Legitimate Cybersecurity Podcasts podcast artwork

PODCAST · technology

Legitimate Cybersecurity Podcasts

Legitimate Cybersecurity Podcasts

Publisher-supplied feed metadata · PodParley refreshed Sep 2, 2026 · Source feed

  1. 67

    SpaceX IPO: Did You Just Fund a Spy Network?

    The SpaceX IPO is being sold as rockets, innovation, and the future of space. But investors may have also bought into a private network with battlefield, intelligence, and surveillance potential. In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer examine what the SpaceX IPO really means when you look beyond rockets and stock hype. Starlink has already proven how powerful satellite internet can be in remote regions and war zones. Starshield raises an even bigger question: what happens when the same company building consumer satellite internet also builds national-security infrastructure? This is not a claim that SpaceX is spying on Americans. It is a question about capability, incentives, oversight, and public-market funding. If Starlink can shape connectivity in Ukraine and Russia, and Starshield is built for government and intelligence use, what stops similar infrastructure from becoming part of domestic surveillance, border enforcement, emergency response, law enforcement, or classified government operations? And if that happens, would ordinary citizens or retail investors ever know? Frank and Dustin discuss: * Why the SpaceX IPO changes the public-interest question * The difference between Starlink and Starshield * How satellite internet became a war-zone capability * Why private infrastructure can become public power * Whether investors understand what they actually bought * Why regulation always arrives after someone sticks their finger in the pencil sharpener * The uncomfortable line between innovation, profit, warfare, and surveillance Media/interview: mailto:[email protected] Audio: https://legitimatecybersecurity.podbean.com/ Hosted by Frank Downs and Dr. Dustin Brewer. Chapters: 00:00 - Did SpaceX Just Become the Biggest IPO Ever? 01:06 - Why Everyone Loves Rockets 02:23 - Starlink vs. Starshield Explained 03:52 - Why Starlink Is Different From Old Satellite Internet 05:22 - The Good Side: Remote Access and Global Connectivity 06:41 - How Starlink Changed Modern War 07:21 - Drones, Jamming, Fiber Optics, and Satellite Links 08:44 - Should One Company Control Battlefield Connectivity? 10:46 - Is This Different From Traditional Arms Dealers? 13:22 - Why the IPO Changes the Question 14:45 - Lockheed, Palantir, Boeing, and Public Funding 16:59 - Did Investors Know What They Bought? 17:28 - The Elon Musk Factor and Private Decision-Making 18:52 - Rockets Are Cool — The Implications Are Harder 20:02 - The Hidden Cost of Powerful Technology 22:12 - Starshield and Government Intelligence Contracts 23:23 - When Safety Tools Become Tracking Tools 24:32 - Could Becomes Should: The Jurassic Park Problem 29:32 - Shareholder Value vs. Human Consequences 31:00 - Facebook, Terrorists, and “We Just Connect People” 35:32 - Why Regulation Exists 37:23 - Who Should Decide Who Gets the Network? 38:33 - Final Thoughts: Know What You Invest In #spacex #starlink #Starshield #cybersecurity #surveillance #ipo #privacymatters #nationalsecurity #techethics #legitimatecybersecurity #ai

  2. 66

    They Send a Fake IT Guy to Hack Your Office

    The hacker isn't a thousand miles away in a hoodie. He's standing at your desk in a polo shirt, holding a clipboard, asking to plug something into your computer. And law firms are the target. Frank Downs and Dustin Brewer break down the Silent Ransom Group — the crew skipping the phishing email and walking straight through the front door. In this episode of Legitimate Cybersecurity, Frank and Dustin dig into SRG (aka Luna Moth, aka Chatty Spider), a Conti offshoot now assessed — and corroborated by an FBI FLASH alert — to be running physical IT-impersonation attacks against law firms and other data-rich targets. They discuss why physical social engineering is suddenly back from the 1990s, the cyber-psychology that makes us trust a stranger with a lanyard, Dustin's casino fake-badge pen test, why law firms are such a rich target (trade secrets, M&A, criminal defense, HIPAA data), and the brutally simple fix most companies skip: trust but verify. The conversation also covers why "keyboard Frank" is a different person, the hospital HIPAA nightmares you've personally witnessed, and AI's role on both sides of the kill chain. The one thing to leave with: if an IT person shows up unannounced, it costs you nothing to call IT and confirm before you let Steven in. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 — The hacker shows up at your door 00:36 — Mandiant + FBI: who Silent Ransom Group really is 02:39 — The cyber-psychology of "why physical works" 06:00 — War story: the student who ran from the front desk 08:00 — Cutouts, proxies, and unwitting accomplices 11:53 — Why physical access does damage instantly 12:09 — Law firms: the richest target set there is 15:46 — Mar-a-Lago, thumb drives, and the history of in-person hacks 19:08 — Tailgating past security (Dustin's seventh-floor proof) 20:58 — Trust but verify: the fix that actually works 26:26 — The societal norms bad guys exploit 27:02 — The casino badge: getting your face "known" 28:00 — The human is always the weakest link 29:41 — AI is only as smart (and hackable) as we are 32:12 — Keep on cybering #Cybersecurity #SocialEngineering #Hacking #InfoSec #DataPrivacy #LawFirms #PenTesting #AI #CyberAwareness #SilentRansomGroup #LunaMoth #PhysicalSecurity

  3. 65

    AI-Built Apps Are Leaking Private Company Data

    Researchers just found thousands of AI-built apps leaking medical records, financial data, and customer PII straight to the open internet. The scary part isn't that AI writes code — it's that it writes code just well enough that nobody asks questions. Frank Downs and Dustin Brewer break down the hidden cost of vibe coding: insecure-by-default software shipped to production, AI tools replacing the junior developers who'd grow into the people who fix it, and AI quietly wired into services you never consented to — including a dentist's chair that records every cleaning and sends it to an insurance-linked system. AI learned security from us. And we were never good at it. 🎙️ Listen: https://legitimatecybersecurity.podbean.com/ 📩 Media/interview: [email protected] Hosted by Frank Downs and Dustin Brewer. Chapters: 00:00 The code works — that's the problem 01:24 "Do you consider yourself a coder?" 03:15 What AI actually learned to copy (us) 04:58 Vibe-coded tools running in production 05:19 3,380 exposed apps, 5,000 data leaks 07:56 Who fixes it when the cyber team finds holes? 08:26 The $1.5M QA cut that cost $6M 09:35 AI talking to AI: nobody reads the code 15:21 "Your password is God" — security never changed 16:27 Should AI touch the live service? 17:48 The dentist chair that records everything 21:00 Where the line actually is (help desk vs. prod) 24:20 AI monitoring employees & the gold-standard trap 28:23 Always-on "streaming AI" is 5 years out 29:25 The coming AI caste system 30:34 Adversaries already use it (the Lego propaganda) 33:14 We're about to lose every junior analyst 40:15 The Twitter "efficiency" parallel 41:35 Keep on cybering #vibecoding #cybersecurity #aisecurity #dataprivacy #shadowit #infosec #aitools #privacy #devsecops #surveillance

  4. 64

    AI Pioneer Warns: AI Wants Your Private Files

    AI companies are running out of easy data — and the next target may be your private files, calendars, medical records, photos, and desktop activity. AI pioneer Dr. Jonathan Schaeffer joins Frank Downs and Dustin Brewer to explain why today’s AI tools are powerful, flawed, and increasingly hungry for personal data. In this episode of Legitimate Cybersecurity, Frank and Dustin talk with Dr. Jonathan Schaeffer, University of Alberta Professor Emeritus, AI pioneer, AAAI Fellow, entrepreneur, and founder of Synsara. They discuss why today’s chatbot boom is not the AI future many researchers imagined, why “hallucination” is the wrong word for AI errors, how AI companies depend on more and more data, and why desktop AI tools may create a new privacy boundary problem. The conversation also covers AI bias, manipulation, private data, local AI, regulation, data centers, environmental costs, and why solving AI’s safety and privacy problems should matter before the race to AGI gets even faster. Dr. Schaeffer’s key warning is that current AI systems do not understand the consequences of their answers, yet people increasingly treat them like trusted authorities. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 — AI’s privacy problem is getting bigger 01:27 — Jonathan Schaeffer’s AI origin story 03:29 — Beating humans at checkers before Deep Blue 05:48 — Why modern AI feels like the wrong future 07:50 — Why “hallucination” is the wrong word 09:01 — How “chat” created false trust 10:32 — AI does not understand consequences 13:52 — Why AI companies are desperate for data 15:12 — Your private files are the real gold mine 16:32 — The hidden cost of “free” AI tools 20:44 — AI wants access to your desktop 22:50 — The safety, security, and privacy problem 24:05 — The AGI race is moving faster than safeguards 27:07 — Why Jonathan built private local AI tools 30:59 — The security risk nobody talks about 32:31 — Why AI systems need audits 34:21 — When AI answers become manipulation 39:13 — Influence, rage content, and algorithmic persuasion 42:21 — Why AI regulation cannot keep up 46:05 — Canada’s failed attempt to regulate AI 50:40 — Is it already too late? 55:16 — What polar exploration teaches us about AI risk 59:39 — Data centers, power, water, and responsibility 1:03:18 — Jonathan’s life advice: fun beats money #ArtificialIntelligence #AIPrivacy #Cybersecurity #DataPrivacy #ChatGPT #AISafety #Privacy #TechPolicy #LegitimateCybersecurity #Synsara

  5. 63

    Your Ex May Still Have Access to Your Phone

    Your ex may still have access to your accounts, your phone, or your private life — even after you changed your password. This episode explains how cyberstalking hides inside logged-in devices, shared biometrics, old account access, and security questions people close to you already know. On this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer break down real cyberstalking cases involving toxic exes, stolen images, account impersonation, hidden device access, and the overlooked settings that keep people exposed. Most people think the danger is “getting hacked.” But in toxic relationships, the real danger is often simpler: someone close to you already had the key. Frank and Dustin explain: Why changing your password may not log someone out How old devices can stay connected to your accounts Why shared phones, laptops, and biometrics create risk How security questions can be abused by people who know you What warning signs suggest someone may be monitoring you Where to get professional help if this is happening to you This episode is part of our cyber safety series for people dealing with toxic relationships, stalking, harassment, and digital abuse. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 — Your Ex, Walmart, or the State Agency Problem 00:51 — Why Cyberstalking Is Now Everyday Life 01:27 — Case 1: She Changed Her Password, But He Stayed Logged In 03:39 — Why “Logged-In Devices” Are So Hard to Read 05:20 — Don’t Share Accounts in Relationships 07:28 — The Netflix / Hotel TV Problem 08:20 — Why Access Tokens Keep People Logged In 10:21 — Marriott, Hotel TVs, and Automatic Logouts 11:41 — Case 2: Private Images Posted for 14 Years 13:36 — The Law Slowly Caught Up 14:41 — Photos, Trust, and Digital Leverage 16:32 — Treat Your Phone Like a Toothbrush 17:43 — Red Flags: When They Know Things They Shouldn’t 20:20 — Case 3: He Added His Thumbprint to Her Phone 22:28 — Why Biometrics Can Become Relationship Risk 23:31 — Used Phones, Forensics, and Hidden Data 28:27 — Don’t Let Someone Else Use Your AI Either 30:49 — Security Questions Are Broken 32:08 — Personal Cyber Hygiene Checklist 34:18 — One Year of Legitimate Cybersecurity 34:53 — Where to Get Real Help 35:46 — Keep on Cyberin’ #cyberstalking #cybersafety #digitalsafety #toxicrelationships #onlineprivacy #phonesecurity #cybersecurity #domesticabuseawareness #dataprivacy #legitimatecybersecurity

  6. 62

    A $29 Tracker Could Be Following You Right Now

    One could be hidden in your car, purse, luggage, or jacket — and it may cost less than dinner. Bluetooth trackers were built to find lost keys, but they can also turn nearby phones into a surveillance network. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer break down how AirTags, Tile trackers, Samsung SmartTags, Find My-compatible devices, and other Bluetooth beacons can be abused for stalking, theft, and surveillance. They explain why these devices do not “call home” like GPS trackers, how nearby phones quietly report their location, why some safety alerts can fail, and what to do if you suspect someone is tracking you. This episode also covers real-world cases involving hidden trackers, vehicle sweeps, modded AirTags, stalkerware, smart clothing, and the broader problem of everyday devices becoming personal surveillance infrastructure. If you think you may be in danger, contact professionals who can help: National Domestic Violence Hotline: 1-800-799-7233 Coalition Against Stalkerware: StopStalkerware.org Operation Safe Escape: SafeEscape.org Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 0:00 — A $29 tracker could be on you 0:46 — Why Bluetooth trackers changed personal safety 2:55 — How AirTags actually track location 5:18 — Why abusers use trackers instead of GPS 7:18 — AirTags, Find My, and Apple’s safety alerts 10:04 — Tile trackers and the limits of smaller networks 11:38 — Samsung SmartTags and smart home tracking 13:07 — Modded trackers and the speaker loophole 14:31 — The ethics of tiny surveillance devices 18:48 — Cars, phones, and surveillance double standards 22:33 — Real cases where trackers led to violence 24:27 — Pattern-of-life tracking in the real world 26:48 — Flipper Zero, Bluetooth footprints, and NFC risks 33:12 — What to do if you think you’re being tracked 34:00 — Where to search your car for hidden trackers 35:37 — Behavioral signs someone may be monitoring you 37:23 — Smart clothing and Bluetooth tracking risks 39:41 — Resources for stalking and domestic violence help 41:09 — Final thoughts #cybersecurity #airtag #BluetoothTracking #digitalprivacy #Stalkerware #personalsafety #surveillance #smartdevices #legitimatecybersecurity

