Skip to content
Artwork for The Cyber Threat Perspective

The Cyber Threat Perspective

SecurIT360

Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.

brad@securit360.com

Play
  • 27 episodes
  • weekly
  • Avg 33 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S1 · E196
    Friday · 52 min

    One Hacker, 42 Targets: Inside Anthropic's AI Threat Report | Ep 196

    One French-speaking hacktivist targeted 42 organizations and got internal access to 14 of them, working alone. That is the kind of detail Anthropic's September 2026 threat intelligence report put on the record, with data spanning December 2025 through August 2026. Spencer and Tyler walk through all six generative threat groups named in it and what actually changes for defenders. Their read: the attacks themselves are familiar. Stolen credentials, unpatched edge devices, exposed services, phishing, SQL injection. What AI changed is speed, automation, and scale, and that is enough to matter. In this episode: The skill floor for hacking has dropped, and solo operators are now running campaigns that used to take a team Threat actors vibe coding phishing kits, credential dashboards, and custom tooling Automated vulnerability discovery and exploit development, including one workflow that produced more than a dozen potential zero-day findings in a month Why older models with looser guardrails are showing up in operations while frontier models refuse the same requests Custom harnesses and multi-agent pen testing frameworks that chain traditional offensive tools under an LLM Stolen AI credentials and API keys as a high-priority target, plus resellers advertising discounted access to frontier models On-the-fly obfuscation and retooling that breaks signature-based detection Why baselining, behavioral detection, application control, and external attack surface hygiene matter more than they did a year ago Groups covered: GTG-2006, GTG-50014, GTG-10007, GTG-50020, GTG-50021, and GTG-50029. Spencer and Tyler are penetration testers at SecurIT360. If you get something out of the show, subscribe and leave a rating or review. It helps more than you would think. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

    • Transcript
    • Chapters
  • September 11 · 31 min

    [Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers

    Replay of Episode 178, originally published April 22, 2026. We are re-running this one because it is the question we get asked most on internal pen test debriefs: of everything on the list, what actually slows an attacker down? Spencer and Tyler answer it from the attacker side, using what has and has not stopped them on real engagements. What's covered: - Application control done right, including where ThreatLocker and WDAC actually block a payload and where they get bypassed - MFA, the Protected Users group, and least privilege as attacker-facing controls rather than compliance checkboxes - Why mismanaged admin privileges and service accounts remain the fastest route from foothold to domain admin - Network segmentation and zero trust, and what separates a real implementation from a diagram - Deception techniques and EDR baselining for catching activity that looks legitimate If you are deciding where the next dollar of your security budget goes, this is the episode that tells you what attackers hope you skip. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E195
    September 4 · 27 min

    Every IT Team Has a Joe | Ep 195

    Interested in a pen test? Visit securit360.com. Every organization has a Joe. He is the long tenured engineer or admin who built half the environment, maintains the other half, and keeps most of it in his head. Everybody depends on him and nobody wants to challenge him. Spencer and Tyler break down key man risk in IT, drawing on hundreds of internal pen tests across law firms, banks, credit unions, manufacturing, municipalities, and SaaS organizations. In this episode: Why tribal knowledge is a security risk, not just an operations problem How word of mouth process handoffs turn into a game of telephone The reason remediations stall for an extra 30 days Shadow IT that originates inside the IT team Privilege creep and the single account that owns the environment When Joe's resistance to change is the correct call Cross training that does not add more work to Joe's plate Incentives, clear ownership, and update deadlines that actually stick Separating fact gathering from decision making so seniority does not win by default This is not a knock on senior admins. It is a look at the risk that accumulates when one person carries everything, and what IT leaders can do about it. All of our content can be found at Offsec.blog. Interested in a pen test? Visit securit360.com. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

