Skip to content
Artwork for YusufOnSecurity.com

YusufOnSecurity.com

YusufOnSecurity.Com

This is a weekly podcast on cyber security domains. We discuss, dissect and demystify the world of security by providing an in-depth coverage on the cybersecurity topics that matter most. All these in plain easy to understand language. Like it, share it, and most importantly enjoy it!

Play
  • 20 episodes
  • Avg 28 min
  • English
  • May 30 · 20 min

    278 - Non-Human Identity Explained - The Invisible Accounts Outnumbering Your Staff

    Enjoying the content? Let us know your feedback! Let me start with a question that sounds simple but isn't. How many identities are on your network? Most people, if you ask them, will reach for the staff headcount. "We've got five hundred employees, so… five hundred logins-ish?" And they'd be wrong. Often wildly wrong. Because on a modern cloud network, the humans are the minority. For every one of your employees there can be ten, fifty, sometimes a hundred or more other identities — and not one of them is a person. They're software. A microservice logging into a database. A serverless function calling a payment API. A script with an access key. A CI/CD pipeline deploying code at three in the morning. And increasingly — this is the new one — an autonomous AI agent, going off and calling tools and services on your behalf while you sleep. Every one of those is an identity. Every one of them authenticates to something. Every one of them holds a secret of some kind. And every one of them can be stolen, abused, or turned against you. Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • May 23 · 29 min

    277 - BitLocker Bypassed - How the YellowKey Zero-Day Defeats Windows 11 Encryption

    Enjoying the content? Let us know your feedback! Let me paint you a picture. You lose your work laptop. Maybe it's lifted off a café table, maybe it walks out of the back of a taxi. And your first thought — once the panic settles — is, "well, at least the drive is encrypted. Whoever has it can't actually read anything." Right? That's the whole deal. That's the promise. Today's episode is about the week that promise got broken on Windows 11. Not with a supercomputer. Not with some nation-state crypto-cracking lab. With a USB stick and a folder. The exploit is called YellowKey, and it does something that, frankly, should not be possible, it walks right past BitLocker without touching the encryption at all. Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • May 16 · 27 min

    276 - copy.fail Explained-The Linux Kernel Bug That Turns Any User Into Root

    Enjoying the content? Let us know your feedback! This week we are going to talk about a bug with one of the most misleading names I have seen in a while. It is called copy.fail. And if you saw that name pop up in your feed, you would be forgiven for thinking it was some clever browser demo, or maybe a problem with your clipboard. It is neither. copy.fail is a Linux kernel vulnerability. Its official label is CVE-2026-31431. And what makes it worth a full episode is not how exotic it is — it is actually quite simple — but how wide its reach is. This single flaw lets an ordinary, unprivileged user on a Linux machine promote themselves all the way up to root. And it does so on nearly every modern Linux distribution shipped since 2017. - https://xint.io:copy.fail - https://www.cisa.gov: CVE-2026-31431 - https://www.bugcrowd.com: Hacker Opinion Piece How Lazy Hacking Killed Curls Bug-bounty Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • May 9 · 30 min

    275 - The Mercor Breach-When Your Security Scanner Becomes the Attack Vector

    Enjoying the content? Let us know your feedback! Today's episode is one of those stories that, when you start pulling the thread, the whole thing just keeps unravelling. We are going to talk about the Mercor breach. Now, if that name doesn't ring a bell, Mercor is a ten-billion-dollar AI recruiting startup. They match human experts with companies like OpenAI, Meta, and Anthropic to help train AI models. Big clients. Big data. Big target. Towards the end of March of this year, a threat group called TeamPCP and no, that is not a household cleaning detergent type of product - managed to steal roughly four terabytes of data from Mercor. And the way they did it? They didn't attack Mercor directly. They didn't even attack the software Mercor relied on directly. They attacked the security tool that was supposed to protect that software. Let me say that again. They compromised the vulnerability scanner. We have all that coming up next in this week's episode. - https://securitylabs.datadoghq.com: LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign - https://www.securityweek.com: SecurityWeek — Mercor Hit by LiteLLM Supply Chain Attack: Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • May 2 · 35 min