  7. 61

    An Aquarium Hacked A Casino. Your House Is Next

    Gloria Globman — CTO of Acclaimed Technical Services, former Senior Cyber Advisor at the US Embassy in Tokyo, US Navy veteran, and Presidential Rank Award recipient — joins Frank Downs and Dustin Brewer to translate what's really happening on your home network. Every smart device is a tiny computer with a camera, a microphone, and an internet connection, constantly talking to its manufacturer, the cloud, and other devices on your Wi-Fi. Many of them will never be patched again. Some of the manufacturers don't even exist anymore. In this episode we cover why mid-sized companies keep underfunding security until it's too late, how AI tools like Mythos and Zealot are compressing the patch window to almost nothing, why the upcoming TP-Link ban probably won't save you, and the simple home-router moves that actually do. If you've ever brought a personal phone onto the work Wi-Fi, set up a smart camera you've stopped thinking about, or assumed "the cloud" means it's somebody else's problem — this one is for you. 🎙 Listen to the audio version: https://legitimatecybersecurity.podbean.com/ 📩 Media / interview requests: [email protected] 👥 Hosts: Frank Downs and Dustin Brewer 🎤 Guest: Gloria Globman, CTO, Acclaimed Technical Services Chapters: 00:00 The IoT problem nobody locks down 00:36 Meet Gloria Globman — Tokyo, the IC, and 20 years of cyber 02:10 Your smart devices are unlocked front doors 03:51 Cognitive offloading: convenience until it isn't 04:42 The aquarium that hacked a casino (MGM) 05:17 Are IoT devices just printers 2.0? 06:14 When personal phones meet corporate Wi-Fi 08:35 Work moved home — security posture didn't 09:19 Mid-sized companies and the 15–20% rule 10:16 Why "not sexy" budgets keep getting cut 11:24 Highest-impact moves: zero trust, segmentation, encryption 12:16 Patch, patch, patch — and why AI changed the timer 12:39 Mythos vs. Zealot: orchestrated AI attacks 16:09 Microsegmentation for your actual house 17:39 Why companies embrace BYOD anyway 18:48 Why VDI never quite won 22:18 Risk transference dysmorphia: "it's the cloud's problem" 22:53 Botnets, dead routers, and the FBI cleanup 23:24 Goodbye TP-Link — security move or theater? 26:25 What the average person should actually do tonight 28:21 Password managers, quantum, and MFA 29:44 Gloria's one piece of life advice #cybersecurity #iotsecurity #smarthome #zerotrust #byod #HomeNetworkSecurity #infosec #dataprivacy #patchtuesday #legitimatecybersecurity

  8. 60

    AI Is Now Faking Loved Ones and Setting Prices

    AI is no longer just answering prompts — it is imitating dead relatives, profiling shoppers, and helping companies decide what people pay. That matters because the same hidden data systems behind convenience can reshape grief, prices, privacy, work, and trust without clear consent. In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer break down a disturbing wave of AI and surveillance stories: AI avatars of deceased loved ones, Maryland’s move against surveillance pricing, Washington’s restrictions around public access to ALPR data, Virginia’s precise geolocation data ban, deepfake CEO scams, remote hiring impersonation, and employee webcam monitoring. The big question: When AI can imitate people, price you individually, and watch you at work, what does consent even mean anymore? Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 — AI avatars of dead loved ones 01:19 — Grief, deception, and consent 02:48 — When an AI “person” is not really a person 04:00 — Frank’s Afghanistan story and withheld grief 07:14 — The problem with resurrecting people through AI 09:16 — AI ghosts, Benjamin Franklin, and Disney presidents 10:58 — Maryland moves against surveillance pricing 12:37 — When dynamic pricing becomes predatory 14:38 — Market pricing vs. personal profiling 15:35 — Washington limits access to ALPR data 18:10 — Virginia bans precise geolocation data sales 21:30 — Location data, pricing, and individual targeting 22:56 — Deepfake CEO scams and wire-transfer fraud 24:17 — The “three-finger test” for deepfakes 26:04 — Remote hiring scams and AI impersonation 28:23 — Laptop farms, proxies, and scam infrastructure 29:56 — Employee webcam and microphone monitoring 34:30 — Final thoughts: stay dressed at work #ai #cybersecurity #privacy #surveillance #dataprivacy #Deepfakes #geolocation #SurveillancePricing #remotework #legitimatecybersecurity

  9. 59

    Can AI Agents Actually Hack Systems?

    A new AI is being framed as a tool that can find zero-days fast and even “hack its way out” of containment. If that claim is real, defenders, developers, and everyday users are about to feel the consequences. On this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer are joined by Jason Casey, CEO of Beyond Identity, to break down the panic around Anthropic’s “Mythos” discussion, what AI can actually do for offense and defense, and where the marketing may be outrunning the real-world risk. They dig into whether this is a true cybersecurity turning point, or the latest example of the industry turning fear into momentum. They also explore how AI is already reshaping blue team work, governance, detection, and security operations. Plus: hacked smart vacuums, trackable e-ink nails, wearable surveillance, and why convenience keeps creating new attack surfaces nobody asked for. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 The new AI panic begins 00:59 What “Mythos” is supposed to do 02:17 Is this a real threat or brilliant marketing? 07:12 Will this change security budgets and priorities? 10:11 Why cybersecurity leaders amplify moments like this 13:58 How AI actually helps blue teams 21:49 Rules, patterns, and better AI detection 23:59 The idea of an AI “security factory” 31:50 Beyond Identity’s new governance layer 35:30 Hacked vacuums, smart nails, and wearable tracking 45:00 Final takeaways #legitimatecybersecurity #artificialintelligence #cybersecurity #anthropic #claude #aisecurity #zerodayjay #blueteam

  10. 58

    Why Is LinkedIn Spying on Your Browser?

    A new lawsuit alleges LinkedIn may have been collecting data from inside users’ browsers in ways most people never expected. If that is true, this is not just normal tracking. It is a much more invasive look into how websites can profile you behind the scenes. In this episode of Legitimate Cybersecurity, Frank Downs and Dustin Brewer break down the class-action allegations against LinkedIn, explain browser extension detection in plain English, and talk about why so many people are fed up with paying for platforms that still treat their identity like a product. They also walk through what this kind of tracking could reveal about you, why regulation keeps falling behind, and what everyday users can do right now to limit exposure online. 📩 Media/interview: [email protected] 🎧 Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 LinkedIn is spying on you? 00:37 What this new lawsuit actually alleges 01:34 Why this one feels different 03:32 Why people are so fed up with LinkedIn 06:04 What websites can already learn about you 08:23 How browser extension detection works 10:13 Why this feels so invasive 14:51 What you can do to protect yourself 18:11 Browser vs app: which gives companies more access? 20:46 Consent, ethics, and hidden tracking 26:56 Will regulation ever catch up? 28:15 Final thoughts #linkedin #privacy #BrowserTracking #cybersecurity #dataprivacy #onlinetracking #surveillance #digitalprivacy #technews #legitimatecybersecurity

  11. 57

    What’s Inside the White House App?

    You expect a government app to inform you. You probably do not expect tracking capability, mystery dependencies, and sloppy security decisions. This episode breaks down why the White House app is a warning sign for anyone who installs “official” software without asking what it can really do. Frank Downs and Dustin Brewer dig into the White House app as a real-world case study in mobile privacy, dormant GPS functionality, third-party code dependencies, digital supply-chain risk, and the uncomfortable question of who is actually accountable when insecure software gets released. This is not just about one app. It is about the broader problem with modern software: hidden permissions, weak development practices, and the false assumption that “official” means secure. If you use apps from governments, brands, schools, banks, or anyone else you assume you can trust, this episode will make you think twice about what is really happening in the background. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Hosted by Frank Downs and Dustin Brewer on Legitimate Cybersecurity. Chapters: 00:00 – Why this app matters 00:50 – The White House app and dormant GPS capability 02:47 – Why “it’s off for now” is not reassuring 07:47 – Real-world GPS tracking through everyday apps 10:06 – Why taxpayers should care about this one 11:35 – Random dependencies and supply-chain risk 14:05 – How software supply-chain attacks really happen 18:35 – Incompetence vs malicious intent 24:47 – Leftover dev tools, WordPress, and security basics 27:46 – Who is actually accountable? 32:49 – Cybersecurity is a mindset, not a checkbox 36:18 – Which frameworks help and which get gamed 39:34 – Listener shout-outs and close #cybersecurity #appsecurity #dataprivacy #mobilesecurity #supplychainsecurity #privacy #WhiteHouseApp #infosec #LegitimateCybersecurity

  12. 56

    AI Is Already in Your Tools. No One Wrote the Rules

    AI is being forced into the tools you use every day before most companies have written real rules. That matters because one careless prompt can become a privacy, compliance, or job-risk problem fast. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Walter Haydock to break down what happens when AI shows up in Word, email, HR systems, search, and business workflows before organizations are actually ready for it. They unpack where companies get AI adoption wrong, why “just use it” is dangerous guidance, what accountability should look like, and how frameworks like ISO 42001 and the NIST AI RMF help organizations build rules before the damage is done. They also dig into AI hiring risks, shadow AI, risky models, and why some AI features feel more like forced adoption than useful innovation. If you’ve ever wondered whether AI is helping your company or quietly creating legal, privacy, and security risk, this episode is for you. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Subscribe for more conversations with Frank Downs and Dustin Brewer as they translate the hidden systems shaping everyday technology. Chapters: 00:00 AI is suddenly in your tools 01:14 Meet Walter Haydock 02:41 Every company needs AI rules 04:42 Why gray areas become risk 05:38 Advice for less technical businesses 09:44 ISO 42001 vs. NIST AI RMF 12:44 Who should own AI accountability? 14:24 AI in hiring and HR 20:50 Why bias never fully disappears 27:29 Will the U.S. regulate AI? 30:27 Where AI is being overused 38:27 Shadow AI and risky models 43:10 What StackAware does 44:23 Walter’s best advice #artificialintelligence #aigovernance #cybersecurity #privacy #compliance #shadowai #iso42001 #nist #techrisks #legitimatecybersecurity

  13. 55

    AI Is Replacing Tech Jobs With Insecure Code

    AI is starting to replace parts of white-collar work faster than most people realize. The bigger problem is that it may also flood the market with insecure code, weaker judgment, and fewer real entry-level paths. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer break down Anthropic’s latest report on the jobs most exposed to AI and explain what the headlines are getting wrong. They dig into the difference between AI exposure and actual job loss, why the data may be skewed toward technical users, and why roles like programmers, analysts, support specialists, and customer service reps are being hit first. They also tackle the deeper issue: if AI keeps making it easier for inexperienced people to ship software, are we about to create a massive wave of insecure code? This is not just a conversation about automation. It is a conversation about who still needs human judgment, where experience still matters, and why “efficiency” can quietly become a security problem. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ #cybersecurity #artificialintelligence #techjobs #softwaredevelopment #jobmarket #anthropic #automation #infosec #legitimatecybersecurity

  14. 54

    Your TV Is Recording What You Watch

    Your smart TV may be taking snapshots of what you watch, even when you think you bypassed the built-in apps. That data can be used to identify shows, measure advertisements, and help build a profile of behavior inside your home. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer explain how Automatic Content Recognition (ACR) works, why HDMI devices like Apple TV or gaming consoles may not stop it, and how companies correlate TV viewing with other data sources. They also break down why opting out can be difficult, how these systems are used for ad measurement and profiling, and what steps viewers can take right now to reduce the tracking. If you own a smart TV, streaming device, or connected home system, this episode explains what is actually happening behind the screen. 📩 Media and interview inquiries: [email protected] 🎧 Listen to the audio podcast: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 — Your TV Is Watching You Back 00:45 — What Automatic Content Recognition Actually Is 01:25 — How TVs Identify What You Watch 02:13 — Why HDMI Devices Do Not Stop It 05:25 — How Viewing Data Gets Linked to Your Phone 09:59 — Why Opting Out Is So Difficult 11:37 — Cameras, Microphones, and Smart Device Monitoring 18:51 — What You Can Do to Reduce Tracking 20:22 — VPNs, DNS Blocking, and Practical Limits 26:33 — The Real Takeaway: Every Screen Collects Data #cybersecurity #privacy #smarttv #dataprivacy #surveillance #smarthome #technology #streaming #legitimatecybersecurity

  15. 53

    After the Breach, the Legal Crisis Begins

    A cyber incident is not just a technical problem. The legal response can shape what happens next, what gets disclosed, and how much worse the damage becomes. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Kate Hanniford, cybersecurity and data privacy partner at Alston & Bird, to unpack the part of cyber incidents most people overlook: the legal side. Kate explains what really happens when the phone rings after a breach, how executives think under pressure, where regulators draw the line between bad luck and negligence, and why data retention can quietly become one of the biggest risks in an investigation. They also dig into SEC disclosure rules, outdated regulations, AI adoption risk, and the growing sophistication of state and federal regulators. This is a grounded look at what actually breaks after a cyber incident — and why the legal response matters just as much as the technical one. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ #cybersecurity #dataprivacy #incidentresponse #breachresponse #compliance #aigovernance #riskmanagement #legitimatecybersecurity Chapters: 00:00 Cyber incidents are legal incidents too 00:36 Meet Kate Hanniford 01:12 How Kate got into cybersecurity law 05:30 How lawyers specialize in cyber 08:34 What the first breach call feels like 12:32 How technical a cyber lawyer has to be 14:45 Which regulators worry companies most 18:47 Bad luck vs negligence in cybersecurity 19:57 Why data retention becomes a legal problem 22:17 The SEC four-day disclosure rule 27:43 Are cyber regulations outdated? 32:43 Which frameworks actually inspire confidence? 35:28 Does AI create more legal risk? 39:20 The fast question round 44:36 Kate’s best life advice #Cybersecurity #DataPrivacy #IncidentResponse #BreachResponse #Compliance #SEC #AIGovernance #RiskManagement #PrivacyLaw