    • Transcript
    • Chapters
  • S1 · E194
    August 27 · 32 min

    Service Accounts: The Shortest Path to Domain Admin | Ep 194

    Service accounts are one of the easiest paths to domain admin on an internal pen test, and one of the most neglected accounts in Active Directory. In this episode, Spencer and Tyler break down why service accounts keep falling: Kerberoasting every service account (not just the privileged ones), cracking the hashes offline, and spraying what cracks across the environment. Tyler shares a recent engagement where a non-administrative service account shared its password with a domain admin. Same password, one "SVC_" prefix apart. That spray handed over the domain. He's also seen the built-in RID 500 administrator account used as a service account on three separate engagements this year. They also get into where these credentials actually live: web.config files on open file shares, plaintext password files (present on roughly 90% of their pen tests), and one .eml attachment with the credentials sitting inside a screenshot. Then the fix list, in the order they'd actually do it: - Inventory the accounts and document where each one is used, before you touch a password - Delete the service accounts that don't need to exist - Strip privileges and restrict interactive logon rights - Get a password vault or PAM solution, and make every password long and unique - Alert on service accounts logging on interactively - Move to group managed service accounts (gMSA) where you can - Enforce 20-25 character minimums in the meantime. They've cracked 20+ character passphrases with a gaming rig, a 180 GB wordlist, and mutation rules producing roughly four quadrillion permutations Plus the three cleanup mistakes that cause the most damage, including the story of a $70 billion enterprise where one undocumented password reset turned into a 10-hour troubleshooting call. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

    • Transcript
    • Chapters
  • S1 · E193
    August 20 · 39 min

    Your IT Job Doubled. Nobody Told Your Boss. | Ep 193

    In July 2026, Microsoft alone released 622 CVEs. In the 2010s, the monthly average was about a dozen. Nobody handed IT teams more time, budget, or headcount to match, and that gap is what burnout is actually made of. Somewhere in the last five to ten years, "keeping the lights on" became "and also prevent cyberattacks." Spencer Alessi and Brad Causey talk through how security landed on IT's plate, why capable admins end up feeling like they're failing, and what to do about it when hiring a dedicated security person isn't on the table. The core of the episode is a four-question framework for prioritizing when you can't do everything: - Harm: what would cause the greatest damage to the business? - Likelihood: what is most likely to actually be attacked? - Improve: what can you realistically fix with the people and tools you have today? - Accept: what risk must leadership explicitly own because your team can't address it? Brad's addition: don't start from the scan report, start from the crown jewels. Client matters if you're a law firm, financial data if you're a bank. From there, draw lines outward to whatever touches them. And executives need to get comfortable accepting risk, because zero risk tolerance isn't a strategy, it's a phrase. We also get into the language that works with leadership. "You gave me four things and I have time for two" is adversarial and doesn't give anyone enough to decide with. "I recommend A and C, here's why, and here's when B and D land if nothing else gets added" is managing up. Same for new projects: price the work honestly, including cost, timeline, and tradeoffs, then hand the decision back to the people with full business context. We close with the four things IT teams need to succeed: authority, budget, team, and support, including a trusted outside partner for the specialized work you shouldn't be doing yourself. Planning your next penetration test? Book a call with us at https://securit360.com If you enjoyed this episode, please share it with your network. See you next week. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

    • Transcript
    • Chapters
  • S1 · E192
    August 14 · 38 min

    Subtractive Security: Stop Adding Tools and Start Deleting Attack Paths | Ep 192

    Work with us --> https://www.securit360.com/#contact-anchor The OWASP Subtractive Security Top 10 Project --> https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10 The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E191
    August 6 · 38 min

