Skip to content
Artwork for The Secure Disclosure

The Secure Disclosure

Mackenzie Jackson

Cyber, Sake, News, Research and more
The Disclosure is a weekly cybersecurity podcast that brings the latest in news, research, and leaders into a 45-minute podcast.
Hosted by Mackenzie Jackson, we bring new guests each week to share their research and expertise in the space.

Play
  • 21 episodes
  • weekly
  • Avg 34 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S2 · E36
    Thursday · 37 min

    Email Security in the Age of AI | Josh Kamdjou, Sublime Security CEO

    Why is email security still an absolute mess in the age of generative AI? In this episode of The Secure Disclosure, host Mackenzie Jackson sits down with Josh Kamdjou, CEO of Sublime Security. Discover how attackers abuse trusted platforms, weaponize LLMs for spear phishing at scale, and how autonomous agentic defenses fight back against next-gen email threats.

  • S2 · E34
    August 31 · 32 min

    AI Agents, The Dark Web & The New Attack Surface with Flare CEO Norman Menz

    How has cybercrime evolved beyond traditional Tor sites into encrypted Telegram channels and automated AI agents? Norman Menz, CEO of Flare, joins the podcast to unpack continuous threat exposure, tracking exposed GitHub secrets, and why non-human identity security is the newest defense battleground. Learn how modern teams stay ahead of relentless digital adversaries.

  • S2 · E33
    August 27 · 53 min

    Can We Actually Fix Software Supply Chain Security? 6 AppSec Leaders Debate

    Software supply chain attacks have gone parabolic over the past year, turning open-source packages, CI/CD pipelines, and developer laptops into prime targets for state-sponsored threat actors and AI-augmented attacks.In this special roundtable panel, security leaders from Aikido Security, Socket, OX Security, Step Security, and open source malware.com come together for an unfiltered conversation on the supply chain security crisis. The panel dives into the real catalysts behind the rise of malware—from North Korean crypto-theft campaigns and weaponized GitHub Actions to the hidden dangers of prioritizing developer velocity over security checks and balances.You'll also learn the critical difference between standard CVE vulnerabilities and active malicious software, why package registries like npm face systemic security challenges, and practical steps engineering teams must take to protect their developer environments against upstream compromises.

  • S32 · E2
    August 19 · 36 min

    Tearing Down Vendor Fluff: The Real State of AI Security | James Berthoty

    n the era of rapid AI adoption, is it time for security teams to rethink their entire AppSec stack and throw away traditional SAST and SCA scanners?In this episode of The Secure Disclosure, host Mackenzie Jackson sits down with James Berthoty, cloud security engineer and founder of Latio, a practitioner-first analyst firm. Together, they cut through vendor marketing fluff to discuss what actually stops modern breaches. James explains why executive mandates are pushing AI adoption faster than the cloud revolution and highlights the critical risks that emerge when autonomous AI agents gain CLI access and compute power.They also explore the dramatic surge in open-source supply chain malware, how AI coding agents lowered the barrier of entry for attackers, and the critical importance of securing developer endpoints, CI/CD pipelines, and Kubernetes infrastructure. To wrap it all up, James tackles the podcast's signature Would You Rather game to navigate terrible security trade-offs.

  • S2 · E31
    August 12 · 29 min

    GitGuardian CEO: How Exposed API Keys & AI Agents Cause Security Breaches - Eric Fourrier

    What happens when two 25-year-old French engineers accidentally discover NASA's Slack admin API key on a public GitHub repository? That exact moment in 2017 launched GitGuardian. In this episode of The Secure Disclosure, GitGuardian CEO and co-founder Eric Fourrier sits down to share the wild origin story behind the company and how the battle against exposed secrets has shifted over the past decade. Eric breaks down how the threat landscape has evolved from public and private GitHub repositories straight to developer endpoints. With the rapid rise of AI coding agents and vibe coding, developers and non-engineers are inadvertently creating massive attack surfaces. Eric also reveals alarming statistics—including why developer laptops contain 50 times more valid secrets than GitHub repos, with 45% placed by non-deterministic AI agents.

  • S2 · E30
    July 14 · 35 min

    How to Stop Supply Chain Attacks Without Destroying Developer Productivity

    In this episode of The Secure Disclosure Podcast, host Mackenzie sits down with Arun Singh, CISO of Tyro Payments. Drawing from his journey from an entry-level service desk role to a fintech security executive, Arun breaks down the counterintuitive realities of modern supply chain attacks, winning developer trust through technical authenticity, and how security leaders must evolve to manage the rapid productivity and threats introduced by AI.Sponsor & Call to ActionThis episode is brought to you by Aikido Security, your complete code-to-cloud security solution that secures everything from your first line of code through your supply chain and dependencies.Ready to shift your security into the developer's workflow? Start for free today at aikido.dev.