  16. 52

    The FBI Isn’t Your Cyber Defense Anymore (It’s Privatized Now)

    America’s cyber “first responder” isn’t the FBI anymore—it’s private companies. That shift changes what gets prioritized during a breach: mission vs. margin, attribution vs. recovery, and who gets help first. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Milan Patel (Global Head of MDR at BlueVoyant, former FBI) to unpack what breaks when cyber defense gets outsourced—because it already has. Milan shares how the FBI actually works in real incidents, why private-sector response dominates, and the recurring failures that keep breaches happening “the same way, with a different cut of sushi.” You’ll learn: Why the private sector responds first ~95% of the time—and what the FBI really does when they arrive The 3 root causes Milan sees behind most breaches (and why they don’t go away) The hidden risk of “unknown, unprotected” network branches and configuration drift What AI will (and won’t) replace in MDR, SOC work, and incident response The real looming problem: training the next generation when Level 1 work gets automated Why AI agents inside your environment force a rethink of identity + data access controls Media / interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ If you want weekly breakdowns of the hidden systems shaping security (and the incentives nobody admits out loud), subscribe and join the conversation in the comments. Chapters: 0:00 Cold open: “The FBI used to be the frontline…” 0:55 Meet Milan Patel: FBI → private sector MDR 2:30 “How do I get into cyber?” Milan’s origin story 6:50 The FBI hiring gauntlet (and why honesty wins) 11:35 Quantico + the “blind monkey” field office lottery 14:05 “Too bad, you’re going cyber” (how cyber squads really looked back then) 17:35 The big shift: who responds first during breaches (and why) 20:10 Why companies don’t care about “catching the bad guy” mid-crisis 22:55 The same breaches keep happening—what people aren’t learning 23:30 Milan’s “3 causes” of most breaches: culture, funding, configuration 26:10 The generational gap in clicking, trust, and risk behavior 29:10 “What security do I even need?” (coverage vs. cost reality check) 31:15 The brutal truth: validating what’s actually deployed vs. what you think is deployed 33:00 AI in cybersecurity: what’s real vs. hype 34:35 “Don’t make me talk to a robot” — the last-mile human requirement 36:10 The coming SOC shift: fewer Level 1s, more “all Level 3” teams 37:25 The pipeline problem: how do juniors learn when grunt work is automated? 38:40 Vibe coding + security: why Milan’s confidence is rising (with guardrails) 44:10 AI arms race: faster attackers, same fundamentals 46:05 AI agents in your network = identity + data access crisis 49:00 Milan’s one life rule: “Focus on your sphere of influence” 49:40 Outro + “keep on cyberin’” #cybersecurity #incidentresponse #fbi #manageddetectionandresponse #ransomware #cybercrime #aisecurity #SOC #cyberrisk #infosec #legitimatecybersecurity

  17. 51

    AI Is Rewriting Compliance (GRC)

    Compliance isn’t “paperwork”—it’s the last line between your customers and the next Equifax-level mess. But GRC teams are stuck chasing screenshots and questionnaires instead of reducing real risk—and AI is about to change that. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Richa Kaul, CEO & Founder of Compliance (an AI-native enterprise GRC platform), right after her company’s $20M raise led by Google Ventures. We dig into: Why GRC gets hated (and how to stop being the “business blocker”) What real AI in compliance looks like vs. “LLM sticker on legacy software” The uncomfortable truth: audits shouldn’t disappear—and why incentives matter How to reduce hallucination risk with tight inputs/outputs + guardrails Third-party risk management (TPRM): the questionnaire nightmare… and the path out Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 – Compliance is the job (and also… you wanted to be an astronaut) 01:20 – Meet Richa Kaul + the “privacy nut” origin story 02:11 – $20M from Google Ventures: why GRC is getting real investment 02:52 – Quick GRC explainer (governance, risk, compliance) 03:35 – “Compliance is broken”: why everyone hates the process 04:49 – The real pain: chasing evidence vs. reducing risk 07:00 – What “AI-powered” actually means (and why most vendors are faking it) 09:31 – Force multipliers: where AI should increase capability, not just save time 11:25 – Completeness problem: you can’t protect what you don’t know exists 13:09 – Example: encryption checks → automation + AI completeness/accuracy criteria 15:58 – The future: continuous monitoring, audits, and what should change 17:24 – Why audits shouldn’t go away (incentives + independence) 20:07 – Gatekeeping, CMMC, and “audit industry” friction 23:58 – TPRM hell: questionnaires, insurance, and repetitive evidence requests 27:05 – Why Richa cares: privacy, consumer harm, and the mission behind GRC 28:46 – Equifax as the “spark” (without breach-shaming) 31:52 – Hallucinations: how to build AI you can trust in compliance workflows 35:24 – “Do you use compliance to ensure compliance?” (dogfooding) 36:00 – Outro: “Keep on cyberin’” #GRC #Compliance #Cybersecurity #AI #RiskManagement #Audit #ThirdPartyRisk #DataPrivacy #Governance #securityculture #legitimatecybersecurity

  18. 50

    Your Doorbell Camera Is Quietly Building a Surveillance Database

    You bought a security camera… but what you actually bought was a cloud evidence locker. And when you hit “delete,” it might only mean you lose access—not that the footage is gone. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer break down what Ring, Google/Nest, Wyze, and other camera ecosystems really are: subscription workflows that convert your home life into searchable records—sometimes shared by default, sometimes accessible through legal requests, and often retained longer than you think. What you’ll learn: What data retention actually means for consumer camera platforms Why “Delete” in the app can be misleading (and what it often really does) The “request economy”: how safety marketing can become privatized surveillance Practical steps to keep the safety benefits while reducing the privacy blast radius Safer alternatives: local storage, POE setups, tighter motion zones, smarter placement Media / interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 You bought an “evidence locker” (not a camera) 01:10 Subscription ≠ ownership: the real product is the workflow 02:35 Face recognition + data correlation (and why it’s creepy) 04:20 Data retention: what it is and why it matters 07:00 GUI illusions: “delete” vs “marked for deletion” 09:05 Deleted doesn’t mean gone (forensics reality check) 12:10 Why companies keep data (and why you should care) 14:20 “You’re not being targeted”… but your data is still valuable 16:10 The request economy + privatized surveillance without a vote 18:40 Local storage alternatives (Reolink, NVRs, POE basics) 20:40 AI inside the home: convenience vs risk 23:05 Pattern-of-life reporting: the “daily brief” problem 26:05 Drones, jammers, and why “taking it into your own hands” backfires 31:05 Practical steps: MFA, settings, sharing controls 34:45 Camera placement: reduce what you collect (reduce what can be used) 37:20 Motion zones + noise reduction (trees, spiders, false alerts) 39:00 Privacy defaults: say “no” first, enable later 41:10 Wrap + viewer question: what surveillance tools worry you? #Cybersecurity #Privacy #Ring #SmartHome #Surveillance #DataPrivacy #IoT #HomeSecurity #digitalrights #legitimatecybersecurity

  19. 49

    AI Agents Are Malware Now (And We’re Installing Them)

    AI agents aren’t just “tools” anymore — they’re getting delegated access, running workflows, calling APIs, and making decisions inside your environment. That’s why some security folks are starting to call them malware… with permission. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer sit down with Jasson Casey (CEO & Co-Founder of Beyond Identity) to break down what actually breaks in identity and access when software can reason, plan, and take real actions. We cover why prompt injection is fundamentally “control + data mixing,” why agent toolchains resemble living-off-the-land techniques, and why visibility + device-bound identity may be the only sane control plane going forward. You’ll learn: Why “delegated auth” becomes the new breach primitive How indirect prompt injection can persist across an agent loop What “treat the agent as a user” gets right—and what it misses Why hardware attestation (TPM/TEE) changes detection and logging strategy How to think about local agents, plugins, and “willful malware execution” risk Media / interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 AI agents: tool or malware-with-permission? 01:02 Meet Jasson Casey (Beyond Identity) 02:03 Delegated authorization: the “easy option is the lazy option” problem 03:30 RAG + RBAC: privilege escalation through indexed knowledge 04:48 Prompt injection = mixing instruction and data (and why that’s provably bad) 06:01 Can injections persist across loops? “Maintain persistence” for agents 07:08 Policies fail when the agent “reaches around the fence” 08:05 Training your org to accept malware-like behavior 09:27 Adoption pressure vs security “wet blanket” reality 11:10 What’s the most weaponizable part of an agent? 13:31 Start with visibility: what’s happening, what has access to what 15:08 The Command & Conquer test: when capability suddenly jumps 20:11 Detection: how do you tell legit agent actions from malicious ones? 21:18 Why device-bound attestation matters (TPM, integrity, authenticity) 23:45 What an agent identity should include (operator + machine + time) 25:59 The logging problem: monitoring humans + agents at scale 27:44 Attestation changes logs: snapshots, reconstruction, reverse queries 29:02 Local agents & plugin ecosystems: “safe because it’s local?” 32:44 “How long before it’s news?” token harvesting and real-world fallout 34:18 AI dating pop-ups + responsibility for outcomes 37:05 Wrap + where to find Jasson #Cybersecurity #AI #AIAgents #IdentitySecurity #ZeroTrust #PromptInjection #PhishingResistantMFA #CISO #SecurityEngineering #InfoSec #legitimatecybersecurity

  20. 48

    This Surveillance Network Is Spreading Quietly—And You Can’t Opt Out

    You can be tracked in the real world—without consent—just by driving down a public road. And the scariest part isn’t “live tracking”… it’s rewind: searchable history after the fact. In this episode of Legitimate Cybersecurity, Frank Downs and Dustin Brewer break down Automated License Plate Readers (ALPRs)—why they’re popping up everywhere, why they’re easy to miss, and why the data is more dangerous than the camera. You’ll learn: What ALPR cameras capture (it’s more than “just plates”) How cheap hardware + open source + cloud storage made this inevitable Why “30-day retention” isn’t the same as “safe” once data is exported/shared The governance gap: private vendors, thousands of customers, inconsistent rules The cybersecurity risk nobody talks about: downstream buyers and sloppy security Practical steps you can take to demand limits and transparency Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 You’re being monitored outside (no consent) 00:45 What ALPR is (and why it’s a misnomer) 01:30 Why it got cheap: hardware + open source + cloud 04:10 The U.S. privacy gap (no single overarching law) 05:00 These aren’t red-light cameras—why you don’t notice them 06:45 Flock Safety + the business of surveillance 08:20 “Vehicle fingerprinting” (tracking without “just plates”) 10:00 Who’s buying it: cities, states, feds… and HOAs 11:15 Data retention: policy vs reality (purge vs sanitize vs export) 13:45 Commercial surveillance = “fog” (hard to see, harder to fight) 14:40 Outsourcing “security” (the Pinkertons comparison) 17:10 Governance: why oversight breaks across customers/jurisdictions 18:30 The Wi-Fi packet parallel (Street View lesson) 24:15 Cyber risk: breaches + bad access controls + spreadsheet exports 27:00 “Nothing to hide” is a trap 30:05 The real danger: rewind + retroactive suspicion 32:00 What you can do: disclosure, guardrails, and pressure points 34:20 Internet cookies → real-world cookies (attached to your car) 34:50 Keep on cyberin #cybersecurity #privacy #surveillance #ALPR #licenseplatereaders #flock #flocksecurity #dataprivacy #infosec #FlockSafety #securityawareness #digitalrights

  21. 47

    Your AI Agents Need Logins (Or They’ll Burn Your Company Down)

    AI is pushing security into a new failure mode: tools that don’t just talk… they act. If you don’t treat AI agents like identities—with guardrails + telemetry—you’re building silent insiders. In this episode of Legitimate Cybersecurity, Frank and Dustin sit down with Ben Wilcox (CTO + CISO at ProArch) to get practical about what’s quietly breaking as companies rush into AI. What you’ll learn: The real conflict (and advantage) of being both CTO and CISO Why DevSecOps “shift left” has stalled—and what actually works How to pitch security to executives: business impact analysis, downtime, and real risk framing Why AI governance is mostly identity + visibility (and what’s missing today) “Paved paths” vs 5,000 snowflakes: the pattern that scales security Cloud-native vs Active Directory reality, passkeys, and legacy debt The weird personal-data leak nobody notices (Gemini thinking Ben is a doctor) Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters 00:00 – The core question: what’s breaking as companies rush into AI? 01:35 – CTO + CISO in one body: conflict or superpower? 03:15 – Why security becomes “the blocker” (and how shadow IT/AI happens) 04:45 – DevSecOps reality check: why “shift security into developers” stalls 07:00 – Boards waking up: due diligence, questionnaires, and exec priorities 09:30 – The only language budgets understand: business impact + downtime 12:20 – AI coding + layoffs: are we shipping secure-looking “slop”? 14:05 – “Paved paths”: fix one road, not 5,000 snowflakes 18:25 – Agents are identities: treat them like users (RBAC, controls, monitoring) 20:45 – Agent behavior drift: what “normal” looks like when it keeps learning 23:05 – Gemini thought I was a doctor: how tiny data errors become big risk 30:00 – What’s changed since the early internet (and what hasn’t) 31:10 – The Active Directory problem + why cloud-native is safer (when done right) 34:40 – Cloud tradeoffs: data residency, trust, and where control actually lives 35:55 – Is cloud cheaper? The real savings (people + speed) 37:05 – Space-based server farms: cool idea or expensive sci-fi? 38:35 – Quantum: roadmap promises vs reality 41:35 – Wrap + the official send-off: “Keep on cyberin’” #Cybersecurity #AI #CISO #CTO #IdentitySecurity #DevSecOps #AIGovernance #CloudSecurity #SecurityLeadership #riskmanagement

  22. 46

    Stop Saying You Have Nothing to Hide! It’s Costing You Money!

