Chat with a White Hat podcast artwork

PODCAST · business

Chat with a White Hat

Real stories from the people breaking and defending the internetEvery week, Michel Chamberland sits down with a cybersecurity professional to dig into the moments that shaped their career, from their first encounter with a computer to the coolest hack they ever pulled off.Every guest answers the same core questions, giving you a unique window into how different people approach the same craft. Whether you're a seasoned red teamer, a bug bounty hunter, a vulnerability analyst, or just getting started, there's something here for you.

Publisher-supplied feed metadata · PodParley refreshed Jun 13, 2026 · Source feed

  1. 108

    A Hacker's Lesson: How a Small Mistake Took Down a Retail Company

    A cybersecurity professional shares a learning experience from causing a small outage at a retail company and emphasizes the importance of monitoring tools and long-term learning lessons.TakeawaysImportance of monitoring toolsLong-term learning lessonsChapters00:00 Learning from a Small Outage16:00 The Importance of Monitoring Tools

  2. 107

    Grit: The Key to Tech Success

    The conversation delves into the importance of grit and determination in achieving success, particularly in the context of technology and organizational value. It highlights the significance of perseverance and resilience in breaking through barriers and proving one's worth.TakeawaysGrit is essential for successDemonstrating grit is crucial for proving value in an organizationChapters00:00 The Power of Grit54:38 Demonstrating Grit in Technology

  3. 106

    Will AI Replace Penetration Testing Experts?

    The conversation explores the future of penetration testing and the role of AI in this field. It discusses the changing landscape of technology and the increasing complexity of testing.TakeawaysAI will replace mundane tasks in penetration testing.Deep knowledge of technology is essential for penetration testing.Chapters00:00 The Future of Penetration Testing24:48 AI in Penetration Testing

  4. 105

    Preparing Environments for Hackers

    The conversation delves into the speaker's role in preparing the environment for hackers and the importance of mentoring and advising. It then transitions to the speaker's interest in understanding system integration and making different systems work better together.TakeawaysMentoring and advising hackersUnderstanding system integration and traffic directionChapters00:00 Preparing the Environment for Hackers

  5. 104

    Penetration Testing: QA with Extra Steps

    The conversation delves into the misconceptions around security testing and penetration testing, highlighting the problem-solving nature of these practices and the focus on identifying and addressing vulnerabilities.TakeawaysSecurity testing is often misunderstood as something glamorous and dramatic, but it's more about problem-solving and finding vulnerabilities.Penetration testing is like QA with extra steps, focusing on identifying gaps and finding solutions.Chapters00:00 Demystifying Security Testing

  6. 103

    Pentesting: The Importance of Fundamentals

    The conversation covers the importance of effective testing practices, the significance of attention to detail, and the role of client communication and defense in the field of security testing.TakeawaysAttention to detail is crucial for better testing results.Effective client communication and defense require a strong understanding of the testing process.Chapters00:00 Effective Testing Practices

  7. 102

    AI in Security: Short & Long Term

    Ed Williams discusses the current and future use of AI in his work, emphasizing a cautious approach and the need for security considerations.TakeawaysCautious approach to AISecurity considerations for AIChapters00:00 Current Use of AI in Work

  8. 101

    AI in Cybersecurity: 2026 Advice

    The conversation covers valuable advice for individuals looking to break into cyber security and pen testing, emphasizing the importance of personal branding and the integration of AI in the field.TakeawaysBuild a personal brand to demonstrate seriousness and commitment.Consider the integration of AI in pen testing for future career prospects.Chapters00:00 Breaking Into Cyber Security

  9. 100

    Guest Spotlight: Meet Nick Aures

    Nick Aures introduces himself and provides a brief overview of his experience in pen testing and IT work.TakeawaysNick Aures is a senior pen tester at Sprocket Security.He has eight years of experience in pen testing and two years in defensive security.Chapters00:00 Introduction and Background

  10. 99

    AI's Impact on Cybersecurity: Offense & Defense

    The conversation delves into the impact of AI on cybersecurity, discussing its influence on both offense and defense. It also explores the acceleration of change in cybersecurity and the necessity for professionals to keep up with new developments. The dialogue emphasizes the need for adaptation and the potential obsolescence of traditional compliance pen tests.TakeawaysAI is lowering the bar for cyber attacksThe rapid pace of change in cybersecurity requires constant adaptationChapters00:00 The Impact of AI on Cybersecurity