  • S2 · E25
    July 1 · 36 min

    Solving the Supply Chain Security & Malware Crisis w/John Amaral

    In this episode of the Secure Disclosure Podcast , host McKenzie sits down with John Amaral, Co-founder and CTO of Root.io. They dive deep into the increasingly complex landscape of open-source supply chain attacks , examining how threat actors like Team PCP leverage AI to weaponize entire package ecosystems. John explains how Root's agentic software factory solves cascading CVE backlogs through precision pinning and automated patch backporting —all capped off with a massive industry merger announcement.Keep your supply chain secure from code to cloud with Aikido Security. Start protecting your ecosystem for free at aikido.dev.

  • S2 · E24
    June 25 · 30 min

    AI is an Amplifier: Why Bad Infrastructure Gets ‘Wronger’ Faster w/ Abdel SGHIOUAR

    In this episode of The Secure Disclosure, Mackenzie sits down with Abdel Sghiouar, Senior Cloud Developer Advocate at Google and co-host of the Kubernetes Podcast. Together, they unpack the messy, high-stakes intersection of AI agents and Kubernetes cluster operations. Abdel breaks down the "Autonomy Catch-22", the technical paradox where an agent's capability to act independently is precisely what makes it a massive security liability. They explore real-world risks like prompt poisoning, how next-gen models like Gemini 3.5 Flash are aggressively ignoring user instructions, and the threat of over-privileged autonomous tools deleting production databases. From tactical mitigation strategies like "hook engineering" to managing massive cognitive overload and false positives for SRE teams, this conversation offers a grounded reality check on the future of cloud-native infrastructure.

  • S2 · E22
    June 16 · 26 min

    Your Microphone Became a Keylogger w/ David vonThenen

    In this episode of The Secure Disclosure, we sit down in Copenhagen with David vonThenen, a keynote speaker and machine learning expert conducting groundbreaking—and terrifying—research. David breaks down his latest work on acoustic keystroke logging: training machine learning models from scratch using PyTorch to identify exactly what you are typing purely by the acoustic signature of your keyboard clicks. From hitting 100% accuracy over Zoom calls to tracing the roots of low-tech Cold War espionage, David explains how computational power has evolved, the threat this poses to corporate environments, and how we can use "digital interference" to fight back against pervasive data tracking.Sponsor Link Protect your code from cloud to deployment with Aikido Security, the leader in AI pen-testing and supply chain defense—start for free at https://aikido.dev.

  • S2 · E21
    June 9 · 30 min

    Understand the Software Supply Chain Chaos w/ Roeland Delrue

    Supply chain security is evolving at a terrifying pace. In this episode of The Security Disclosure, Roeland Delrue (COO and co-founder of Aikido Security) breaks down why attackers have shifted their crosshairs from cloud infrastructure directly onto the individual developer's machine.We dive deep into how malicious JavaScript packages, VS Code extensions, and Chrome extensions manage to slip past traditional endpoint software like CrowdStrike or McAfee, and discuss the practical, counterintuitive steps security teams can take right now to protect themselves. Roeland also shares a surprisingly candid take on why open-source marketplaces like NPM and PyPI need to step up, why giving threat actors "oxygen" on social media does more harm than good, and plays a brutal round of tech "Would You Rather."

  • S2 · E21
    May 28 · 30 min

    Prompt Injection Might Never Be Solved w/ Paul Vann

    In this episode of Secure Disclosure, host Matt sits down with Paul Van, CEO and founder of Validia, to explore the frontier of AI security. Instead of focusing on how bad actors use AI tools, they dive deep into how to protect the AI models themselves from the inside out. From the unsolvable nature of prompt injections and the rise of distillation attacks to the reality of a "machine vs. machine" security landscape, Paul breaks down why traditional firewalls fail and how a model's behavioral "trauma response" might just be the key to defending LLMs. 🛡️ Support Our Sponsor:Stay Secure with Aikido security at https://aikido.dev

  • S2 · E20
    May 22 · 31 min

    AI Broke the Security Ecosystem w/ Chris Hughes

    In this episode of The Secure Disclosure, host sits down with Chris Hughes founder of Resilient Cyber, CISA Cyber Innovation Fellow, and a leading voice in cybersecurity. We dive deep into the chaotic and rapidly shifting landscape of software supply chain security, the sudden operational struggles of the National Vulnerability Database (NVD), and how AI is completely rewriting the rules of vulnerability management. From the technical and social engineering risks plaguing open-source software to the "human-in-the-loop" delusion, Chris shares his honest, unfiltered takes on where the industry is heading and why things will likely get worse before they get better. The episode wraps up with a chaotic round of "Would You Rather," forcing Chris to choose between missing firewalls, permanent vulnerability freezes, and total AI "vibe coding."