    The "I have nothing to hide" argument is dead. It’s not about secrecy anymore—it’s about your wallet. Most people assume data collection is just for "better ads." They’re wrong. In this episode, Frank and Dustin break down how data brokers, insurance companies, and retailers are building a "digital twin" of you to manipulate dynamic pricing and assess your risk profile. From your car reporting your driving habits to insurance providers, to "The Retail Equation" banning you from stores for returning items, the surveillance economy is actively costing you money. In this episode, you’ll learn: The "Price Rigging" Reality: How Instacart and Kayak use your data to charge you higher prices than your neighbor. The Spy in Your Garage: How GM and other automakers are selling your driving data to spike your premiums. Home Surveillance: Why Amazon wants your Roomba’s floor maps. Defense Strategy: The exact browser, VPN, and "data pollution" tactics you need to use today to confuse the algorithms. Join the ongoing investigation: Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 Intro: Why "Nothing to Hide" is a dangerous lie 01:36 The Shorts controversy: Work computers & personal data 03:28 It’s not privacy, it’s mind mapping 06:28 The Target Story: Predicting pregnancy before the family knows 07:24 Day-in-the-Life of your Data: From toothpaste to traffic 08:14 Crucial: Your car is reporting you to insurance companies 09:46 Dynamic Pricing: Why Mac users pay more for flights 12:46 The Instacart Experiment: Same groceries, different prices 15:17 Roomba, LiDAR, and the map of your home 19:08 The "Return Police" (The Retail Equation) 22:30 Flock Safety: The license plate reader network tracking you 26:29 The MIB: How insurance companies track your "inconsistencies" 30:10 Defense Phase: Denial and Data Pollution 31:22 The Browser & VPN Strategy (Brave/Firefox/Nord) 34:54 Windows & Mobile Settings you must turn off 37:31 Advanced Tactic: Pi-hole and Private DNS 40:58 The Mesh-tastic Option (Going off-grid) 43:26 The "Doomsday Computer" & Etsy Scams #DataPrivacy #CyberSecurity #DynamicPricing #DataBrokers #OSINT #PrivacyTips #StopDataCollection #LegitimateCybersecurity

  23. 45

    The TikTok ”Sale” is a Lie: Why the Algorithm remains the Threat

    Everyone thinks the TikTok problem is solved because "US Data stays in the US." That is a dangerous misunderstanding of how the technology works. In this episode, Frank and Dustin break down the 80-page filing of the new TikTok joint venture. We analyze the ownership structure (Oracle, Silver Lake, and ByteDance) and explain why the "divestiture" is actually a loophole. The reality? Your data might live on Oracle servers, but the algorithm—the weaponized model that influences behavior—is still controlled by ByteDance. What we cover: The breakdown of the 19.9% ByteDance / 15% Oracle ownership split. Why "Data Sovereignty" doesn't matter if the Model is foreign-owned. The difference between data theft and behavioral modification (The "Cambridge Analytica" factor). Why ByteDance took a massive financial hit to keep a foothold in the US. Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters 0:00 - The "Deal" that changed nothing 2:03 - Dissecting the ownership: Oracle, ByteDance, & Abu Dhabi 5:22 - The difference between Global Economy and National Security 8:45 - The Privacy Law trap: Backdoor access explained 10:04 - The Real Threat: It's not the data, it's the Model 14:25 - Can you train bias out of an algorithm? 18:29 - What-about-ism: Facebook vs. TikTok incentives 25:23 - The Dopamine Economy: Why Short-form won 30:18 - The "Sho Chu" Factor: Why is the CEO still there? 38:37 - Follow the Money: The $14B vs $100B valuation anomaly 42:39 - Next week: The failure of MFA #TikTok #Cybersecurity #DataPrivacy #Algorithm #TechNews #Oracle #ByteDance #SocialMedia #InformationWarfare

  24. 44

    The Tools Cyber Pros Use To Monitor You!

    Your work laptop isn’t yours — and one legal issue inside your company can put your logins, browsing, and messages under review. We break down the real tools cyber pros use to “see” what’s happening on networks — and what that visibility means for your privacy. In this episode, we unpack: Why Wireshark is the “truth serum” of the internet How SOC tools (like Snort) catch real behavior on real networks Why using personal accounts on a work device can backfire What VPNs and DNS leaks mean for your browsing privacy The tool mindset that separates guessing from knowing Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters 00:00 Your work laptop is not private (cold open) 00:26 Welcome + what this episode is really about 02:00 The big idea: security is visibility 03:00 Wireshark and learning how the internet actually works 10:00 Kali + Metasploit and the reality of “hacking” 19:30 Snort and how SOCs actually catch things 23:10 Why work devices are a privacy trap 27:45 VPNs, DNS leakage, and trust-but-verify 42:20 Tools we loved then vs now (cantennas, Security Onion) 48:35 The one tool that explains our security philosophy 55:00 Wrap-up + keep on cyberin #cybersecurity #privacy #infosec #Wireshark #VPN #workfromhome #dataprivacy #networksecurity #securityawareness #tech

  25. 43

    AI is Hacking Your Brain! The Truth about Digital Affairs!

    AI can sound empathetic, supportive, even “therapeutic”—but it can’t be accountable. That gap matters most when someone is isolated, vulnerable, or in crisis. In this episode, Frank Downs and Dustin Brewer sit down with Dr. Onna Brewer (licensed psychologist) to unpack why people are forming real attachments to AI—friendship, intimacy, and “therapy”—and where the danger line is when general-purpose chatbots become a substitute for human care. What you’ll learn: Why AI relationships meet real needs (and why that doesn’t automatically make them healthy) The difference between cognitive empathy vs affective empathy Where AI can help mental health care (access, training, documentation) vs where it fails Why crisis support is the hard boundary (and why “coin-flip” reliability isn’t acceptable) What guardrails could look like: product design, disclosures, and regulation If you’re in immediate danger or thinking about self-harm, contact local emergency services right now. (This episode is education, not medical care.) References / further reading (full URLs): http://www.brewerbristow.com https://www.apa.org/topics/artificial-intelligence-machine-learning/health-advisory-chatbots-wellness-apps?utm_source=chatgpt.com https://www.nature.com/articles/s41598-025-17242-4#Fig4 https://www.sciencedirect.com/science/article/pii/S2451958825001307?utm_source=chatgpt.com https://hbr.org/2025/08/you-need-to-be-bored-heres-why Media/interview: [email protected] Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 AI can’t be accountable (the core problem) 00:17 Introducing Dr. Onna Brewer 02:06 Why AI relationships are growing (needs being met) 05:01 Isolation + loneliness as the real backdrop 06:42 Intimacy / passion / commitment: how AI fits 08:32 One-way street (why it still feels two-way) 13:22 AI as “therapy”: what’s real vs risky 14:10 Pros: access, stigma reduction, clinician support 18:38 Cognitive vs affective empathy (why therapy depends on humans) 22:23 “Therapist” isn’t what most people think it means 23:01 Normalization: asking AI for everything 29:24 Boredom, attention, creativity, and cognitive offloading 33:19 AI romance stats + shame/stigma dynamics 37:35 AI in marriage: fidelity is defined by the couple 46:00 The safety line: humans can intervene; bots can’t 46:48 Responsibility vs trust: regulation and guardrails 49:35 Wrap + resources + what to watch next #Cybersecurity #AI #Privacy #MentalHealth #DigitalWellbeing #OnlineSafety #AIsafety #TechEthics #AITherapy #AICompanions

  26. 42

    AI Is Rebuilding the Dead — With Your Data

    Your body dies — but your accounts don’t. And now AI can be trained on the dead. So who “owns” your digital afterlife… and who gets to use it? In this episode of Legitimate Cybersecurity, Frank and Dr. Dustin Brewer unpack the real risk behind “legacy accounts,” AI memorial bots, and digital grief tools: consent, identity control, and what happens when someone can simulate you without you. We cover the ethics of training on deceased users, the slippery slope from grief-support to manufactured relationships, and why regulation vs. private control matters more than people realize. Media & interview requests: [email protected] Audio subscription: https://legitimatecybersecurity.podbean.com/ C) Chapter Breaks (YouTube Chapters) 0:00 — Your body dies… does your data? 1:05 — Legacy accounts & “consent” after death 3:20 — The DIY “Talk to my dead loved one” GPT 5:45 — Why Facebook stopped being “social” 7:10 — DNA data + the real nightmare scenario 10:50 — Should your AI ghost include your flaws? 13:05 — “Do we erase the racism?” (history vs. sanitizing) 17:45 — Sci-fi already warned us (AI Lincoln moment) 20:20 — Grief tools: healthy coping or dependency? 26:00 — The slippery slope: AI partners & manufactured bonds 27:40 — Who should control this: government or private sector? 34:00 — Guardrails + “whole-ham” threat actor reality 36:10 — Wrap: what we should demand before “digital afterlife” goes mainstream #Cybersecurity #AI #Privacy #DataOwnership #DigitalIdentity #Deepfakes #TechEthics #OnlineSafety #DigitalLegacy #Governance #LegitimateCybersecurity #AI #DigitalAfterlife #Privacy #Cybersecurity #ArtificialIntelligence #TechEthics #DataOwnership

  27. 41

    5 Holiday Scams That Drain Your Money Fast (Gift Cards, Texts, QR)

    Your gift card can be empty before you even buy it—and that’s just one of the holiday scams exploding right now. In December, attackers don’t need skill. They need distracted people. In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer break down the five highest-volume holiday scams hitting normal, smart people—gift cards, shipping texts, QR codes, travel Wi-Fi, and even AI voice cloning. You’ll learn: How gift cards are drained before activation Why “package can’t be delivered” texts work so well How QR codes are being weaponized in parking lots and charities What actually keeps you safe while traveling How to stop family-emergency scams instantly Media & interview requests: [email protected] 🎧 Audio version: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 — Christmas morning: the gift card is already empty 01:40 — Why December supercharges scams (stress + urgency) 07:45 — Gift card heists (how they steal it before purchase) 15:55 — “Pay in gift cards” = funding a crime 17:00 — Shipping smishing texts (the #1 holiday scam) 23:15 — MFA: annoying, but it works 24:40 — QR scams & fake charities (quishing explained) 28:10 — Travel season: Wi-Fi, hotel TVs, charging traps 34:15 — Proximity attacks: NFC & crowded spaces 36:45 — AI voice cloning & family emergency scams 41:45 — The boring-target checklist (do this, relax) 44:10 — Final takeaway + share with the link-clicker #cybersecurity #holidayscams #onlinesafety #phishing #giftcards #scams #identitytheft #LegitimateCybersecurity #Cybersecurity #HolidayScams #GiftCardHeist #AIVoiceCloning #Privacy #Infosec #TechSafety

  28. 40

    Your Phone, Your Car, Your Movies—You Don’t Actually Own ANY of It #cybersecurity

    Your smartphone, your streaming library, even your tractor—none of them actually belong to you. Companies can lock you out, delete your data, revoke your access, or simply shut down the servers your devices rely on. And now with AI moderation quietly deleting accounts behind the scenes… who’s really in control? In this episode of Legitimate Cybersecurity, Frank and Dr. Dustin Brewer explore: How Apple, Google, Tesla, and John Deere can remotely brick your devices Why your “purchased” movies on Vudu/Fandango can disappear The subscription takeover: cars, games, self-driving, even pill bottles How AI bots on Reddit, Facebook, and Google can silently erase your account Why Gen Z and Gen Alpha face a job market that’s never been harder The hidden danger of companies shutting down and taking your devices with them Whether you can really own anything digital anymore From tractors to Tesla pricing chaos, FMV Sega nostalgia, disappearing media libraries, HOA jokes, and mushroom farming jokes… this episode covers the entire collapsing spectrum of digital ownership in 2025. 🎯 QUESTION FOR YOU: What’s something you thought you owned… that you later realized wasn’t really yours? Post it in the comments — we’ll feature the best ones. 🎧 Prefer audio? Subscribe to the Legitimate Cybersecurity podcast on any platform: 👉 https://legitimatecybersecurity.podbean.com/ 📩 Media / interview requests: [email protected] Chapter Breaks: 00:00 – Cold Open: “Your phone can be remotely disabled—so do you actually own it?” 00:33 – Streaming, OS licensing, and why your iPhone is rented, not owned 01:20 – Companies can delete your data at will — Google, Tesla, Apple 01:45 – The John Deere DRM nightmare 02:58 – Gaming industry: the original warning sign 04:09 – Cloud gaming, Stadia, GeForce Now, and the upside of subscriptions 05:59 – But tractors doubling in price? Ownership gone wrong 06:30 – “They can brick you at any moment” — the Dustin phone hypothetical 07:23 – Dustin’s reaction: “I’d never use Google again” 08:08 – OFAC, false positives, and the real risk of automated bans 08:43 – Dustin’s farming family and the tractor brand civil war 09:24 – The horse-as-subscription joke + automated farming tech 10:35 – Tesla’s bizarre pricing, self-driving subscriptions, and BlueCruise 12:08 – Frank’s Sega CD tragedy and the death of ownership nostalgia 13:42 – Porn, HD DVD vs Blu-ray, and where video compression really came from 15:55 – Streaming illusions of ownership: Vudu → Fandango disaster 17:27 – EULA manipulations and the illusion of choice 18:56 – Forced ads even with “ad-free” subscriptions 19:27 – Millennials vs the streaming trap — we’re back to cable pricing 20:27 – Pillsy shutdown: When smart devices die because companies die 21:49 – The normalization of owning nothing 23:33 – Subscription cars, self-driving distrust, and ambulances costing thousands 24:40 – Can we stop the subscription takeover? Voting with wallet & laws 25:34 – Food costs, Whole Foods jokes, inflation, and generational struggle 26:10 – Mitsubishi Mirage, Slate truck, and forced compromise 27:30 – Gen Z’s brutal job market and AI crushing coder roles 29:33 – The CyberSeek fallout: disappearing salary data 32:20 – AI moderation deleting posts and accounts without warning 33:33 – Should AI ever be allowed to delete people? Objectivity vs bias 35:19 – Moderating subreddits and HOAs = punishment jobs 36:16 – What digital things do you really own? NAS vs cloud 37:26 – Photos, privacy, and pulling memories off the cloud 38:25 – Average people don’t have the tools to self-host anything 39:13 – Benjamin Franklin quote + “It’s too late to go back” 40:32 – Knock-knock joke + Dustin’s hope speech 42:24 – The 98% vs the 2% — who really has control 43:54 – Outro + Raspberry Pi phone joke #legitimatecybersecurity #cybersecurity #digitalownership #righttorepair #streamingwars #AIModeration #SubscriptionEconomy #johndeere #tesla #cloudcomputing #techpodcasts #dataprivacy #digitalrights #genz #cyberjobs