    274 - Ransomware Hit a Water Plant - Why Your Tap Water Is a Cybersecurity Problem

    Enjoying the content? Let us know your feedback! Today's episode is one of those stories that really does hit home. Not a bank breach. Not some government leak. I want to talk about the water coming out of your tap. On March 14th, 2026, hackers dropped ransomware on a water treatment plant in Minot, North Dakota. Staff walked in that morning, saw a ransom note sitting on a server screen, and had to unplug the whole thing. For the next sixteen hours, plant operators were physically walking through the facility, reading gauges by hand — old school, the way it was done decades ago — while the FBI got the call. The city says the water stayed safe. Nobody got sick. But this incident ripped the cover off a problem the cybersecurity community has been warning about for years: water infrastructure is dangerously exposed. And most people have no idea. Today I want to unpack what happened in Minot, why water utilities are such soft targets, what SCADA systems actually are and why they are so difficult to defend, and what defenders and regulators are doing — and should be doing — about all of this. - https://therecord.media: North Dakota Ransomware Water Plant - https://www.cisa.gov: CISA — Adapting Zero Trust Principles to Operational Technology Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • April 25 · 28 min

    273 - Project Glasswing (Mythos) - Anthropic Watershed Moment for Cybersecurity - Part 2

    Enjoying the content? Let us know your feedback! This is Part 2 of our deep dive into Anthropic's Claude Mythos Preview and Project Glasswing. In Part 1, we covered what Mythos is, how it fits into the Claude model family, and why Anthropic is pushing the boundaries of extended thinking and complex reasoning. Today, we are picking up right where we left off and turning our attention to Project Glasswing — what it is, what it means for security professionals, and why this convergence of advanced AI reasoning and autonomous capability should be on every defender's radar. If you have not listened to Part 1 yet, I would recommend going back and starting there, but if you are already caught up, let us get right into it. https://www.forrester.com: Project Glasswing The 10 Consequences Nobody Writing About Yet - https://www.anthropic.com: Project Glasswing - https://blogs.cisco.com: Rising To the Era of AI Powered Cyber Defense - https://www.wired.com: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • April 18 · 27 min

    272 - Project Glasswing (Mythos) - Anthropic Watershed Moment for Cybersecurity - Part 1

    Enjoying the content? Let us know your feedback! About three weeks ago, on the 7th of April, Anthropic — the company behind the Claude family of AI models — announced something called Claude Mythos Preview. They paired the announcement with a coordinated industry effort they're calling Project Glasswing. And the headlines that followed have been, frankly, alarming. Fortune ran a piece headlined that Mythos can hack nearly anything, and we aren't ready. Coindesk reported that banks like JP Morgan, and crypto exchanges like Coinbase and Binance, are already approaching Anthropic to test it. And Anthropic's own researchers described this as a watershed moment — meaning, a before-and-after divide in how we think about software security. So let's break this down. What is Mythos? What can it actually do? And — most importantly — what should you and I, as defenders, be doing about it starting today? - https://www.anthropic.com: Project Glasswing - https://blogs.cisco.com: Rising To the Era of AI Powered Cyber Defense - https://www.wired.com: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • April 11 · 22 min

    271 - $21 Billion Lost to Cybercrime — FBI's 2025 Report and Microsoft's Massive April Patch Tuesday

    Enjoying the content? Let us know your feedback! We have got two big stories to get through today. First, the FBI just released its 2025 Internet Crime Report — and the numbers are not just record-breaking, they are genuinely alarming. We are talking about over twenty billion dollars in reported losses in a single year. And for the first time ever, the report includes a dedicated section on how criminals are using artificial intelligence to supercharge their scams. Then, we are going to pivot to Microsoft's April 2026 Patch Tuesday — one of the largest patch cycles we have seen in a long time. A hundred and sixty-seven vulnerabilities fixed, including an actively exploited zero-day in SharePoint Server. If your organisation runs SharePoint, and most do, you are going to want to hear this. Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • April 4 · 26 min