  • S2 · E19
    May 15 · 37 min

    PostHog is placing a wild bet on AI Coding w/ James Hawkins

    In this episode of Secure Disclosure, James Hawkins, the co-founder and co-CEO of PostHog, dives into the "radical transparency" that turned a pivoted startup into a billion-dollar open-source powerhouse. James shares his unfiltered thoughts on why most B2B software pricing is a scam, why "collaboration" is often just a form of procrastination, and how AI is fundamentally changing the role of the engineer from a code-writer to a product-architect.The conversation gets spicy as they discuss the security risks of open-source software in the age of AI, the controversy surrounding "vibe coding," and PostHog’s ambitious bet on a future where you might code via Slack, or even a phone call.

  • S2 · E18
    May 6 · 26 min

    AI Panic is Driving Shadow IT w/ Noora Ahmed-Moshe

    In this episode, we sit down with tech veteran and behavioral science enthusiast Noora Ahmed-Moshe to tackle the growing phenomenon of Shadow AI. As employees scramble to stay relevant in an AI-driven world, many are turning to unsanctioned tools, and bringing sensitive company data with them. Noora explains why "banning" these tools is a losing game and how organizations can bridge the gap between security and productivity. We dive into the "human layer" of cybersecurity, the million-dollar risk of AI note-takers, and how fostering psychological safety is the ultimate defense against the next big breach.

  • S2 · E17
    April 29 · 29 min

    When AI Agents Change their Intent w/ Frank Vukovits

    AI agents are transforming cybersecurity, from how access is granted to how attacks unfold. Frank Vukovitz (Delinea) joins Secure Disclosure to unpack the rise of non-human identities, the risks of autonomous agents, and why concepts like least privilege, identity lifecycle management, and continuous monitoring are more critical than ever. The big question: will AI ultimately make us more secure, or less?

  • S2 · E16
    April 22 · 38 min

    OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca

    Tanya Janca joins the podcast for a sharp, no-nonsense conversation on the OWASP Top 10, why secure coding still gets skipped, and how AI is reshaping the way developers build and review software. She breaks down why broken access control keeps topping the charts, what security teams keep getting wrong, and how to create guardrails developers will actually use. The episode also dives into vibe coding, supply chain risk, and the future of secure software training. It’s fast, practical, and packed with opinions worth stealing.

  • S2 · E15
    April 15 · 40 min

    The Future of Hacking is Agentic w/ Jason Haddix

    Jason Haddix joins the podcast to break down how AI is transforming offensive security — from attacking LLM-powered applications to why he believes 90% of pentests will soon be done by AI. We dive into prompt injection, defending AI systems with layered controls, and how enterprises are (sometimes dangerously) adopting AI internally.We also explore the impact of AI on bug bounty programs, why “fighting AI with AI” is becoming necessary, and what the future holds for human pentesters in an increasingly automated world.

  • S2 · E14
    April 7 · 38 min

    Open Source Malware, Supply Chain Risk, and Contagious Interviews: w/ Paul McCarty and Jenn Gile

    In this episode of The Secure Disclosure, Jenn Gile and Paul McCarty from Open Source Malware break down how malicious packages are evolving, why developers are now a primary target, and what security teams still get wrong about software supply chain defense. From contagious interview campaigns to registry weaknesses and response playbooks, this conversation covers the real world risks behind today’s open source malware problem. Sponsored by Aikido Securityhttps://aikido.devLearn more about Open Source Malwarehttps://opensourcemalware.com/Connect with Jenn Gilehttps://www.linkedin.com/in/jenngile/Connect with Paul McCartyhttps://www.linkedin.com/in/mccartypaul/Follow The Secure Disclosure on LinkedInhttps://www.linkedin.com/company/the-secure-disclosure

  • S2 · E14
    April 2 · 35 min

    Bugcrowd Founder Casey Ellis: AI Slop, and the Future of Hacking

    Casey Ellis, founder of Bugcrowd, joins the show to talk about the evolution of bug bounty, how hackers went from outsiders to strategic assets, and why AI-generated bug reports are putting pressure on security teams. We also get into VDPs vs public bounties, pentesting, vulnerability economics, and where security research is headed over the next five years.

  • S2 · E13
    March 25 · 26 min

    Are Humans the Weakest Link in Security? w/ Sean Juroviesky

    In this episode of the Secure Disclosure Podcast, we dive into the human side of security with Sean Juroviesky. From why people remain the biggest challenge in cybersecurity to how organizations can build effective security cultures, this conversation explores identity, access management, and the risks introduced by shadow IT and AI. We unpack how to make the secure path the easiest path, how to detect risky behavior without alienating employees, and why over-permissioned AI tools may be the next big threat. It’s a practical, honest discussion on balancing security, usability, and the rapid evolution of AI in modern organizations.SponsorThis episode is brought to you by Aikido — https://aikido.devSecure everything from code to cloud

Showing 1–20 of 21 episodes