  29. 39

    Why Security Tools Are Designed To Fail (VP Revelations) #cybersecurity

    The cybersecurity industry is gaslighting you. We spend billions on dashboards that look pretty but act like "sleep paralysis demons" for the analysts trying to use them. In this episode, Jennifer Von Kainold (VP of Product Management at BlueVoyant) reveals the dirty secret of security engineering: the tools are built for the builders, not the defenders. Jen breaks down the "Sleep Paralysis" of modern SOCs, why the industry refuses to simplify, and how she went from a Chemistry degree to leading product strategy for a major MDR firm. We also dismantle the panic over Quantum Computing and explain why you’re worried about Q-Day when you don’t even have an asset inventory. Media and interview requests can be made to: [email protected] Audio listeners can subscribe on any platform and can do it through: https://legitimatecybersecurity.podbean.com/ ⏱️ CHAPTER BREAKS 00:00 – The Dashboard That Causes Panic Attacks 00:14 – The “Illusion of Safety” in Tech 02:31 – From Coding Fortran to Hacking Genomes 06:18 – The “Sleep Paralysis Demon” of Bad UI 09:16 – Why Engineers Build Tools for Robots, Not Humans 14:29 – Translating “Engineer” to “Human” (The Polyglot Problem) 19:31 – The Archer Paradox: When Flexibility Becomes Failure 21:58 – Agentic AI: The End of the Dashboard? 31:22 – The Myth of the “Single Pane of Glass” 35:37 – The Quantum Computing ("Q-Day") Hysteria 37:44 – “Where Is Your Super Cold Fridge?!” 40:32 – Why We Refuse to Do the Basics (Burnout & Cognitive Load) 44:29 – Don’t Wait for the Apocalypse to Lock Your Door 46:22 – The Final Verdict #legitimatecybersecurity #uxdesign #quantumcomputing #infosec #burnout #agenticai #techfails #cyberwarfare

  30. 38

    The Drone Privacy Crisis: What No One Is Telling You. #cybersecurity

    Drones are showing up where they shouldn’t — over backyards, pools, windows, driveways, campsites, neighborhoods, and even over insurance customers’ houses to jack up premiums. And here’s the terrifying part: nobody knows who owns them, and the laws protecting you are a mess. In this episode of Legitimate Cybersecurity, Frank, Dustin, and Chris Adkins break down: • The explosion of drone trespassing across the U.S. • Drone “etiquette” (if such a thing exists) • Why shooting down a drone might be illegal… but hijacking its open Wi-Fi might not be • How insurance companies are secretly flying drones to deny coverage • Whether YOU own the air above your home (the answer will piss you off) • The ethics of taking over unencrypted drones • Why the U.S. military once had its Predator drones hacked • The insane world of bathtub drones and balloon monks • And how long until drones accidentally kill someone and trigger a legal revolution This episode is chaotic, hilarious, and honestly a little terrifying — one of our most eye-opening discussions yet. Media or interview inquiries: [email protected] Subscribe to the audio podcast: 🔗 https://legitimatecybersecurity.podbean.com/ Chapters 00:00 – A Drone Could Be Watching You Right Now 00:35 – Drone Trespassing is Exploding 01:30 – Drone Etiquette: Does It Even Exist? 02:45 – The Campsite Drone Freakout 03:20 – Drones vs. Guns: Which Is Actually Easier to Stop? 04:00 – Anti-Drone Weapons & the FCC Problem 05:20 – Building “Ghost Wi-Fi Guns” (Totally Legal?) 06:30 – Why Drones Are Outpacing the Law 07:15 – Privacy, Backyards & the “Altitude Problem” 08:55 – Insurance Companies Are Flying Drones Over Your Home 10:45 – Data, Bias & Discrimination From the Sky 12:20 – The Future of Drone Regulation (and Why It Will Suck) 14:10 – Enforcement, Penalties & the Reality of Privacy 16:00 – Drones Getting Better, Cameras Getting Scarier 17:20 – Can You Hijack an Unencrypted Drone? 19:30 – Military Drone Hacks (Yep… That Happened) 20:50 – Ukrainian Fiber-Wire Drones 21:30 – Dustin’s Ethics: “If It’s Unsecured… That’s On You.” 22:15 – Should Homeowners Be Notified Before Being Filmed? 23:00 – Air Rights: Who Actually Owns the Sky Above Your House? 26:00 – Maryland Airspace Laws You Didn’t Know 27:30 – The Insane Bathtub Drone Guy 28:20 – Balloon Monks & BB Guns at 10,000 Feet 29:50 – Final Thoughts & Holiday Schedule Hashtags #legitimatecybersecurity #cybersecurity #dronesurveillance #DronePrivacy #technews #Hacking #privacyrights #infosec #cyberethics #InsuranceFraud

  31. 37

    SIM Swapping Is Back — And They Can Steal Your Phone Without Touching It #cybersecurity

    SIM swapping has returned — and the attackers have leveled up. In this episode, Frank, Dustin, and returning guest Chris Adkins break down how modern thieves hijack your SIM, clone your phone, intercept your MFA codes, and drain your accounts… all without ever touching your device. We cover: • Why your phone number is the master key to your digital life • How eSIMs changed the threat landscape • Real-world stories of Gmail & crypto takeovers • Why teens AND the elderly are getting hit hard • Why your SIM might be less secure than the Coca-Cola formula • Chinese electronics bans, printer economics, zombie barter value, and exploding Hezbollah pagers (yes, really) This episode is technical, hilarious, terrifying, and extremely relevant — especially if you rely on your phone for anything in your life. 📩 Media & Interview Requests: [email protected] 🎧 Audio listeners can subscribe on any platform: https://legitimatecybersecurity.podbean.com/ ⏱️ CHAPTER BREAKS 00:00 — HOOK: “Why is my phone being used at 3AM?” 00:35 — Welcome Back + Celebrating 10,000 Subscribers 01:25 — What SIM Swapping Looks Like in the Real World 02:22 — Why Your Phone Number Is the Master Key to Your Life 03:36 — Kids, Phones, and the Multi-Screen Generational Divide 04:07 — Why eSIM Makes Attacks Easier to Pull Off 05:23 — Dustin’s 40 Old Burner Phones and Spy-Grade Persona Tricks 06:25 — The Ancient Sony Xperia Tablet-Phone Monster 07:25 — What SIM Cards Actually Are (Clear Explanation) 08:10 — SIM Cloning → eSIM Social Engineering Attacks 09:20 — MFA Hijacking & Why Your Text Codes Aren’t Safe 10:22 — The Missing Industry: “SIM Credit Freezing” 12:00 — Carriers as the Weakest Link (And Why They Can’t Stop It) 13:10 — Third-Party Risk: Your Data Is Only as Safe as Everyone Else’s Security 14:30 — The $90 ‘Most Secure Phone Service on Earth’ 15:35 — Chris’s Gmail + Coinbase Hack Story From Vacation 17:34 — Frank’s 100,000+ Unread Emails & Gmail Identity Crisis 19:01 — Credit Report Drama & Who’s Really Most Vulnerable 20:11 — Elderly Crypto Retirement Liquidation Scams 21:20 — Dustin’s Grandmother Rode a Horse to School (And Why Tech Speed Matters) 22:15 — People Don’t Understand How Phones Actually Work 24:00 — Teens & AI: The New Scam Generation 25:25 — Printer Economics: “Is it Cheaper to Buy a New Printer?” 26:34 — Apocalypse Bartering: Printers, Lithium, and Ham Radios 29:01 — The Hezbollah Exploding Pagers Operation 30:12 — Chinese Electronics Bans: Are We Going Too Far? 32:19 — Consumer vs Enterprise Tech Vulnerabilities 34:00 — Free Market, Tariffs, and Why We Can’t Buy China’s Best EVs 36:00 — Why TP-Link Isn’t Malicious… It’s Just Cheap 38:15 — Regulation vs Innovation: Who Should Protect the Consumer? 39:26 — FINAL QUESTION: What’s More Secure — Your SSN, Nuclear Blueprints, Your SIM, or the Coca-Cola Formula? 43:00 — Closing + The New Catchphrase: “Be Safe, Don’t Do Anything We Wouldn’t Do.” #legitimatecybersecurity #cybersecurity #infosec #simswapping #esim #PhoneHacks #digitalidentity #databreach #techpodcasts

  32. 36

    AI vs Religion: The Vatican Breaks Its Silence — And It’s Terrifying #cybersecurity

    The Vatican just issued a massive warning about AI — and it might be the most unexpected twist in the religion-tech debate yet. Frank and Dustin dive deep into the rising spiritual panic around artificial intelligence: AI as a therapist, AI as a partner, AI as a spiritual advisor… and the truly wild question: Should an AI ever be baptized? In this episode of Legitimate Cybersecurity, we explore why major religious leaders are suddenly speaking out, whether AI could cause a crisis of faith, what it means for humanity’s spiritual future, and whether we’re all just NPCs in God's cosmic simulator. Plus: • Why people are telling AI their deepest secrets • Whether AI can “feel” anything • Star Trek’s Data vs. real-world AI • What the FIRST religion to baptize an AI will be • Why robots should NOT have teeth • Dustin invents the term “Crab with a K Cybersecurity” • Frank creates “FrankBible.ai” (please, no one do this) If you want an episode that’s funny, thought-provoking, and utterly uncomfortable in all the best ways… this one’s it. Media & interview requests: [email protected] Audio listeners: Subscribe everywhere or at https://legitimatecybersecurity.podbean.com/ 🧭 Chapters 00:00 – Can AI cause a crisis of faith? 00:42 – The Vatican’s AI Warning: Extinction-level concerns 01:23 – Why NOW? Dustin explains the timing 02:20 – Anthropomorphizing AI & why we do it 03:20 – AI hallucinations vs. just “breaking” 03:45 – When people start dating AI 04:30 – AI replacing spouses, therapists… and maybe pastors? 05:21 – Why the Church might be afraid of losing influence 06:19 – When religious leaders start using AI themselves 07:10 – Social media déjà vu: Echo chambers and faith 08:00 – Will AI reshape religion? 09:30 – Frank and Dustin’s childhood church trauma dump (lol) 11:00 – Can AI enhance sermons without replacing faith? 13:00 – Are religious texts just “data”? 14:45 – Using AI to process spiritual conflicts 16:00 – Danger: AI as a moral mirror 16:30 – Echo chambers & spiritual distortion 17:47 – Bible versions + algorithmic interpretation 18:37 – How do OTHER religions interpret this? 19:20 – Talking to AI = talking to yourself? 20:30 – Can AI really replace clergy? 22:00 – Faith vs. Ones & Zeros 23:30 – Will AI ever be baptized? 25:00 – Can AI “feel” emotions? Frank hopes the answer is no 27:00 – Why emotional responses ≠ AI feelings 28:30 – Philosophical chaos: Are WE God’s AI? 29:30 – Frank’s “FrankBible.ai” — the heresy arc 30:20 – Which religion baptizes AI first? The answer is spicy 31:00 – VR Church, Second Life, and digital baptisms 33:10 – Household robots, C-3PO vs. R2-D2 34:45 – Why are we building humanoid robots? 36:00 – Ewok-shaped robot companions? Dustin says no teeth 37:20 – Do we need AI commandments? 38:00 – Historical pattern: tech never actually kills religion 40:00 – Jesus as organic AI?? Frank breaks Dustin 41:00 – Are we all Sims and God is AFK? 42:00 – The wrap-up: uncomfortable but enlightening #legitimatecybersecurity #ai #religion #vatican #artificialintelligence #cybersecurity #techpodcasts #faithandtech #aiwarning #VaticanStatement #llm #ethicsinai

  33. 35

    Leonardo da Vinci Had Better Wi-Fi: The $100M Louvre Heist #cybersecurity

    What happens when the most secure museum on Earth has a Wi-Fi password that’s literally “louvre”? 💎 $100 million in jewels disappear, and the world’s best art collection learns what Defense in Dumb really means. In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer unpack how the Louvre Museum was robbed in broad daylight — not just by thieves, but by bad passwords, unpatched servers, and leadership that never took cybersecurity seriously. 👉 Topics include: The Windows Server 2003 still guarding priceless art “Defense in Dumb” vs. real defense in depth Why pen tests without remediation are a waste of money How boredom and bureaucracy kill security programs The Rosetta Stone irony: stolen artifacts complaining about theft What NIST CSF, GRC, and governance diffusion all have to do with it Why multi-factor authentication isn’t two French guards and a shrug And yes — Leonardo da Vinci had better wireless security. 📩 Media & Interview Requests: [email protected] 🎧 Audio listeners: Subscribe on any platform → https://legitimatecybersecurity.podbean.com/ 👇 Comment below: What’s the dumbest password or security setup you’ve seen in the wild? We might feature your story in a future episode. Chapters 00:00 – Cold Open: “Imagine robbing the most secure museum on Earth…” 01:00 – Defense in Dumb: Louvre’s password was literally “louvre” 02:10 – British & French museums suddenly hate theft 03:45 – The Cyber Audit That Nobody Fixed 05:30 – Pen Testing vs. Actually Doing the Work 07:00 – Roof access, open windows, and Netflix-level stupidity 09:00 – Boring but critical: why remediation never happens 11:00 – Framework fails: ISO, NIST, GDPR, and no one enforces them 13:30 – Cyber careers, boredom, and the “borification” of information 16:00 – “It really HUMPS your packets”: why GRC isn’t sexy but matters 18:30 – Leadership without packets: Steve Jobs, Woz, and cyber blind spots 20:00 – How the Louvre failed every NIST CSF function 23:00 – MDR myths: detection ≠ protection 25:00 – APTs, insurance loopholes, and cyber blame games 29:00 – Governance diffusion: when everyone assumes someone else did it 31:00 – Legacy tech, no funding, and free open-source fixes 33:00 – PFSense, Security Onion & AI helping broke orgs 35:00 – Final Takeaway: “Leonardo da Vinci had better Wi-Fi security.” #LegitimateCybersecurity #LouvreHeist #CyberFail #DataBreach #cybersecurity #Hackers #PenTesting #InfoSec #NISTCSF #GRC #MDR #APT #CyberRisk #MuseumHeist #DefenseInDumb #WindowsServer2003