    The CrowdStrike Settings That Actually Stop Us | Ep 191

    Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned. In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire left and right, while Spencer runs nearly identical tooling against the same product at another client and the SOC sees nothing all week. Same CrowdStrike. Same version. Different checkboxes. From there it's a tactical walkthrough of Endpoint Security → Prevention Policies and the settings worth your attention: Enhanced Exploitation Visibility, which unlocks command-line and PowerShell telemetry that Microsoft disables by default; Enhanced DLL Load Visibility for side-loading attacks; WSL2 Visibility, which closes a sandbox threat actors have been using to run Kali tooling under the radar; memory scanning for in-memory C# tradecraft; Office malicious macro removal; file system containment for ransomware over SMB; vulnerable driver protection, the direct mitigation for BYOVD attacks and EDR killers; and cloud-based anomalous process execution for living-off-the-land binaries. They also cover custom IOA rule groups for blocking unauthorized RMM tools, centralized firewall policy management, device policies for USB control, and a warning on exclusions — especially wildcard paths, which Tyler calls a threat actor's best dream. The takeaway is simple: you're paying real money for EDR, and default configurations aren't giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment. TOPICS COVERED - Why EDR vendors ship deficient defaults on purpose - Enhanced Exploitation Visibility and the telemetry gap in PowerShell attacks - DLL side-loading, WSL2 abuse, and vulnerable driver attacks - Memory scanning and in-memory tooling detection - Blocking RMM tools with custom IOA rule groups - Exclusion hygiene and the wildcard path problem - Device policies, USB blocking, and insider threat Sentinel One and Defender for Endpoint are next — let us know what else you want covered. Blog: https://offsec.blog Work with us on an internal pen test: https://securit360.com Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

    • Transcript
    • Chapters
  • S1 · E190
    July 31 · 22 min

    Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures

    Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them? In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compromise, why platforms like Security Scorecard and BitSight inflate their severity anyway, and where genuine cryptographic risk actually lives. Jordan also walks through a real penetration test finding: a JSON Web Token signed with HS256, an exposed configuration backup sitting on the web server, and the signing secret that turned a standard user into an administrator. In this episode: - Why A04 dropped on the OWASP Top 10 without becoming less important - The difference between exploitable risk, hygiene risk, and brand reputational risk - An honest take on Security Scorecard and BitSight scores — what they measure, what they miss, and why a perfect score can coexist with a weak password policy and no MFA - The two halves of A04: data in transit (TLS/HTTPS, integrity, tampering) and data at rest (secure storage of credentials, PII, and payment data) - What a JWT actually is, and why pen testers love pulling them apart - Real pen test story: exposed config backup → leaked JWT secret → signature tampering → privilege escalation to admin - Broken server-side signature validation and other improperly implemented cryptography - Why MD5 and SHA-1 still show up for password storage 20 years too late — and what to use instead (Argon2, scrypt, bcrypt) - HSTS, secure renegotiation, and certificate expiration as A04 subcategories - The coffee shop scenario: the full chain of conditions required to exploit SWEET32 — including roughly 250 GB of captured traffic — and why no one has ever documented it happening in the wild - Why a decade-plus-old vulnerability in your environment says more about your vulnerability management program than about your crypto - Quantum computing: how today's theoretical attacks may not stay theoretical The takeaway: classify your data, choose modern algorithms, retire deprecated protocols, and keep a functioning vulnerability management program. Not because a threat actor is sitting in your local coffee shop waiting to derive your session key — but because leaving decade-old findings in place is a signal about everything else you might be missing. Next up: OWASP A05, which Brad promises is way cooler than A04. Blog: https://securit360.com/blog/ Podcast: https://securit360.buzzsprout.com/ YouTube: https://www.youtube.com/@SecurIT360 Contact: https://securit360.com/contact/ Have a topic you want us to cover? Send it our way. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

    • Transcript
    • Chapters
  • S1 · E189
    July 24 · 27 min

    Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

    Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you. Brad and Jordan cover both sides of supply chain risk: the trusted third-party applications you deploy (SolarWinds being the case that put this category on the map) and the open-source components you pull into your own code without always knowing what's inside. They explain why AI and vibe coding are accelerating the problem, why jQuery is the modern-day Flash, and why "just upgrade the package" is rarely that simple. From there it gets practical: What a Software Bill of Materials (SBOM) is and why you need one Transitive dependencies — the packages hiding beneath your packages Building security checks into your CI/CD pipeline and shifting left Why a flaw caught in static analysis can cost ~$200, while the same flaw found in a pen test can cost $20,000+ Why a pen test should validate your controls, not be your first line of defense How SecurIT360's Project Lantern and ChainGarde automate SBOM analysis against known and actively-exploited vulnerabilities A playbook for vetting vendors, writing accountability into contracts, and holding third parties responsible for actually fixing findings The takeaway: whether you're writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have. Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaY Part 2 — Security Misconfigurations: https://youtu.be/Po8H140BijE Need a web app pen test? SecurIT360 | Cybersecurity From Every Angle More content: https://offsec.blog Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

