows faster, more scalable, and more repeatable. More importantly, AI platforms, agent skills, integrations, and dependencies are now becoming targets themselves. Topics covered include: AI for vulnerability discovery and exploit development: Google's first confirmed case of a zero-day exploit developed entirely with AI, including intentional prompts like "You are currently a network security expert specializing in embedded devices" Claude skills weaponization: A distilled knowledge base of over 85,000 real-world vulnerability cases integrated into AI research workflows Automation and scaled research: APT45 sending thousands of repetitive prompts to recursively analyze CVEs and validate proof-of-concept exploits AI-powered obfuscation techniques: Dynamic modification, evasive payload generation, and decoy logic using Gemini API for just-in-time VBScript obfuscation Autonomous attack orchestration: Moving beyond content generation into sophisticated malware command automation, including PromptSpy navigating Android UI for persistence AI-enhanced reconnaissance: Generating detailed organizational hierarchies and third-party relationships for high-value targets in finance, security, and HR departments Information operations and deepfakes: Taking legitimate journalist videos, editing in fabricated content, and adding AI-generated voiceovers Attacking AI dependencies: TeamPCP (UNC6780) targeting AI environments as initial access vectors, including March 2026 supply chain attacks on Trivy, Checkmarx, and LiteLLM The Mini Shai-Hulud worm: May 2026 attacks targeting AI infrastructure and dependencies Defensive fundamentals: Why inventory, zero trust principles, and behavioral monitoring matter more than ever Brad and Spencer emphasize that while the threat landscape is evolving rapidly, doubling down on foundational security practices remains the most effective defense strategy. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • May 7 · 29 min

    Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry

    In Episode 180, hosts Brad Causey and Spencer Alessi tackle a critical but often overlooked issue in cybersecurity: the echo chambers that can undermine critical thinking and effective security programs. Inspired by recent experiences at the ILTA Evolve conference, Spencer and Brad explore how cybersecurity professionals, from practitioners to executives, can fall into bubbles where everyone reinforces the same ideas without questioning underlying assumptions. Topics covered include: What cybersecurity echo chambers look like: conferences where everyone "reaffirms what they already knew" instead of challenging assumptions The AI hype cycle as a prime example: why the industry's multi-million-dollar conferences around "the new thing" miss the point that fundamental security principles still apply Social media's role in amplifying bias: how anecdotes from single engagements get generalized into "every organization is terrible at X" without considering nuance Conference culture and groupthink: when entire events operate in lockstep without anyone asking critical questions The danger of not having your own opinion: how IT and security leaders without formed opinions become vulnerable to the best sales pitch rather than the best solution Vendor influence on thought leadership: understanding financial and emotional motivations behind industry messaging Strategies to combat echo chambers: doing your own research, questioning everything, admitting when you don't know something The power of diverse perspectives: why opinions from people outside your expertise can be the most valuable Acknowledging bias and being wrong: how intellectual humility breaks down echo chambers Building a network of trusted advisors: asking people you trust what they think, even if they're not domain experts While technical skills are crucial, nothing ruins a cybersecurity organization like bad culture, and echo chambers are a subcategory of that cultural problem. Whether you're navigating conferences, evaluating vendors, or building your security program, this episode offers practical guidance for maintaining critical thinking in an industry that can be driven more by hype than substance. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • April 30 · 28 min

    Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained

    In Episode 179 of the Cyber Threat Perspective podcast, host Brad Causey and web app pen tester Jordan Natter kick off a multi-part series on the OWASP Top 10, the newly updated list of the most common and critical web application security risks, with a fresh version released in 2025. Before diving in, Brad sets the record straight on something that's been bugging him for 20 years: the OWASP Top 10 is an awareness document, not a compliance framework, not a pen test checklist, and not a comprehensive defense guide. If your vendor claims they "comply with the OWASP Top 10," that's a red flag — you can't comply with an awareness document. Part 1 focuses entirely on A01: Broken Access Control — the most dangerous and most common category on the list — and the conversation goes deep with real-world stories from active engagements. Topics covered include: What OWASP actually is — and why the Top 10 is both invaluable and widely misunderstood Broken Access Control — what it means, why it tops the list, and how it manifests in real applications JWT validation failures — a healthcare application where improper JWT handling allowed unauthorized access to admin functionality MFA bypass via broken access control — a university application where MFA codes weren't properly scoped, enabling account takeover CORS misconfigurations — how Cross-Origin Resource Sharing policies fail in modern Node and React applications, including a real story of bypassing CORS by allowing AWS resources Insecure Direct Object References (IDOR) — why IDOR isn't just about changing integer IDs, including a university app where changing a student ID number led to staff-level privilege escalation S3 bucket IDOR — how a modern web application exposed PHI by returning GUIDs in JSON responses that could be enumerated directly Hidden functionality as false security — why hiding admin URLs from the navigation bar is obscurity, not security, and how Jordan accessed an entire admin PDF panel as an unauthenticated user just by copying a URL OWASP Top 10: https://owasp.org/Top10/2025/0x00_2025-Introduction/ Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • April 22 · 31 min