  34. 34

    Haunted Networks: Possessed Printers, Phantom Texts, and the OG Computer ‘Bug’ #cybersecurity

    Tonight’s Halloween special gets deliciously weird. 🦇 Dustin and Frank unpack four true tech “hauntings”: • The Ghost in the Printer—Why old JetDirects spit hieroglyphics at night. • Laughing Alexa—The infamous 2018 bug that creeped out the world. • #GhostText—When delayed SMS messages arrived from the… beyond. • Grace Hopper’s Moth—The first literal computer “bug,” preserved in a logbook. We translate spooky glitches into plain-English cyber hygiene: broadcast storms, wake-on-LAN, noisy IoT, always-listening assistants, SMS spoofing, and why physical world failures (heat, humidity, insects!) still crash modern stacks. 🎤 Media & interview requests: [email protected] 🎧 Audio listeners: subscribe on any platform via https://legitimatecybersecurity.podbean.com/ 💬 Drop your own “haunted tech” stories in the comments—we may read them on-air! Chapter Breaks 00:00 – Cold open: “Possessed” printers in Portland 01:21 – Halloween setup + how we’ll demystify “paranormal” tech 02:14 – Case #1: The Ghost in the Printer (broadcast storms + wake-on-LAN) 05:01 – Why vulnerability scans make printers spit gibberish 08:32 – Broadcast packets 101 (and why Frank hates wake-on-LAN) 12:15 – Case #2: Alexa’s bone-chilling laugh (2018 trigger bug) 16:55 – Smart speakers as always-listening risk (home & remote work) 18:31 – Agentic AI + voice triggers = future home-automation threats 23:16 – Case #3: #GhostText—delayed SMS from the “afterlife” 27:42 – “HauntLater.com” (Frank’s dubious startup idea) 32:59 – Case #4: Grace Hopper and the first literal computer “bug” 36:45 – Physical world vs. digital systems (heat, humidity, pests) 39:45 – Wrap & CTA: Share your creepy tech stories #legitimatecybersecurity #cybersecurity #halloweenspecial #ghostinthemachine #infosec #smarthome #iot #gracehopper

  35. 33

    AI Is Quietly Killing Entry-Level Jobs (And No One Wants To Admit It)

    Are we watching the ladder get pulled up? A new Harvard-linked analysis shows companies that adopt generative AI hire 7.7% fewer junior roles — a subtle shift with massive consequences for cybersecurity, tech, and the middle class. Frank Downs and Dr. Dustin Brewer break down what’s really happening: the automation sugar high, the hollowing of mid-tier careers, why experience over degree over certifications is driving gatekeeping, and how this ends if we don’t course-correct. Learn more about the study here: https://www.economist.com/graphic-detail/2025/10/13/can-ai-replace-junior-workers?giftId=c059cef1-fdf2-4e22-80f7-e8fc16f025bf&utm_campaign=gifted_article Media and interview requests: [email protected] Audio listeners: subscribe on any platform via https://legitimatecybersecurity.podbean.com/ Chapter Breaks 00:00 – Cold Open: AI is quietly killing entry jobs 00:27 – The stat nobody’s talking about 7.7 percent junior hiring drop 02:05 – Correlation vs causation pandemic and RTO chaos 03:35 – Gatekeeping madness 8 years of Swift and entry roles needing 5 years 04:50 – What employers actually value experience over degree over certs 06:20 – Why juniors are disappearing AI excels at lower-level tasks 07:40 – The seduction shareholders execs and the AI won’t leave you trap 09:00 – Societal fallout angry grads hollowed middle class 12:30 – Who replaces us if we skip training 14:10 – The wall where AI plateaus and humans must return 15:30 – Safe vs squeezed trades and specialists vs shrinking middle 16:50 – Adaptation 2.0 lessons from past automation waves 19:40 – Tech is not automatic good phones social media and productivity 23:30 – Cyber never sleeps always-on culture and cognitive offloading 25:45 – AI friends the Zuckerberg take and why it is dangerous 29:20 – Phone yes social no ethics engagement and shareholders 31:10 – Sign-off Black Mirror the void and what we do next #aijobs #cybersecurity #techcareers #futureofwork #generativeai #automation #entryleveljobs #jobmarket #middleclass #legitimatecybersecurity #ai

  36. 32

    The Day the Cloud Died: How One Outage Broke Everything

    What happens when ONE “cloud” hiccup in Virginia slams the brakes on your life—smart beds trap sleepers, Alexa goes dumb, Venmo sputters, and enterprise apps face-plant? Frank & Dr. Dustin break down Monday’s AWS DNS outage, why the internet’s “old bones” (DNS/IPv4) still run everything, how dependency hell spreads a local failure worldwide, and whether Web3/IPv6/real decentralization can stop the next domino run. 👂 Audio listeners: subscribe on any podcast platform via our feed: https://legitimatecybersecurity.podbean.com/ 🎤 Media & interview requests: [email protected] Chapters below. Drop your wildest “my house broke when AWS sneezed” story in the comments. ⬇️ Chapter Breaks 00:00 – Cold Open: “This was Monday” doomsday (beds, banks, Blackboard) 00:50 – DNS for Normals: the internet’s phone book (and why it failed) 02:45 – Single Point of Failure? us-east-1 and the centralization problem 04:03 – “There is no cloud, it’s someone else’s computer” (and your bed’s on it) 05:21 – How a regional outage went global: dependencies & third-party calls 06:40 – SBOMs, supply chain, and internet-scale dependency hell 07:24 – Pi-hole story: when your home DNS goes down, everything stops 09:12 – Resiliency vs reality: why some services lived while others died 10:45 – The domino stack: uptime, TTLs, and stale DNS making pain linger 12:18 – Could IPv6 help? (and why we still haven’t adopted it) 14:25 – “Second-gen DNS”: what would a safer, faster resolver look like? 16:07 – Monopoly math: if busting big clouds won’t happen, what will? 18:47 – Web3/Blockchain as a decentralized DNS idea—promise & tradeoffs 20:13 – Tor ≠ the model: decentralization without the dark-web baggage 22:20 – AI as infrastructure: power, cost, and more single points of failure 23:53 – Why blockchain never got sexy (and why it still might) 26:24 – Ghosts in the machine? (Spooky season teaser) 27:54 – Wrap: what to do before the next Monday #aws #dns #outage #cloudcomputing #cybersecurity #web3 #ipv6 #smarthome #supplychain #sbom #devops #incidentresponse

  37. 31

    AI Is Spying on You: Zero-Touch Hacks, Secret Data Leaks, and the “No Legal Privilege” Bombshell

    Your AI assistant is helpful… until it isn’t. In this episode, Frank and Dustin break down the zero-touch exploits (EchoLeak & ShadowLeak) that can hijack AI integrations like email and office suites, quietly exfiltrate your prompts and IP, and even leak them to attacker infrastructure—no clicks required. We also talk about why your chats aren’t protected by legal privilege, how AI activity factored into the California wildfire arsonist story, and what actually works: DLP, model governance, and when you should go local with LLMs. We keep it real (and a little nihilistic) while giving CISOs, IT leaders, and curious humans the playbook to reduce risk without killing innovation. 👉 Media & interview requests: [email protected] 🎧 Audio listeners: subscribe on any platform via https://legitimatecybersecurity.podbean.com/ 💬 Drop your idea for our new sign-off catchphrase in the comments! Chapters: 0:00 Cold Open — “What if your AI is spying on you?” 0:30 Welcome & Today’s Agenda (EchoLeak, ShadowLeak, legal privilege, arsonist story) 1:55 Zero-Touch Exploits Explained (no clicks, still owned) 3:11 How It Works via Email & Integrations (silent prompt injection → exfil) 4:48 Old Tradecraft, New Target (drive-by vibes, LLMs in the loop) 7:55 “Plain-Language Hacking” (Gandalf game, prompt judo) 10:27 Why This Still Counts as a Hack (intent, abuse of designed behavior) 12:52 Why SOCs Might Miss It (looks like normal AI traffic) 14:24 DLP, Asset Mgmt, and the “Hated but Needed” Controls 16:44 Should You Run Local LLMs? (pros, cons, update churn) 20:30 Liability & Definitions — Is This Really a Hack? (yes, and why) 22:25 AI Has No Feelings… But It Leaks Yours (reflection, social engineering) 23:16 “No Legal Privilege” Bombshell & The Arsonist Example 26:36 Privacy Culture Shift (profiling even when you opt-out) 29:45 Cat-and-Mouse Prompts (policy workarounds, “encrypt my answer” tricks) 31:19 Don’t Panic, Do Fundamentals — Then Regulate 32:36 What Good Regulation Looks Like (and where it fails) 35:40 Penalties with Teeth (or companies just budget the fines) 38:26 Next Week Tease: DOGE whistleblowers & data handling 39:01 Help Us Pick a Catchphrase (Outro & CTAs) #cybersecurity #ai #dataprivacy #pentesting #ZeroTouch #llm #copilot #chatgpt #dlp #infosec #datalossprevention

  38. 30

    AI Won’t Save You: James Gustafson on Junior Talent, Button-ology, and Real Risk Reduction

    Why train when you can just hire?” In this episode, BlueVoyant Senior Vulnerability & Risk Analyst James Gustafson explains why that mindset—and the myth that AI can replace fundamentals—is putting orgs at risk. From Army “combat cable guy” to enterprise VM leader, James breaks down how to move from scan → prioritize → fix, how to develop junior talent without gatekeeping, and where AI actually helps (and where it absolutely doesn’t). 🎧 Audio listeners can subscribe on any platform (Spotify, Apple, etc.) or here: https://legitimatecybersecurity.podbean.com/ 💼 Media & interview requests: [email protected] You’ll learn Why scan ≠ secure and how to make risk registers stick The hiring shift: junior roles, budgets, and AI misconceptions Packets vs. button-ology—what juniors lose when tools do too much How to communicate VM risk at 10k+ asset scale AI’s “sweet spot” for practitioners (and the painful edges) Chapter Breaks 00:00 Cold Open — “Misconceptions about what AI can replace” 00:17 Intro — Who is James Gustafson (BlueVoyant) 01:14 Origin Story — Movies, IRC, and early curiosity 03:13 Army to IT — “Combat cable guy” and real-world networking 04:31 Breaking In — 2009 job market, degrees & certs 05:48 Obsession & Passion — How to pivot from IT to cyber 06:39 Where Did Juniors Go? — Budgets + AI hype 08:20 AI Reality Check — Risk shifts, phishing, unknowns 10:02 History Rhymes — From mainframes to printing press to AI 14:05 VM at Scale — Actionable comms, policy, and ownership 15:18 Why Orgs Scan but Don’t Fix — The uncomfortable truth 17:06 Priorities vs. Patching — Firefights and thin teams 18:05 SOC Then vs. Now — Packets, Snort, SIEM & automation 19:54 Button-ology vs Fundamentals — Hiring for platforms 22:10 Teaching Without Gatekeeping — Recreating “packet” intuition 28:07 Training the Next Gen — Translating deep knowledge 30:26 Parenting & Passion — “Be excellent at something” 34:27 What’s Going Right — Industry sobers up on AI 36:33 Thought Experiment — If we “laid down arms” in cyber… 38:08 Wrap — Why fundamentals still win #cybersecurity #vulnerabilitymanagement #bluevoyant #ai #riskmanagement #soc #infosec #careerincybersecurity #cve #CISAKnownExploited #wireshark #Qualys #tenable #crowdstrike #microsoftdefender

  39. 29

    Shadow Credit Bureau Exposed: How LexisNexis Tracks Your Every Move (Even Roller Coasters!)