  11. 98

    Passion and Commitment: Keys to Success

    The conversation emphasizes the importance of passion and commitment in achieving success. Mike highlights the value of being passionate and committed, and how it can lead to significant progress and growth in one's career. He also emphasizes the need to consume as much information as possible and to be obsessed with learning and improvement.TakeawaysPassion and commitment are key to successContinuous learning and obsession with improvement are essential for growthChapters00:00 The Power of Passion

  12. 97

    Turbopentest: Find Hidden Vulnerabilities

    The conversation covers the importance of ongoing pen testing and the demonstration of Gentic Pen Test. It emphasizes the need for continuous testing to identify hidden vulnerabilities and make smarter security decisions.TakeawaysContinuous pen testingIdentifying hidden vulnerabilitiesChapters00:00 Gentic Pen Test Demo

  13. 96

    Security Testing: Not as Glamorous as Movies

    The conversation delves into the misconceptions surrounding security testing, highlighting the meticulous and less glamorous nature of the process.TakeawaysSecurity testing is not as glamorous as people thinkIt requires meticulous attention to detailChapters00:00 Misconceptions About Security Testing

  14. 95

    Mike Shares His Experience at a High-Stakes Hacking Event

    Mike describes his experience at a live hacking event where he was invited to participate in finding vulnerabilities in a critical financial application. The event provided an overview of the technology and emphasized the significance of the application's impact and the importance of finding vulnerabilities.TakeawaysLive hacking events provide opportunities to identify vulnerabilities in critical applications.Understanding the significance of an application's impact is crucial for prioritizing vulnerability identification.Chapters00:00 Live Hacking Event

  15. 94

    AI Boosts Penetration Testing Speed

    The conversation covers the evolution of cloud code and its use with MCP servers, as well as the increasing power of penetration testing with AI agents and token budgets. The future of testing is discussed, highlighting the need for faster and more frequent testing.TakeawaysCloud CodePenetration TestingAI Agent and Token BudgetChapters00:00 The Evolution of Cloud Code and MCP Servers

  16. 93

    Understanding Vulnerability Impact

    The conversation delves into the importance of articulating the impact of vulnerabilities, emphasizing the significance of understanding the impact for classification, prioritization, and fixing of vulnerabilities.TakeawaysArticulating vulnerability impact is crucialUnknown impact requires further explorationChapters00:00 Understanding Vulnerability Impact

  17. 92

    AI's Impact on Penetration Testing

    The conversation covers the impact of AI on code writing and pen testing, highlighting the potential for AI to accelerate in the wrong direction.TakeawaysAI is increasingly writing codeAI can be used to fight AIAI can accelerate in the wrong directionChapters00:00 AI in Pen Testing

  18. 91

    Web App Pen Testing: Eye-Opening Factor

    The conversation delves into the significance of application penetration testing and the eye-opening factor it provides. It also highlights the prevalence of web applications in modern life and the security implications associated with them.TakeawaysApplication penetration testingWeb application securityChapters00:00 The Eye-Opening Factor of Application Penetration Testing

  19. 90

    Learn to Build Before You Break

    The conversation emphasizes the importance of learning to build things first and the significance of understanding in the field of cybersecurity. It highlights the value of programming skills and the impact of understanding on effectively exploiting vulnerabilities.TakeawaysLearn to build things firstUnderstanding is keyChapters00:00 The Importance of Learning to Build Things

  20. 89

    Mike's Favorite Security Testing: Infrastructure & Cloud

    The conversation explores the diverse types of security testing and emphasizes the importance of infrastructure testing in the field of cybersecurity.TakeawaysDiverse types of security testingImportance of infrastructure testingChapters00:00 Exploring Security Testing Types

  21. 88

    AI: The New Computer

    The conversation explores the inevitability of AI integration in everyday life, drawing parallels to the adoption of computers. It also delves into the hope that AI will provide more time for leisure activities and creative pursuits.TakeawaysAI integration is inevitableAI may provide more time for leisure and creativityChapters00:00 Hope for More Leisure and Creativity

  22. 87

    Code Review: My Preferred Approach

    The conversation covers different approaches to code reviews, the importance of setting up and running the code, and how time constraints impact the approach to code reviews.TakeawaysCode review approachesSetting up and running the codeTime constraints impact approachChapters00:00 Code Review Approaches