    270 - Securing AI - The 3 Frameworks Every Defender Must Know

    Enjoying the content? Let us know your feedback! If you've been watching the cybersecurity space for the last two years, you've noticed something. Almost every breach report, every vendor pitch, every board meeting — AI is in the conversation. Sometimes as the hero, sometimes as the villain, and very often as both at the same time. But here's the uncomfortable truth. Most organisations are racing to deploy AI far faster than they are learning how to secure it. We're plugging large language models into customer service, into code pipelines, into decision-making workflows — and we're often doing it without a framework to guide us. So in today's episode, I want to fix that. I want to walk you through the three frameworks that have become the gold standards for AI security. They are NIST AI RMF, MITRE ATLAS, and the OWASP Top 10 for LLM Applications. Hopefully by the end of the next fifteen minutes, you will know what each one is, what each acronym actually stands for, what problem each one solves, and — most importantly — how they fit together so you can use them in the real world. - https://www.nist.gov: AI Risk Management Framework - https://atlas.mitre.org: MITRE ATLAS - https://owasp.org: OWASP Top 10 for Large Language Model Applications Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • March 28 · 43 min

    269 - Cyber Resilience in 2026 - The Skills Gap, Team Readiness, and What Security Leaders Must Do Now

    Enjoying the content? Let us know your feedback! In this week's episode, I am joined by my good old friend Shakel Ahmed, a cybersecurity practitioner with over 20 years of experience across some of the most demanding environments in the industry. We are covering the importance of skills and cyber resilience — and this is particularly important for those of you who are responsible for building and maintaining security teams, managing risk at a strategic level, or simply trying to figure out where to focus your energy in an industry that never sits still. Whether you are an analyst wondering which skills will keep you relevant in the age of AI, or a CISO trying to ensure your organisation can absorb a hit and keep operating, this conversation is for you. Shakel brings a practitioner's perspective — not theory, not vendor talk — just hard-won insight on what it actually takes to build resilient people, resilient processes, and resilient organisations. So grab a coffee, settle in, and let's get into it. Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • March 21 · 30 min

    268 - The Stryker Attack: How State Sponsored Hackers Weaponised a Microsoft Tool to Wipe 80K Devices

    Enjoying the content? Let us know your feedback! Just over a week ago, on 11 March 2026, a cyberattack brought one of the world's largest medical device makers to its knees. Stryker - a $25 billion company that manufactures surgical robots, joint implants and emergency equipment - woke up to find thousands of employee devices wiped clean, its ordering systems offline, and surgeries being rescheduled around the world. This was not ransomware. This was something more deliberate and destructive - a wiper attack carried out by a state sponsored-linked hacking group called Handala, who exploited a trusted Microsoft device management tool to erase data from up to 80,000 employee phones and laptops in one move. In this episode, we break down exactly what happened, how it happened, and what it means for every organisation that relies on cloud-based device management tools. We also look at the governance lessons - from business continuity planning to privileged access controls - that this attack makes impossible to ignore. - https://csrc.nist.gov: NIST SP 800-34 Rev. 1 - https://www.cybersecuritydive.com: Stryker attack raises concerns about role of Microsoft Intune Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • March 14 · 29 min

    267 - SMB Protocol Explained-Why It Keeps Getting Hacked and Why We Can't Remove it?