    Episode 178: Internal Security Controls That Actually Frustrate Attackers

    In Episode 178 of the Cyber Threat Perspective podcast, hosts Spencer and Tyler take a practitioner-first look at the internal security controls that genuinely make attackers' lives difficult, drawing directly from their experience conducting hundreds of internal penetration tests every year. This isn't a vendor comparison or a theoretical framework. It's an honest account of what works, what gets misconfigured, and what separates organizations that slow attackers down from those that don't. Topics covered include: Application Control — ThreatLocker and Magic Sword — why app control is probably the single most effective endpoint control against attackers, how the learning period works, why jumping straight to enforcement mode is a mistake, and why executive buy-in is as critical as the technical implementation WDAC vs. traditional App Locker — the differences, what closed-book enforcement actually means for attackers, and the two schools of thought on allow-list vs. block-list approaches Strong identity controls — MFA beyond RDP including SMB, WinRM, and HTTP via products like Silverfort, why push notification MFA falls short, and why number matching matters Protected Users Group — one of the most powerful and underused Active Directory controls, with a real-world story of how it nearly matched a full third-party identity product in effectiveness during a law firm pen test Least privilege and admin tiering — why Help Desk is one of the most targeted groups for social engineering, how over-permissioned service accounts hand attackers domain admin in minutes, and the real cost of control path vulnerabilities Network segmentation and zero trust — why domain controllers don't need internet access, how segmentation limits attacker recon, and where products like Zscaler fit in EDR baselining and UEBA — why plugging in an EDR tool and expecting it to work isn't enough, the case for getting back to behavior-based detection, and why catching recon activity matters more than catching execution Deception — honeypots, canaries, and fake assets — why deception is underrated, why high-fidelity low-false-positive alerts change the game, and what it actually feels like as a pen tester to trip on a well-placed decoy without knowing it Also mentioned: Spencer and Brad's Tools of the Trade workshop at ILTA Evolve — Denver, end of April. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • April 14 · 41 min

    Episode 177: Claude Mythos — What It Actually Does, What It Doesn't, and What Your Organization Should Do Now

    In Episode 177 of the Cyber Threat Perspective podcast, host Brad Causey and virtual CISO Daniel Perkins take a clear-eyed look at Claude Mythos — Anthropic's AI model that's generating serious buzz in the cybersecurity world for its ability to analyze source code, identify vulnerabilities at scale, build working exploits, and surface flaws that have sat undetected for decades. The cybersecurity community is reacting. Brad and Daniel think a more measured response is warranted. This episode breaks down what Mythos actually is, what it actually did, and what it actually means for your security program — without the hype or the hand-waving. Topics covered include: What Mythos really is — a purpose-built code analysis model, not a hacker-in-a-box or AI overlord, and why that distinction matters The BSD vulnerability reality check — it cost $20,000 to find a 20-year-old DOS flaw in software almost nobody uses, and what that tells us about the real-world economics of AI-driven vulnerability discovery Speed, not net-new — why Mythos hasn't introduced anything fundamentally new to the threat landscape, just compressed the timeline dramatically Vulnerability chaining — how Mythos could change triage by identifying how low and medium severity CVEs combine into critical attack paths The vibe coding problem — why organizations that have never written code before are now writing a lot of it, and why that's where Mythos becomes genuinely important What this means for pen testing — why AI finding code flaws doesn't replace the human-driven validation of security programs, business logic testing, and misconfiguration discovery The shift to continuous vulnerability management — why monthly or quarterly scanning cycles won't be sufficient once Mythos capabilities proliferate, and how to make the move to continuous without going big bang The Mythos-Ready framework — a look at the CSA guidance document, what's useful, what needs to be scaled to your organization, and why inventory and attack surface should come before governance for most teams Supply chain and third-party risk — how Mythos changes the questions you should be asking your software vendors The bottom line from Brad and Daniel: be responsive, not reactive. Tighten your patching SLAs, understand your attack surface, document your decisions, and execute the fundamentals well. The organizations that do that won't be caught flat-footed when this becomes mainstream. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • April 9 · 38 min