    • Chapters
  • S1 · E188
    July 17 · 31 min

    Guaranteed way to catch threat actors | Ep 188

    In this episode, Spencer and Tyler discuss why deception is one of the best ways to catch threat actors. Resources Spencer's Cyber Deception Webinar Spencer's X posts on the topic of cyber deception https://thinkst.com/, https://canary.tools/ @_subtee on X, @haroonmeer on X https://tracebit.com/ Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E187
    July 10 · 16 min

    Avoid this cyber leadership trap | Ep 187

    Need a pentest or vCISO? Work with us! https://www.securit360.com/ A major leadership failure in Cybersecurity is l buying tools first then figuring out where they fit and how to use them. That’s super backwards. Here’s what I would do instead. Plan first, buy & implement second. I’m going to cover just the planning part this week. Next week we will talk about buying and implementing. Because honestly, implementation is where a lot of security teams go wrong. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E186
    July 3 · 35 min

    Episode 186: Real Life Active Directory Attack Paths

    In this episode Spencer and Tyler discuss real life Active Directory attack paths, taken from real internal pentest engagements over the last several years. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • June 25 · 33 min

    [Replay] Episode 172: The Biggest Security Blind Spots in Midsized Companies

    Some of the most dangerous security gaps aren't sophisticated — they're the ones hiding in plain sight. In this replay, Brad and Spencer break down the biggest blind spots they see over and over in mid-size companies: poor asset inventory, flat networks, flat identities, overconfidence in security tools, credential reuse, and the emerging risks with AI. If any of these hit home, go to our website, fill out the form, and see if we're a fit for you. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • June 18 · 45 min

    Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

    AI agents can search the web, manipulate files, run commands, make API requests, access cloud platforms, and operate fully autonomously. They are powerful, they are here, and most organizations have no security controls around them whatsoever. In this episode, Brad and Spencer break down the five major AI agent risk categories security teams need to understand right now, using Simon Willison's "lethal trifecta" as a framework and building on it with two additional risk areas they see in the field. In this episode: - What an AI agent actually is and why the definition matters before you can secure it - What AI agents are capable of: files, commands, APIs, memory, cloud access, and autonomous execution - The lethal trifecta: access to private data, exposure to untrusted content, and external communication - Risk category 1: Access to private data - why agents inherit your permissions and why that is dangerous - Risk category 2: Exposure to untrusted content and prompt injection attacks - Risk category 3: External communication and data exfiltration (including a real canary token experiment) - Risk category 4: Privileged access and limiting blast radius with least privilege identities - Risk category 5: Autonomous actions, approval gates, rate limits, and kill switches - Why backups, rollback plans, and recovery playbooks are more important than ever in an AI agent world Resources mentioned: - Simon Willison's lethal trifecta post (June 2025): https://simonwillison.net - Zach Korman's ContinuumCon sandbox escape workshop: https://continuumcon.com/schedule/ - offsec.blog | securit360.com Need a pen test before end of year? Q3 slots are filling up fast. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E184
    June 11 · 28 min

    Episode 184 | Active Directory Isn't Dead. It's Just Undefended.