  23. 86

    Security Testing: More Than Just Scanning

    The conversation covers the misconceptions about security testing and highlights the manual probing and hard thinking involved in the process.TakeawaysMisconceptions about security testingManual probing and hard thinking involved in security testingChapters00:00 Misconceptions About Security Testing

  24. 85

    AI in Security: Short & Long Term

    The conversation covers the impact of AI on security and the integration of AI optimization into normal operations.TakeawaysAI's impact on securityIntegration of AI into normal operationsChapters00:00 AI and Security

  25. 84

    Hack: Domain Admin Password in 20 Seconds

    The conversation covers a quick hack experience during infrastructure testing and the importance of checking for vulnerabilities. It emphasizes the need for thorough security checks and highlights the lessons learned from the experience.TakeawaysInfrastructure testingImportance of checking for vulnerabilitiesChapters00:00 The Quick Hack

  26. 83

    Exploiting SAML Audience Misconfigurations

    The conversation delves into the topic of SAML hacking and the exploitation of audience attributes in service provider initiated scenarios. It highlights the significance of audience attributes in SAML requests and the potential security vulnerabilities associated with them.TakeawaysSAML hacking involves exploiting audience attributes in service provider initiated scenarios.Audience attributes in SAML requests can lead to authentication vulnerabilities if not properly checked.Chapters00:00 SAML Hacking and Audience Attributes

  27. 82

    Hacking Prison Management System

    The conversation covers the discovery of a well-secured application called Black Creek, the exploration of a prison management system, and the acquisition of network credentials to access a server.TakeawaysBlack CreekPrison ManagementNetwork CredentialsChapters00:00 Black Creek Application

  28. 81

    AI in Cybersecurity: Offensive & Defensive Uses

    The conversation covers the use of AI in quick development and automation, as well as its impact on cybersecurity in offensive and defensive applications. IQimpz discusses the ways in which AI is utilized for rapid code development and automation, as well as its role in offensive and defensive cybersecurity strategies.TakeawaysAI in quick developmentAI in cybersecurityAI in offensive and defensive securityChapters00:00 AI in Quick Development and Automation

  29. 80

    AI & Cybersecurity: The Unpredictable Future

    The conversation delves into the unforeseen growth of the internet and the challenges it presents for cybersecurity. It also explores the future of the internet and cybersecurity, the pace of change in cybersecurity, and the need for progress in cybersecurity.TakeawaysInternet growthCybersecurity challengesChapters00:00 The Unforeseen Growth of the Internet

  30. 79

    Security Testing: More Than Just Hacking

    The conversation delves into the importance of reporting in offensive security, highlighting the need to convey the impact of work and balance hacking with reporting responsibilities.TakeawaysReporting is crucial in offensive securityBalancing hacking and reporting is essential for effective penetration testing.Chapters00:00 The Importance of Reporting in Offensive Security

  31. 78

    Guest Spotlight: Philip's Journey into Cybersecurity

    The conversation covers the early exposure to computers and the influence of family on the interest in computers.TakeawaysEarly exposure to computersInfluence of family on interest in computersChapters00:00 Early Exposure to Computers

  32. 77

    Domain Admin Password in Plain Sight

    Discovering a critical security flaw in infrastructure testing led to the realization of the importance of thorough checks and vigilance. The incident highlighted the need to verify all aspects of the system to uncover potential vulnerabilities.TakeawaysThorough checks are essentialVigilance is keyChapters00:00 Infrastructure Testing and Security Flaws

  33. 76

    AI in Cybersecurity: Friend or Foe?

    The conversation delves into the use of AI in security, addressing concerns, optimization, bug discovery, code generation, and its role in penetration testing. It also highlights the need for human guidance in AI-driven security testing.TakeawaysAI is being used in security for reporting, password cracking, and bug discovery.AI is seen as a force multiplier for pen testers, making good pen testers better and bad ones worse.Chapters00:00 AI in Security

  34. 75

    Hacking Financial Infrastructure

    The conversation delves into the significance of the technology being discussed, particularly its impact on the financial industry and the associated vulnerability concerns.TakeawaysImportance of the TechnologyVulnerability AwarenessChapters00:00 The Significance of the Technology