    Episode 176: Cybersecurity Advice That Sounds Smart But Fails in Practice

    In Episode 176 of the Cyber Threat Perspective podcast, Brad and Spencer break down some of the most repeated cybersecurity best practices in the industry and explain why, despite sounding solid on paper, they consistently fall short in real IT environments. This isn't about dismissing good security principles. It's about closing the gap between advice that looks great in a framework and controls that actually hold up against how attackers operate. Topics covered include: "Just enable MFA everywhere" — why focusing only on RDP leaves SMB, WinRM, service accounts, and legacy protocols wide open "EDR will catch it" — the danger of over-relying on a single control, including a little-known CrowdStrike behavior where it self-disables on domain controllers at 90% resource utilization — often completely unnoticed "Patch everything immediately" — why blind speed creates its own operational risk, and how to build a prioritized, high-risk patching process that actually works "Least privilege everywhere" — why removing permissions without providing alternatives drives workarounds, shared accounts, and exceptions that undo the whole point "Follow the framework and you're secure" — why compliance is a starting point, not a finish line, and what most standards actually require vs. what actually reduces risk Focusing on attack paths over checklists — why thinking like an attacker leads to better security decisions than ticking boxes Brad and Spencer close with what actually works: context-driven decisions, management buy-in, clear communication when making sweeping changes, and validating every control through internal penetration testing. As Spencer notes, most clients don't have full confidence in their EDR and SOC after a pentest — and that's exactly why trust but verify matters. Also mentioned: Spencer and Brad's upcoming Tools of the Trade workshop at the ILTA Evolve conference in Denver. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • April 2 · 24 min

    Episode 175: NetTools - The Free Active Directory Swiss Army Knife for IT Admins & Pen Testers

    In Episode 175, Spencer and Tyler break down NetTools — a free, self-contained Active Directory management and troubleshooting tool that’s become a go-to for their internal penetration testing engagements. They start with the backstory: years of relying on AD Explorer from Microsoft Sysinternals, and the growing need to evade EDR detections. At one point, that meant manually obfuscating binaries with a hex editor. NetTools eliminates that friction entirely — no installation, no dependencies, no signatures to fight. Topics covered include: Why NetTools replaced AD Explorer and how EDR pressure forced the shift Group Policy enumeration, including how to spot dangerous GPO permissions like authenticated users with write access to server OUs LDAP Search & Browser for querying AD, identifying risky data (like passwords in descriptions), and exploring object relationships Assigned Trustees & Permissions Reporter for fast, visual identification of misconfigurations How to run NetTools from non-domain-joined machines using saved credential profiles Password checker functionality for targeted validation without spraying the environment For pentesters, it’s a faster way to get visibility into AD risk. For IT admins, it’s a practical way to audit and harden your environment. NetTools combines the functionality of multiple tools into one portable utility. Learn more at nettools.net. Credit to creator Gary Reynolds. NetTools | The Swiss army knife of AD troubleshooting Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • March 26 · 28 min

    Episode 174: Web Application Penetration Testing Tools & Techniques with Jordan

    In Episode 174, host Brad Causey is joined by guest Jordan Natter for a practical, tool-focused conversation on web application penetration testing. Together they break down the essential tools and Burp Suite Pro extensions that make up a modern web app pen testing toolkit. Topics covered include: Burp Suite Pro vs. OWASP ZAP — comparing capabilities, extensions, and use cases CSP Auditor — identifying unsafe Content Security Policy directives JSON Web Token (JWT) extension — surfacing and tampering with JWTs in HTTP history Retire.js — flagging outdated JavaScript libraries with known vulnerabilities CyberChef & JWT.io — encoding, decoding, and debugging tokens Postman & Swagger — API testing and documentation workflows SQLMap — powerful SQL injection discovery (and why you should never run it in production) Proxy Forge — evading cloud-based WAFs and testing geo-blocking GraphQL Hunter — enumerating and testing GraphQL instances Have a tool or extension you swear by? Drop it in the comments — Brad and Jordan want to hear from you! --- Burp Suite is an integrated platform for attacking web applications. http://portswigger.net/burp/ Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

  • March 19 · 23 min

    Episode 173: How to Find Insecure Active Directory Permissions with ADeleg

    How do you find insecure permissions in Active Directory before they turn into attack paths? In this episode, we take a practical look at how to identify insecure Active Directory permissions using ADeleg, a free security tool trusted by penetration testers. Misconfigured delegation and overly permissive access rights are a common source of risk in Active Directory environments. These gaps can create hidden attack paths—but many teams don’t know where to look or how to interpret what they’re seeing. In this episode, we cover: How to identify insecure permissions in Active Directory What to look for in high-risk users and groups like Domain Users, Everyone, and Authenticated Users How these misconfigurations translate into real-world attack paths How to use ADeleg to analyze delegated permissions and uncover hidden risk We also include a reference to ADeleginator, a related tool that can help automate parts of this process using PowerShell. While this episode focuses on hands-on analysis with ADeleg, ADeleginator is a useful companion for scaling this work. Tools referenced: ADeleg: https://github.com/mtth-bfft/adeleg Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.