    What if your “credit score” wasn’t the full story? Frank and Dr. Dustin uncover LexisNexis, the massive data broker quietly collecting everything about you — from your social posts and insurance claims to your driving habits (even roller coasters count). 💥 In this episode: The hidden company that knows more about you than Equifax or Experian Why you can’t easily see, freeze, or delete your LexisNexis file The outrageous “roller coaster incident” that broke a man’s insurance rating How U.S. privacy laws fail to protect your data — and why you’re still the product Plus: Taco Bell’s failed AI experiment & what it reveals about the limits of artificial intelligence 📺 Watch to the end for a hilarious (and slightly terrifying) discussion on AI gone wrong — from 100,000 tacos to SOCs that might order them next. Subscribe for more Legitimate Cybersecurity deep dives — where we mix real-world cyber truths with humor, clarity, and brutal honesty. 👉 Listen anywhere you get podcasts 💬 Join the community: r/LegitimateCyber 🎙️ Hosted by Frank Downs & Dr. Dustin Brewer Chapter Breaks 00:00 – Cold Open: The roller coaster that broke his insurance 00:20 – “There’s a company tracking your life — and it’s not Equifax” 01:25 – The Big Three vs. the unseen fourth: LexisNexis 03:44 – How LexisNexis profiles you: social, insurance, driving, and debt 05:34 – The invisible rules: Not a credit bureau, not regulated 07:36 – Frank’s nightmare: trying to request your LexisNexis file 09:29 – “It knows your driving habits — and it’s probably wrong” 11:51 – Where’s the line for privacy, jobs, and mortgages? 13:18 – Data pollution: Can you flood your profile with fake info? 14:11 – OPM breach, lost privacy, and why we’ve already been exposed 15:34 – Privacy vs. necessity: the cost of living in a connected world 17:22 – Capitalism, democracy, and the right to your own data 19:44 – “It just hasn’t made you upset yet”: why no one fights back 20:48 – Data ownership: should we get paid for our data? 23:10 – The last bipartisan law (and why it was about dogs, not data) 27:22 – Hard left turn: Taco Bell’s AI disaster 29:44 – The limits of AI — and why you’ll always need humans 31:17 – Machine learning déjà vu in cybersecurity 32:13 – Cloud, costs, and the AI uncanny valley 33:37 – Wrap-up: The real threat behind the “shadow credit bureau” #cybersecurity #dataprivacy #lexisnexis #databrokers #ShadowCredit #ai #consumerprotection #privacyrights #infosec #legitimatecybersecurity

  40. 28

    Reddit’s Spiciest Cyber FAQs—Board Risk, Automation Fails, Pay Cuts & “Cyber Sucks”

    Dr. Dustin Brewer just passed his dissertation defense (👑 incoming), so we celebrated the only way we know how: by tackling Reddit’s most controversial cybersecurity questions—no fluff, real talk. In this episode, Frank Downs and (now) Dr. Dustin break down: How to brief a non-technical board so they actually fund security (tie risk to $$, ops impact, and avoid doom-mongering). What should already be automated (network topology & asset management… why isn’t this solved yet?). Should you take a pay cut to break into cyber? The honest “it depends” with finance, family, and sanity in mind. Unpopular opinions: degrees vs certs, do you need to code, and why humility beats fake expertise. “Cybersecurity sucks”—when it does, why it does, and how to know if it’s time to pivot. Where the next gen of cyber talent will come from (CS, bootcamps, liberal arts, law… and maybe alien overlords 👽). 👉 New episodes every week. 💬 Press or communications inquiries: 👇 Chapters below for quick jumping. If you found this helpful, smash Like, drop your spiciest hot take in the comments, and Subscribe for weekly episodes. Chapter Breaks 00:00 – Frank crowns Dr. Dustin Brewer (graduation, hoods, and coronation jokes) 01:42 – How do you explain risk to a non-technical board? 03:16 – From vuln counts to business dollars ($500k vs $23M losses) 05:26 – Avoiding “boy who cried wolf” cyber doom-scenarios 09:37 – What should already be automated in cybersecurity? 10:25 – Network topology & asset management: the automation failures 15:25 – Frank’s asset management horror story (Vista laptop box fail) 15:51 – Should you take a pay cut to get into cybersecurity? 19:20 – Frank’s unsolicited marriage advice for career-changers 22:19 – You are not your job: cyber ≠ your identity 23:22 – Unpopular opinions: degrees vs certs, no coding required 29:30 – Why you still need a risk register 29:51 – “There are no experts in cybersecurity”… or are there? 35:33 – Does cybersecurity suck? When it does, and why 37:37 – Frank’s dentist “tongue suction” horror story → career clarity 42:26 – Where the next generation of cyber talent will come from 47:48 – Final thoughts & wrap-up #cybersecurity #ciso #riskmanagement #cybercareers #automation #infosec #cyberjobs #reddit #legitimatecybersecurity

  41. 27

    From US Intelligence to DoD Cyber Ops: Frank & Dustin’s Origin Stories in Cybersecurity

    Why should you listen to us? Honestly—you shouldn’t. But if you do, know this: we’re not just two jokers talking theory. In this episode of Legitimate Cybersecurity, Frank Downs and Dustin Brewer open up about their real beginnings—from accidental entry into US Intelligence after 9/11, to packet-hunting puzzles, Wi-Fi tinkering, and Linux dependency hell, to Dustin’s Coast Guard days that led him into DoD cyber operations and battlefield coding. What you’ll hear: Frank’s unexpected pivot from English major → Arabic → US Intelligence → Packet Hunters → ISACA → vCISO Dustin’s childhood obsession with modems, Prodigy, and “Hackers” → DoD cyber ops → Iraq deployment software award → BlueVoyant leadership Why Wireshark still matters more than ever in an encrypted world The three inflection points that changed Frank’s career forever Why frameworks (NIST, ISO, HITRUST) keep failing—and Dustin’s PhD research into the human factor of security What we focus on today: AI, vCISO work, penetration testing, and the balance of family + cyber 🎯 If you’re looking for career inspiration, real stories, and unfiltered lessons from two practitioners who’ve done the work—this episode is for you. Timestamps below. 📩 Questions? [email protected] 💬 Drop a comment—we reply fast. 🔔 Subscribe for more real-world cybersecurity with humor and honesty. Chapter Breaks 00:00 Cold Open – “Why should you listen to us? You shouldn’t.” 00:19 Meet your hosts: Dustin & Frank 00:36 Why this episode: career steps & credibility check 01:23 Setting the stage: our backgrounds in cyber 02:06 Frank’s accidental entry into cybersecurity (post-9/11, US Intelligence) 03:26 The language grind: Arabic immersion & Spanish surprises 05:24 From Nordstrom suits to DoD analyst (wrong master’s degree first!) 07:15 Building real skills, Packet Hunters, and ISACA transition 07:40 Discovering Wireshark: packets as puzzles with real-world impact 09:02 Wi-Fi experiments, streaming flex, and home internet humility 09:48 Frank’s advice: explore cyber early—or you’ll be miserable 10:19 Dustin’s story begins: Palm Bay, Florida + engineering neighbors 11:14 Simpsons saxophone teacher → first coding mentor 12:32 AOL for DOS, Prodigy, CompuServe → modem obsession 13:26 Networking excitement & “Hackers” movie inspiration 14:23 Linux from scratch & dependency hell at age 15 15:17 School vs passion: community college frustrations → military track 16:25 Coast Guard IT school → voluntold to Fort Meade (DoD cyber ops) 18:03 Ground-up learning → teaching others by doing 19:13 Linux from scratch = trial by fire learning 19:51 Wireshark packet analysis as the foundation skill 21:02 Policy + frameworks: the cowboy days before NIST awareness 22:43 Frank’s 3 inflection points: contracting leap, Packet Hunters, discovering NIST 25:50 Dustin’s inflection points: first root login, Project Phalanx, Iraq software success 27:54 Building impactful systems → Army Achievement Medal for battlefield code 29:27 Perspective: cyber ops under fire → calm in the private sector 30:22 Frank now: family focus, vCISO variety, and AI’s cultural impacts 34:14 Tech culture & identity: from iPods to Meta glasses 34:53 Dustin now: pen testing, vuln mgmt, and a PhD on framework adoption 37:42 Why frameworks keep failing: the human layer 39:31 Rethinking cybersecurity like medicine, not just militaristic defense 40:15 How to reach us & engage with the show 41:04 Sign-off #cybersecurity #careerstories #packets #wireshark #linux #dod #usintelligence #techcareers #careeradvice #pentesting #vCISO #humanfactors #ai #frameworks

  42. 26

    Secret Algorithms Controlling You! Are You the User… or the Product?

    Are algorithms helping—or handling—you? Frank and Dustin dive into how recommender systems, data brokers, and AI-powered platforms shape your news, drives, purchases, health, and even relationships. From TikTok fear-mongering to Cambridge Analytica, OPM’s breach fallout, Google Maps routing incentives, Amazon “sponsored” defaults, and Facebook’s engagement shift—this episode asks the hard question: are you in control, or are you being steered? We also hit the nuance: when AI spots tumors earlier and flags outbreaks faster, do the ends justify the data means? Echo chambers, algorithm “poisoning,” privacy laws (or lack thereof in the U.S.), and the real-world line between convenience and manipulation—plus the wild story of a nurse who could smell disease before doctors could test for it. 🎧 Subscribe for sharp, funny, no-fluff cyber talk every week. 💬 Drop your take: are you comfortable trading agency for convenience? — 👥 Hosts: T. Frank Downs & Dustin Brewer 🎙️ Podcast + clips: @LegitimateCybersecurity 🧠 Subreddit: r/LegitimateCyber 🔔 Like, subscribe, and share to beat the algorithm at its own game. Chapter Breaks 00:00 – Cold Open: “If you’re not paying, you’re the product.” 01:20 – TikTok: personalization vs. geopolitics 02:37 – OPM breach & SF-86: the most intimate data spill 04:08 – Data brokers & geolocation: finding anyone (even Congress) 05:22 – The U.S. privacy gap (hello CCPA, goodbye federal law) 06:11 – Shadow credit files: LexisNexis, GM telemetry & your insurance 07:45 – Maps that nudge: are routes sold to brands? 08:23 – Amazon’s “sponsored” defaults & subtle purchase steering 09:39 – “Emergent behaviors” & divisive feed design 10:53 – Can we trust any filter—and do we have options? 11:30 – AI is code (and code is messy): hallucinations & ad-stuffed search 12:27 – Living private vs. living miserable: the balance problem 15:16 – Biased training data: we met the trainer and it’s us 17:47 – Medicine wins: diagnostics vs. the data tradeoff 19:30 – Joy Milne & “the smell of disease”: human pattern-finding #cybersecurity #algorithms #privacy #ai #databrokers #tiktok #opm #EchoChambers #RecommenderSystems #DigitalEthics #Nudging #LegitimateCybersecurity 22:44 – AI for signals, humans for meaning 23:34 – Robots, laundry… and the rental future 24:57 – Do people want out of echo chambers? 26:57 – Comfort vs. being “right”: why rage sells 27:24 – Algorithm poisoning ethics: self-defense or sabotage? 28:11 – The kindness trap: loneliness, AI compliments & harms 30:16 – What practitioners should do: policy, guardrails, education 32:25 – The inevitable? Choosing agency in a steered world 33:16 – Outro: “If this was recommended to you…”

  43. 25

    From Submarines to Cybersecurity: Chris Adkins’ Wild Journey Into Cyber Defense

    What do submarines, Linux servers, Apple X Servers, and SOC analysts all have in common? They were all part of Chris Adkins’ path into cybersecurity. In this episode of Legitimate Cybersecurity, Frank and Dustin dive deep with Chris as he shares his unique journey from being a sonar technician in the U.S. Navy to breaking into cyber through a SOC—and eventually advising top companies through breaches and building cyber programs. We cover: How non-traditional paths (like the Navy) can launch cyber careers The evolution of SOC life and tools (FireEye, ArcSight, Palo Alto, CrowdStrike, etc.) The AI security paradox: why AI will cause more breaches, not fewer Why leadership culture determines breach resilience The controversial new “Letters of Marque” bill that could legalize U.S. cyber privateers This episode is packed with career lessons, insider war stories, and the kind of weird/funny hypotheticals that only Legitimate Cybersecurity delivers. ⏱️ Chapter Breaks 00:00 – Intro & Chris’ non-traditional entry into cyber 01:20 – Life on submarines & discovering IT underwater 04:20 – From BackTrack to BP: finding cybersecurity as a career 07:00 – SOC life at BP: Panama shifts, POCs, and new tools 10:40 – FireEye, EDR, and the evolution of detection tech 13:50 – Why AI may actually increase breaches 16:30 – Career changers & why it’s hard to “get into cyber” 20:00 – The problem with cybersecurity education & perception 27:30 – The “Letter of Marque” bill: cyber privateers?! 38:40 – Post-breach consulting: calming chaos & fixing culture 44:20 – Bias, assumptions, and the hidden root of breaches 50:00 – If SOCs ran on ChatGPT: complaints & HR problems 52:40 – Funniest phishing excuses & cyber training fails 59:40 – Leadership, culture, and why CEOs define cyber success 1:03:30 – Wrap up & Chris’ future return #Cybersecurity #Hacking #AI #SOC #CyberCareers #LegitimateCybersecurity #NavyToCyber #Infosec

  44. 24

    He Helped Take Down the Dark Web (Twice) — Vincent D’Agostino on DFIR, FBI & Real-World Cyber

    Former FBI agent and attorney Vincent “Vinnie” D’Agostino (now Head of Digital Forensics & Incident Response at BlueVoyant) joins us to unpack dark web takedowns, real DFIR process, and how a “range” of skills (law, tech, stand-up, curiosity) compounds into cyber success. We cover: How a team helped take down the dark web—twice DFIR reality vs myth: scoping, persistence hunts, EDR triage, due diligence in M&A The RDP ≈ drunk driving analogy you’ll never forget FBI - Private sector: what translates (and what doesn’t) Career advice for students & pros in the age of AI: become “rangeful,” seize moments 👥 Guest: Vincent D’Agostino — Head of DFIR @ BlueVoyant; former FBI agent & attorney 🎙 Hosts: Frank Downs & Dustin Brewer 📌 Subscribe for deep, funny, legit cyber every week. Chapter List 0:00 Cold Open — “Dark Web x2” 0:22 Intro & Who is Vincent D’Agostino 1:05 8086, 5MB HDD & falling in love with computers 5:30 From law to FBI: timing, tech, and reality checks 10:45 Cyber squads, TOR, Bitcoin & dark web context 16:30 DFIR in practice: scoping, EDR, persistence hunts 24:30 The RDP ≈ drunk driving analogy every CISO needs 29:30 Competence over politics (how to show up in calls) 34:30 Career “Range”: why hobbies compound into expertise 45:30 M&A due diligence: IR skills without the sirens 51:00 Humor as a tool: rapport in dark situations 57:00 3 Takeaways + Subscribe/Next Episode #DarkWeb #DFIR #DigitalForensics #IncidentResponse #FBI #BlueVoyant #Cybersecurity #CyberPodcast #ThreatHunting #EDR #Velociraptor #SentinelOne #Ransomware #CISO #Bitcoin #TOR #BlueTeam #CareerAdvice #AI #LegitimateCybersecurity #MandA #DueDiligence

  45. 23

    ChatGPT-5: Smarter Hackers, Dumber Defenders?