    Think Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ years. In this episode, Brad and Spencer break down why AD attack paths remain one of the most critical threats in enterprise environments and what defenders can do about it right now. Spencer also previews his ContinuumCon workshop "Killing AD Attack Paths Once and For All" where he demonstrates how authentication policies and silos can eliminate an entire class of lateral movement attacks built into Windows and Active Directory. In this episode: - Why Active Directory is still alive, well, and heavily targeted - What an Active Directory attack path is and how attackers use them - The four prerequisites attackers need to abuse AD attack paths - Real-world examples: Kerberos ticket theft, SCCM abuse, certificate misconfigurations, and misconfigured permissions - Tools defenders should know: Bloodhound, PingCastle, Purple Knight, Locksmith, and ADelegator - How to prioritize remediations based on ease of exploitation vs. impact - Why retesting is the most overlooked step in any remediation cycle Resources mentioned: - Spencer's ContinuumCon Workshop (Fri. June 12, 10:30am PT / 1:30pm ET): https://continuumcon.com/schedule/ - Hybrid Identity Protection Podcast (Semperis): https://www.semperis.com/hybrid-identity-protection-podcast/ - Bloodhound CE: https://github.com/SpecterOps/BloodHound - PingCastle: https://www.pingcastle.com - Purple Knight: https://www.purple-knight.com - Locksmith: https://github.com/TrimarcJake/Locksmith - offsec.blog | securit360.com Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E183
    June 5 · 28 min

    Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked

    Security misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Natter cover OWASP A05: Security Misconfiguration with real stories from recent engagements and practical takeaways for developers, security teams, and organizations of all sizes. In this episode: Hardcoded Active Directory credentials and API keys discovered in a public GitHub repo during a healthcare pen test Default credentials (admin/1234) found on a clinical research app storing PHI A rogue Apache basic auth panel that survived from dev into production How verbose error handling and stack traces hand attackers a roadmap to your app Why dev-to-production is the most dangerous transition in your app's lifecycle The shift-left mindset and DevSecOps — empowering devs to ship secure code How CIS lockdown guides can dramatically improve your security posture overnight Resources mentioned: OWASP Top 10: OWASP Top Ten Web Application Security Risks | OWASP Foundation CIS Benchmarks: https://www.cisecurity.org/cis-benchmarks Ep. 182 – OWASP Top 10 Part 1: https://youtu.be/BwYJ-kZ3XaY Need a web application pen test? Reach out: Offensive Security - SecurIT360 Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E182
    May 27 · 30 min

    Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR)

    Hosts Brad Causey and Spencer Alessi break down the 2026 Verizon Data Breach Investigations Report, focusing on the findings that actually matter for IT and security teams. The biggest surprise: vulnerability exploitation has overtaken stolen credentials as the top initial access vector, accounting for 31% of attacks, while credential abuse dropped to just 13%. This completely flips the script on years of "identity is the new perimeter" thinking. Topics covered include: Vulnerability explosion and remediation crisis: Why there are too many vulnerabilities and not enough time for patching, with only 26% of CISA KEV vulnerabilities fully remediated (down from 38%) The patching time paradox: Median remediation time increased from 32 days to 43 days despite organizations initially getting faster at patching from 2022-2024 Web application sprawl: How the push to cloud and SaaS has created massive attack surfaces organizations don't own and can't patch The top 4 initial access vectors: Vulnerability exploitation, phishing, credential abuse, and pretexting Ransomware economics shifting: 48% of breaches involved ransomware, but 69% of victims didn't pay and median payments dropped to $139,875 Mobile phishing success: Mobile-centric phishing had 40% higher success rates than email phishing as users get better at spotting email threats Social engineering evolution: The human element appeared in 62% of breaches, with pretexting requiring different countermeasures than traditional phishing Shadow AI explosion: 45% of employees are regular AI users on corporate devices (up from 15%), with 67% using non-corporate accounts AI data exfiltration: Shadow AI is now the third most common non-malicious insider risk, with source code being the top data type leaked MCP and IDE extension risks: Real-world examples including PocketOS having their entire production database deleted by Claude connected to a railway CLI MCP Brad and Spencer emphasize that while the threat landscape is shifting dramatically, the fundamentals still matter. Organizations need to get comfortable with not being able to patch everything and focus on what matters most. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • May 20 · 44 min