    Enjoying the content? Let us know your feedback! Today we are talking about a protocol that is older than most of the people working in IT security right now, a protocol that has powered some of the most catastrophic cyberattacks in history, a protocol that security professionals have been trying to retire for years — and a protocol that is still quietly running in the background of almost every Windows environment on the planet. I am talking about SMB — the Server Message Block protocol. By the end of this episode, you will understand what it does, why it has been so dangerous, how it connects to something we have touched on before called Kerberos and NTLM authentication, and most importantly, what you should actually be doing about it in your organisation today. So, lots to talk about today. Lets go! - https://learn.microsoft.com: SMB Security Hardening - https://blog.barracuda.com: Majority of Attacks Against SMB Protocol Attempt to Exploit EternalBlue - https://securelist.com: NTLM Is Being Abused In 2025 Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • March 7 · 25 min

    266 - Why ClickFix Is Exploding, LLMs Make Terrible Password Generators, and Certificates Are Getting Shorter?

    Enjoying the content? Let us know your feedback! It has been a little while since my last update episode, and a lot has been happening in the world of cybersecurity. So today I want to catch you up on three things that have been on my radar and, more importantly, should be on yours. First, we are going to talk about ClickFix — a social engineering attack technique that has exploded in popularity over the past year and is now being used by everyone from cybercriminals to nation-state hackers. I will explain what it is, how it works, and why it is so dangerous. Second, we are going to tackle a question that more and more people are asking: can I just ask an AI chatbot to generate a password for me? The short answer is no, and I will explain exactly why using some very revealing research that just came out. And third, we are going to cover an important change happening in the world of digital certificates right now — specifically code signing certificates, which are getting significantly shorter lifespans starting this year. I will explain what code signing is, why it matters to defenders, and what your organisation needs to do. Lots to get through, so let us dive right in. Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • February 28 · 29 min

    265 - The AI Agent Security Crisis – How OpenClaw's ClawJacked Flaw Compromised 40K Systems

    Enjoying the content? Let us know your feedback! In late February 2026, a Meta executive lost her entire email inbox when an AI agent she was using deleted everything despite explicit instructions to confirm before taking action. At the same time, over 40K OpenClaw AI agent instances were found exposed to the internet, vulnerable to complete takeover by any malicious website a developer happened to visit. This isn't a story about a theoretical vulnerability or a proof-of-concept attack—this is happening right now, and if your organization is using AI agents for automation, you need to understand what just went wrong and why it matters. - https://thehackernews.com: ClawJacked Flaw - https://www.oasis.security: OpenClaw Vulnerability - https://www.microsoft.com: Cyber Pulse AI Security Report - https://www.microsoft.com: 80% Of Fortune 500 Use Active AI Agents Observability Governance And Security Shape The New Frontier Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • February 23 · 29 min

    264 - Inside the Cisco Live SOC: Securing the World's Biggest Networking Event

    Enjoying the content? Let us know your feedback! Cisco Live is one of the largest networking and security conferences in the world, bringing together thousands of IT and security professionals for a week of learning, innovation, and hands-on experience — and this year, I was there, working as a SOC analyst on the ground -protecting the event. At an event of this scale, thousands of devices and connections are generating traffic around the clock, and behind the scenes, a dedicated SOC team is watching every packet, every connection, and every anomaly in real time. This week, I sat down with the Director of the SOC to pull back the curtain on what it actually takes to secure an event like this — from threat patterns unique to a security-savvy crowd, to the tools and team structure that keep it all running.This is a conversation you don't want to miss - https://blogs.cisco.com: SOC In A Box - http://cs.co/SOCEvents: Inside the event SOC-Securing the world's flagship conferences - https://www.cisco.com: Endace Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • February 14 · 35 min

    263 - BGP Hijacking - The Invisible Threat That Can Redirect Your Traffic Anywhere

    Enjoying the content? Let us know your feedback! On June 27, 2024, millions of people worldwide suddenly couldn't access one of the internet's most popular DNS services—not because of a cyberattack in the traditional sense, but because a single network in Brazil convinced the internet that it owned an IP address that belonged to someone else. This wasn't hacking in the way most people understand it—no passwords were stolen, no systems were breached, yet traffic from 300 networks across 70 countries was instantly rerouted into oblivion. In this episode, we break down BGP hijacking: the invisible routing attack that lets anyone with the right access redirect your internet traffic anywhere they want, and why the protocol holding the entire internet together was built on a foundation of trust that no longer makes sense in 2026. - https://gcore.com: What IS BGP? - https://isbgpsafeyet.com: Is BGP Safe Yet? - https://blog.apnic.net: APNIC Blog – BGP Security Analysis and Updates - https://en.wikipedia.org: Regional Internet Registries Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • February 7 · 24 min