  35. 74

    Hacking with Perl: A Cybersecurity Journey

    The conversation delves into the early days of computer security and the transition from Perl to Python, providing insights into the tools and techniques used during that time.TakeawaysEarly days of computer securityTransition from Perl to PythonChapters00:00 Early Days of Computer Security

  36. 73

    From BBC Micro to Red Teaming (Ed Williams on Hacking, AI & Cybersecurity)

    New episode of Chat with a Whitehat is live.In this Episode, Ed Williams shares his journey from early BASIC programming to leading modern red team operations. We dive into real-world penetration testing stories, offensive security insights, and how AI is reshaping the field—while fundamentals still remain the key to success.00:00 – 00:32 | Introduction & Ed Williams’ background00:32 – 02:56 | Early interest in computers (BBC Micro & BASIC)02:56 – 04:05 | Getting into cybersecurity & university experience04:05 – 05:48 | Early tools, Perl vs Python, and learning to hack05:48 – 07:09 | Building projects (mini kernel, remote bash, Unix systems)07:09 – 08:30 | Fastest hack ever (domain admin in seconds)08:30 – 09:59 | Real-world red teaming & social engineering stories09:59 – 12:42 | Bank engagements & physical security testing12:42 – 14:45 | Favorite type of security testing (infrastructure vs web)14:45 – 17:09 | Importance of planning in penetration testing17:09 – 18:07 | Time management & lessons learned during tests18:07 – 19:33 | How to get better results in security testing19:33 – 23:43 | How AI is being used in cybersecurity today23:43 – 27:32 | AI’s impact on offensive & defensive security27:32 – 29:33 | Biggest misconceptions about penetration testing29:33 – 30:41 | Most underestimated attack vector (passwords)30:41 – 32:41 | Why fundamentals matter in cybersecurity32:41 – 35:19 | Advice for breaking into cybersecurity (2026)35:19 – 36:10 | Where to find Ed Williams & closing remarks

  37. 72

    SQL Injection: Fingerprinting DBMS

    The conversation delves into the nuances of database exploitation and vulnerability, emphasizing the importance of understanding the type of SQL and backend used. It also highlights the significance of database documentation and fingerprinting in the context of cybersecurity.TakeawaysDatabase exploitation depends on the type of SQL and backend usedUnderstanding database documentation and fingerprinting is crucialChapters00:00 Database Exploitation and Vulnerability

  38. 71

    AI in Cybersecurity: Offensive & Defensive Shift

    The conversation delves into the impact of AI on cybersecurity, both in offense and defense. It also explores the accessibility of pen testing for small businesses and individuals, highlighting the changing landscape of cybersecurity.TakeawaysAI impact on offensive and defensive cybersecurityAccessibility of pen testing for small businesses and individualsChapters00:00 AI Impact on Cybersecurity

  39. 70

    Hack: Domain Admin Password in 20 Seconds

    Ed Williams shares some of the coolest hacks he has pulled off, including a quick domain admin password discovery and social engineering tactics for gaining access to secure buildings.TakeawaysVulnerability enumeration is crucial in infrastructure testing.Social engineering can be used to gain physical access to secure buildings.Chapters00:00 Quick Domain Admin Hack

  40. 69

    Exploiting SAML Audience Misconfiguration

    The conversation covers the exploitation of SAML authentication and the vulnerability related to the Audience URI. It also delves into bug bounty and pen testing strategies for identifying and exploiting these vulnerabilities.TakeawaysSAML authentication exploitationAudience URI vulnerabilityChapters00:00 SAML Authentication Exploitation

  41. 68

    Fighting AI with AI: The Future of Pen Testing

    The conversation explores the impact of AI on software development and testing, highlighting the evolution of development processes and the challenges and opportunities presented by AI in testing.TakeawaysAI in software developmentImpact of AI on testingChapters00:00 The Evolution of Software Development with AI

  42. 67

    CSS Injection Leads to Zero-Day Vulnerability

    The conversation covers the discovery of HTML to PDF vulnerabilities, uncovering CSS injection vulnerabilities, and exploiting zero-day vulnerabilities to demonstrate significant security impacts. It highlights the importance of thorough security testing and the potential impact of zero-day vulnerabilities.TakeawaysHTML and CSS injection can lead to significant security vulnerabilitiesUncovering zero-day vulnerabilities can have a substantial impactChapters00:00 Discovering HTML to PDF Vulnerabilities

  43. 66

    Security Testing: Not Glamorous, But Essential

    The conversation delves into the misconceptions and realities of cybersecurity, highlighting the lack of glamour and the monotonous, meticulous nature of the work. It also touches on the unsocial and frustrating aspects of the field.TakeawaysCybersecurity is not as glamorous as people thinkIt can be unsocial and frustrating at timesChapters00:00 The Monotony and Meticulousness of Cybersecurity

  44. 65

    Pentesting: A Fool's Errand?