    ChatGPT-5 is here — but is it really the leap forward everyone’s claiming? In this episode of Legitimate Cybersecurity, Frank and Dustin break down the hype vs. reality. From coding disasters that “look pretty but don’t work,” to AI being more like “that coworker who makes everything harder,” we explore what this means for hackers, defenders, and the future of cybersecurity. 👉 Is ChatGPT-5 truly artificial intelligence, or just machine learning with a better paint job? 👉 Can AI pass cybersecurity exams like the CISSP? 👉 Will AI babysit your kids one day — and should that terrify you? Stay tuned for the myths, the laughs, and the real risks. Watch to the end for a wild take on Star Trek, civil wars, and whether AI could really replace humans. #AI #CyberSecurity #ChatGPT5 #Hacking #TechNews Chapter List: 0:00 – Cold Open (funny/hooky clip) 0:10 – Welcome + Episode Setup 1:00 – What’s Actually New in ChatGPT-5? 3:00 – Pretty Code That Doesn’t Work 5:00 – AI as the Annoying Coworker 7:00 – Is This Really AI or Just ML? 10:00 – Hackers Don’t Care If It’s Wrong 13:00 – Cognitive Offloading + Laziness Debate 15:30 – Weird Time: Frank’s Coding Fail Story 18:30 – The Rise of Prompt Engineers 21:00 – AI Gone Wrong (Teen Suicide Example) 23:30 – Postmodern Truth & Poisoned Data Sources 27:00 – Can AI Pass the CISSP? Cheating & Proctors 33:00 – The Real Definition of AI (John McCarthy 1956) 36:00 – AI Slop in Writing and Coding 38:30 – Certification Exams & The Drunk Security Practitioner 40:30 – Wrap Up: ChatGPT-5 = Faster, Not Smarter #ChatGPT5 #CyberSecurity #ArtificialIntelligence #TechNews #Hacking #MachineLearning #AIHype

  46. 22

    From Recon to Wrecked: The Cyber Kill Chain Breakdown (With Laughs)

    What if you could break down every cyberattack into just 7 steps? In this episode of Legitimate Cybersecurity, Frank and Dustin dive deep into the Cyber Kill Chain — Lockheed Martin’s 7-stage framework for understanding and stopping attacks — and compare it to the MITRE ATT&CK framework, hacker methodology, and even… honeypots, magicians, and Christopher Nolan films. We cover: The 7 stages: Recon, Weaponization, Delivery, Exploitation, Installation, C2, and Actions on Objectives Why insurance companies make cyber defense harder Why honeypots are the “magician’s trick” of cybersecurity How to explain attacks to executives so they actually care Tangents about Comic-Con, The Simpsons, Star Trek, and South Park (because of course we did) Whether you’re a seasoned pro or just cyber-curious, this episode makes frameworks fun. And dangerous. And maybe slightly nerdy. 💬 Drop your favorite Kill Chain phase in the comments! #CyberKillChain #CyberSecurity #EthicalHacking #MITREATTACK #PenTesting #InfoSec #Honeypots #CyberInsurance #CyberDefense #NIST #LockheedMartin #LegitimateCybersecurityPodcast Chapter List 00:00 – Welcome & accidental name change to “The Cyber Kill Chain Podcast” 00:37 – Comic-Con chaos & nerd solidarity 01:40 – What is the Cyber Kill Chain? (And why Lockheed Martin made it) 03:18 – Cyber Kill Chain vs. MITRE ATT&CK: Different perspectives 05:22 – Insurance nightmares & cyber policy loopholes 08:03 – The 7 stages explained (Recon → Actions on Objectives) 14:42 – Framework overload & mapping standards 18:59 – Real-world pen test insights & APT patience 21:19 – Teaching grad students & professor naming quirks 23:03 – AI politeness, South Park, and AI “relationships” 25:01 – Cybersecurity fatigue & losing the funding edge 28:22 – Where defenders can actually break the Kill Chain 29:41 – Honeypots: magician’s trick or wizard’s weapon? 34:42 – Christopher Nolan, The Prestige, and Wireshark wizardry 38:13 – Why conveying frameworks simply wins the boardroom 40:26 – Wrapping up: Vote for us & leave your questions

  47. 21

    Quantum Day is Coming: Will Quantum Computing Break Cybersecurity?

    Quantum computing is no longer science fiction—it’s a ticking clock for modern encryption. In this episode of Legitimate Cybersecurity, Frank and Dustin break down Q-Day, the moment when quantum computers may render current cryptography useless. We explore how close we really are, the science (and hype) behind quantum technology, and what CISOs should be doing NOW to prepare. Along the way, expect tangents about Star Trek, Ant-Man, AI, and a few moments that’ll make you laugh out loud. 🎙️ Got a topic or guest suggestion? Email us at: [email protected] 👍 Like, comment, and subscribe for weekly cybersecurity deep-dives that mix humor with hard truths. Chapters: 00:00 – The ASMR Frank & Star Wars Quantum Vibes 02:12 – What is Q-Day & Why Does It Matter? 05:54 – How Cold is Quantum? (Hint: Near Space Cold!) 09:40 – Breaking Encryption: The Qubit Threat 14:45 – How CISOs Should Handle Quantum Hype 19:16 – Hidden Financial Meltdowns & The Transfer of Wealth 23:32 – Quantum Internet & Faster-Than-Light Data 28:26 – Hackers, Ant-Man, and Sci-Fi Meets Science 33:26 – Turning Q-Day Concerns into Real Security Wins 35:49 – Final Thoughts & How to Prepare Today #quantumcomputing #QDay #cybersecuritypodcast #encryption #postquantumcryptography #ai #nisteoameni #ciso #legitimatecybersecurity #techfuture #startrek #antman

  48. 20

    Internet of (Terrifying) Things: IoT Hacks, Biochips & Beer Bots

    Today on Legitimate Cybersecurity, Frank and Dustin dive deep into the weird, wild, and worrying world of IoT (Internet of Things) — from smart thermostats and connected doorknobs to pacemakers with IP addresses and hacked fish tanks. You’ll hear real-life stories of IoT gone wrong (including a connected beer brewer used for hacking), explore the creepy rise of biohacking and RFID implants, and find out what happens when Roombas spy on you in the bathroom. We also break down why IoT devices are so vulnerable, the challenges with industry standards like Zigbee and Matter, and whether privacy laws like HIPAA and GDPR are enough to protect us in a hyper-connected future. This episode blends expert insight, sarcasm, and actual advice — with a few nostalgic tech throwbacks thrown in. 👉 Tell us in the comments: Would YOU put an RFID chip in your hand? Or is that a step too far? 🧠 Topics Covered: Biohacking at DEF CON IoT in Human Evolution Pacemaker recalls & medical device hacks Why Ring doorbells talked to children The Fish Tank Casino Hack Why Alexa might be gaslighting you ISO standards, Z-Wave, Zigbee, Matter Smart home fails (IKEA blinds, anyone?) Why Apple might be the “luxury” privacy model CRISPR, AI, and Neuralink 🔗 Don’t forget to like, comment, and subscribe. It helps us battle the algorithm overlords and keeps our IoT-connected fridge from judging us. 🗳️ We’ve been nominated for the Podcast Awards! Vote for us at podcastawards.net 📬 Press inquiries, sponsorships, or topic requests? Email us at: [email protected] Chapter List: 00:00 – Intro: Is IoT Out of Control? 00:27 – How IoT Went from SCADA to Dog Collars 01:50 – IoT & Cognitive Offloading: Are We Getting Lazier? 04:31 – Biohacking: RFID Chips & Pacemaker Hacks 09:02 – Self-CRISPR?! The Shocking Reality 12:15 – Mark of the Beast vs. Palm Scanners: Privacy Panic 15:03 – Your Coffee Maker Could Burn Down Your House 16:26 – Hacking Beer Makers & Server Farms 22:26 – Casino Hacked by a Fish Tank? 23:25 – Ring Cameras Talking to Kids: IoT Nightmares 25:25 – Roombas Spying on You in the Bathroom 27:52 – Cheap IoT: A Privacy Disaster Waiting to Happen? 30:25 – Apple vs. Android: Who’s Winning the Privacy War? 32:03 – Outro & Podcast Awards Announcement #IoT #Biohacking #Cybersecurity #RFIDImplants #CRISPR #SmartHomeSecurity #ConnectedDevices #InternetOfThings #PacemakerHack #FishTankHack #RingCameraHack #PrivacyMatters #AIandCyber #TechEthics #CyberAwareness #Neuralink #HackedDevices #LegitimateCybersecurity #CyberThreats #SmartDeviceFails

  49. 19

    We’re Losing the Cyber War — Here’s Why | UMD’s Charles Harry

    Dr. Charles Harry — former NSA leader, cybersecurity strategist, and professor at the University of Maryland — joins Legitimate Cybersecurity to expose the hidden gaps in U.S. cyber defense. From nation-state strategy to local school vulnerabilities, this episode uncovers why most cybersecurity efforts are missing the mark… and how to fix it. We explore: Strategic cyber risk (not just IT vulnerabilities) Mapping 50,000+ exposed devices across U.S. counties The "operational art" of cyber warfare Why grants are being wasted The AI & quantum arms race vs. China 💣 This episode is packed with insights for CISOs, policy makers, military analysts, and tech leaders alike. 🎙️ Listen to the audio version on Spotify, Apple Podcasts & more. 📩 For guest inquiries or partnerships, reach us at: [email protected] Vote for our podcast at: podcastawards.com #Cybersecurity #CyberWar #CharlesHarry #LegitimateCybersecurity #CyberStrategy #NISTCSF #QuantumSecurity #AIInCybersecurity #PublicSectorCyber #NvidiaVsChina #RiskManagement #CyberGovernance 00:00 – Cold Open + Intro 00:22 – Meet Dr. Charles Harry 01:52 – What Is Strategic Cybersecurity? 05:02 – Risk at the Sector Level 08:22 – Cyber Operational Art: The Missing Middle 13:47 – Mapping 50,000+ Public Sector Devices 21:00 – Why Federal Cybersecurity Grants Fail 28:00 – Red Team vs. Blue Team: The Divide That Shouldn't Exist 34:02 – Risk Frameworks: Useful or Useless? 43:02 – Quantum & AI: Reshaping the Threat Landscape 48:50 – Nvidia vs. China: The True Arms Race 53:10 – Final Thoughts + How to Build a Strategic Cyber Defense

  50. 18

    You Can’t Trust Your Eyes or Ears Anymore: How AI Is Breaking Cybersecurity

    🎙 In this episode of Legitimate Cybersecurity, we dive deep into the unsettling reality of AI in modern cybercrime. Senator Marco Rubio was impersonated by AI in a high-level cyber deception campaign, and that's just the beginning. Frank and Dustin unpack: 🧠 Deepfake threats to democracy 🔐 Signal messaging & nation-state exploitation 🧪 Data poisoning and post-truth dangers 🛡️ AI in cybersecurity: helper or hazard? 🎭 Aquaman scams grandma?! 🗳️ The future of elections in the AI age This is the episode that asks: What is truth? And can we still trust anything we see or hear? 👉 VOTE for us in the Technology category at PodcastAwards.com 👉 Like, Subscribe, and hit that 🔔 — it helps more than you know! #Cybersecurity #AIThreats #Deepfakes #AIinCyber #MarcoRubio #Cybercrime #DataPoisoning #LegitimateCybersecurity #PostTruth #ElectionSecurity #PodcastAwards #AIDeepfakes #ChatGPT #GrokAI #QuantumComputing Chapter Breaks: 00:00 – Welcome to the AI Chaos 01:00 – Marco Rubio’s Deepfake Scandal 03:30 – Signal App, Trust, and Exploitation 06:00 – Grandma Got Catfished by Aquaman (Real Story) 08:30 – AI: Making Hacking Easier or Dumber? 11:00 – Prompt Injection, Scambaiting, and Evil Clippy 13:30 – Deepfakes vs. Quantum Computing 16:00 – The Dystopia of AI Dating and “Spin the DJ” 19:00 – Truth, Misinformation, and Model Poisoning 23:00 – Blockchain for Truth? (Business Idea Alert) 25:30 – Star Wars, White Lotus, and the Collapse of Truth 28:00 – Elections, Echo Chambers, and Deniability 30:00 – Vetting Info in the AI Age 33:00 – Should ChatGPT Run a Town? 34:00 – Final Thoughts + Next Episode Preview (The Economics of Cyber)

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Legitimate Cybersecurity Podcasts

HOSTED BY

LegitimateCybersecurity

CATEGORIES

Frequently Asked Questions

How many episodes does Legitimate Cybersecurity Podcasts have?

Legitimate Cybersecurity Podcasts currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Legitimate Cybersecurity Podcasts about?

Legitimate Cybersecurity Podcasts

How often does Legitimate Cybersecurity Podcasts release new episodes?

Legitimate Cybersecurity Podcasts has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Legitimate Cybersecurity Podcasts?

You can listen to Legitimate Cybersecurity Podcasts on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Legitimate Cybersecurity Podcasts?

Legitimate Cybersecurity Podcasts is created and hosted by LegitimateCybersecurity.
URL copied to clipboard!