    262 - DORA Explained – What Financial Firms Need to Know About EU's Cyber Resilience Law

    Enjoying the content? Let us know your feedback! On January 17, 2025, the European Union's Digital Operational Resilience Act — known as DORA — became fully enforceable, fundamentally changing how financial institutions across Europe manage cyber and operational risk. One year into enforcement, regulators have designated critical ICT providers, penalties are now being levied, and the January 2026 supervisory review is underway. In this episode, we break down what DORA actually requires, who it applies to, why it matters even if you're not in the EU, and what the upcoming review means for the financial sector globally. - https://www.eiopa.europa.eu: Digital Operational Resilience Act (DORA) - https://eur-lex.europa.eu: The regulation Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • January 31 · 14 min

    261 - Passkeys in 2026 – Are We Finally Done With Passwords?

    Enjoying the content? Let us know your feedback! After sixty years of password resets, forgotten credentials, and phishing attacks, the authentication landscape is finally shifting — and 2026 marks the tipping point. In this episode, we break down what passkeys actually are, why over a billion people have already adopted them, and what the regulatory push from NIST, CISA, and global financial regulators means for your organisation. Passwords aren't dead yet, but for the first time, they're genuinely on the way out. We have all that coming up next, in this week's podcast! - https://passkeys.io: Comprehensive implementation guides, device compatibility checker, and passkey directory - https://pages.nist.gov/800-63-4: Official SP 800-63-4 with AAL2/AAL3 Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • January 24 · 27 min

    260 - From NTLM to Kerberos - Microsoft's Security Transformation Begins - Part 2

    Enjoying the content? Let us know your feedback! In Part 1 of this series, we explored why Microsoft is finally saying goodbye to NTLM authentication after more than 25 years of service. We discussed NTLM's security weaknesses, from relay attacks to weak cryptography, and touched on Kerberos as the obvious alternative that's been waiting in the wings since ...well....Windows 2000. Today in Part 2, we're getting practical. We'll explore the two groundbreaking major Microsoft is adding to Kerberos—IAKerb and Local KDC—that will finally allow organizations to eliminate NTLM entirely. More importantly, we'll discuss what this means for you as a defender, how to prepare your environment, and of course...what timeline you're working with. - techcommunity.microsoft.com: The evolution of Windows authentication - www.securityweek.com: Microsoft Improving Windows Authentication, Disabling NTLM - www.bleepingcomputer.com: Microsoft plans to kill off NTLM authentication in Windows 11 - thehackernews.com: Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

  • January 17 · 27 min

    259 - From NTLM to Kerberos - Microsoft's Security Transformation Begins - Part 1

    Enjoying the content? Let us know your feedback! Today, we're diving into a significant announcement from Microsoft that will fundamentally change how Windows handles authentication. In this two-part series, we'll explore Microsoft's plan to phase out the NT LAN Manager protocol, better known as NTLM, and fully embrace Kerberos authentication in Windows 11. This isn't just a minor technical adjustment—this represents a major shift in how organizations will secure their Windows environments. In Part 1 today, we'll understand what NTLM is, why it's been around for so long despite its security weaknesses, and explore the fundamental reasons Microsoft has decided it's finally time to pull the plug. - techcommunity.microsoft.com: The evolution of Windows authentication - www.securityweek.com: Microsoft Improving Windows Authentication, Disabling NTLM - www.bleepingcomputer.com: Microsoft plans to kill off NTLM authentication in Windows 11 - thehackernews.com: Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication Be sure to subscribe! You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too.

Showing 1–20 of 20 episodes