    The conversation covers Neil Kettle's favorite testing methods, the challenges of pen testing, and the application of first principles in security testing.TakeawaysFavorite testing methodsChallenges of pen testingFirst principles in security testingChapters00:00 Favorite Testing Methods and Challenges

  45. 64

    The Importance of Articulating Vulnerability Impact

    The conversation covers the importance of articulating the impact of vulnerabilities and the use of AI for quick development and automation. It emphasizes the significance of understanding and communicating the impact of vulnerabilities and the benefits of using AI for rapid development and automation.TakeawaysArticulating the impact of a vulnerability is crucialUsing AI for quick development and automationChapters00:00 Articulating the Impact of Vulnerabilities

  46. 63

    Journey into Cybersecurity: HaxrByte's Story

    The conversation covers the journey from gaming to cybersecurity, the future of red teaming and pen testing, learning from previous engagements, and the impact of AI on security operations.TakeawaysEarly exposure to gaming led to an interest in cybersecurityImpact of AI on red teaming and pen testingChapters00:00 From Gaming to Cybersecurity17:34 The Future of Red Teaming and Pen Testing24:58 Learning from Previous Engagements33:32 AI's Impact on Security Operations

  47. 62

    SQL Injection: Understanding the Backend

    The conversation covers the importance of understanding the backend code for hacking and the value of documentation in dealing with SQL injection vulnerabilities.TakeawaysUnderstanding the backend code helps with hackingDocumentation is super helpful for SQL injectionChapters00:00 Understanding the Backend Code

  48. 61

    AI in Cybersecurity: 2026 Advice

    The conversation covers advice for individuals looking to break into cyber security and pen testing, emphasizing the importance of showcasing expertise through a blog or YouTube channel and considering automation with AI.TakeawaysStart a blog or YouTube channel to showcase expertiseConsider automation with AI in cybersecurityChapters00:00 Breaking into Cyber Security and Pen Testing

  49. 60

    CSS Injection Leads to Major Security Breach

    The conversation covers the exploitation of SSRF and LFI vulnerabilities, leading to an account takeover and unauthorized data access. It also highlights the recognition received for the impactful zero-day vulnerability and its real-world consequences.TakeawaysSSRF and LFI vulnerabilities led to account takeover and data accessImpactful zero-day vulnerability led to significant consequencesChapters00:00 Recognition for Impactful Zero-Day Vulnerability

  50. 59

    Dylan’s Quick Introduction

    Dylan Lahan, a full-time bug bounty hunter and independent security researcher, shares insights on ethical hacking and cybersecurity.TakeawaysEthical hacking as a careerImportance of bug bounty programsChapters00:00 Introduction to Ethical Hacking and Bug Bounty Hunting

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Real stories from the people breaking and defending the internetEvery week, Michel Chamberland sits down with a cybersecurity professional to dig into the moments that shaped their career, from their first encounter with a computer to the coolest hack they ever pulled off.Every guest answers the same core questions, giving you a unique window into how different people approach the same craft. Whether you're a seasoned red teamer, a bug bounty hunter, a vulnerability analyst, or just getting started, there's something here for you.

HOSTED BY

Michel Chamberland

Frequently Asked Questions

How many episodes does Chat with a White Hat have?

Chat with a White Hat currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Chat with a White Hat about?

Real stories from the people breaking and defending the internetEvery week, Michel Chamberland sits down with a cybersecurity professional to dig into the moments that shaped their career, from their first encounter with a computer to the coolest hack they ever pulled off.Every guest answers the...

How often does Chat with a White Hat release new episodes?

Chat with a White Hat has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Chat with a White Hat?

You can listen to Chat with a White Hat on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Chat with a White Hat?

Chat with a White Hat is created and hosted by Michel Chamberland.
URL copied to clipboard!