    [Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works

    We're re-releasing one of our most practical episodes this week — originally published November 2025, and still one of the best roadmap conversations we've had on the show. Brad and Spencer share no-fluff advice for breaking into cybersecurity, whether you're switching careers, starting from scratch, or leveling up from a general IT role. They cover what employers actually look for, the fastest paths in, and what to skip. If you're exploring a cybersecurity career, or know someone who is, this one's for you. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E181
    May 12 · 41 min

    Episode 181: AI Zero Days (Google Threat Intelligence Report)

    Brad and Spencer break down Google Threat Intelligence Group's latest report on how adversaries are weaponizing AI across the entire attack lifecycle. The big takeaway isn't that AI has magically replaced attackers, but that it's making certain workflows faster, more scalable, and more repeatable. More importantly, AI platforms, agent skills, integrations, and dependencies are now becoming targets themselves. Topics covered include: AI for vulnerability discovery and exploit development: Google's first confirmed case of a zero-day exploit developed entirely with AI, including intentional prompts like "You are currently a network security expert specializing in embedded devices" Claude skills weaponization: A distilled knowledge base of over 85,000 real-world vulnerability cases integrated into AI research workflows Automation and scaled research: APT45 sending thousands of repetitive prompts to recursively analyze CVEs and validate proof-of-concept exploits AI-powered obfuscation techniques: Dynamic modification, evasive payload generation, and decoy logic using Gemini API for just-in-time VBScript obfuscation Autonomous attack orchestration: Moving beyond content generation into sophisticated malware command automation, including PromptSpy navigating Android UI for persistence AI-enhanced reconnaissance: Generating detailed organizational hierarchies and third-party relationships for high-value targets in finance, security, and HR departments Information operations and deepfakes: Taking legitimate journalist videos, editing in fabricated content, and adding AI-generated voiceovers Attacking AI dependencies: TeamPCP (UNC6780) targeting AI environments as initial access vectors, including March 2026 supply chain attacks on Trivy, Checkmarx, and LiteLLM The Mini Shai-Hulud worm: May 2026 attacks targeting AI infrastructure and dependencies Defensive fundamentals: Why inventory, zero trust principles, and behavioral monitoring matter more than ever Brad and Spencer emphasize that while the threat landscape is evolving rapidly, doubling down on foundational security practices remains the most effective defense strategy. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  • S1 · E180
    May 7 · 29 min

    Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry

    In Episode 180, hosts Brad Causey and Spencer Alessi tackle a critical but often overlooked issue in cybersecurity: the echo chambers that can undermine critical thinking and effective security programs. Inspired by recent experiences at the ILTA Evolve conference, Spencer and Brad explore how cybersecurity professionals, from practitioners to executives, can fall into bubbles where everyone reinforces the same ideas without questioning underlying assumptions. Topics covered include: What cybersecurity echo chambers look like: conferences where everyone "reaffirms what they already knew" instead of challenging assumptions The AI hype cycle as a prime example: why the industry's multi-million-dollar conferences around "the new thing" miss the point that fundamental security principles still apply Social media's role in amplifying bias: how anecdotes from single engagements get generalized into "every organization is terrible at X" without considering nuance Conference culture and groupthink: when entire events operate in lockstep without anyone asking critical questions The danger of not having your own opinion: how IT and security leaders without formed opinions become vulnerable to the best sales pitch rather than the best solution Vendor influence on thought leadership: understanding financial and emotional motivations behind industry messaging Strategies to combat echo chambers: doing your own research, questioning everything, admitting when you don't know something The power of diverse perspectives: why opinions from people outside your expertise can be the most valuable Acknowledging bias and being wrong: how intellectual humility breaks down echo chambers Building a network of trusted advisors: asking people you trust what they think, even if they're not domain experts While technical skills are crucial, nothing ruins a cybersecurity organization like bad culture, and echo chambers are a subcategory of that cultural problem. Whether you're navigating conferences, evaluating vendors, or building your security program, this episode offers practical guidance for maintaining critical thinking in an industry that can be driven more by hype than substance. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

Showing 1–20 of 27 episodes