The 443 - Security Simplified podcast artwork

PODCAST · news

The 443 - Security Simplified

Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cyber security headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into easily understood and actionable insights.

  1. 378

    Helping APAC Organizations Stay Ahead of Cyber Threats with Brett Chalmers - The 443 Podcast - Episode 374

    Recorded live at WatchGuard’s APAC Partner Conference in Bali, Indonesia, this episode of 443 – Security Simplified features Brett Chalmers joining Marc Laliberte and Corey Nachreiner to discuss the evolving cybersecurity landscape across APAC. The conversation covers emerging threats, security challenges facing organizations, and how MSPs can help customers build resilience and strengthen their security posture in an increasingly complex threat environment.

  2. 377

    Cybersecurity Challenges and Opportunities Across APAC with Henson Yem - The 443 Podcast - Episode 373

    Recorded live at WatchGuard’s Impact Partner Conference in Bali, Indonesia, this episode features Henson Yem, CIO and Technical Services Director at Tang Technology. Henson joins Marc Laliberte and Corey Nachreiner to discuss the evolving cybersecurity landscape across Australia and APAC, including emerging threats, the growing impact of AI, and the challenges organizations face in strengthening their security posture. The conversation also explores how MSPs can help customers build resilience, improve security maturity, and navigate an increasingly complex threat environment.

  3. 376

    Time to Exploit is Cratering - The 443 Podcast - Episode 372

    This week on the podcast we bring back WatchGuard's VP of MDR and Endpoint Adam Winston to discuss the cratering mean time to exploit of vulnerabilities and GitHub's recent data breach.

  4. 375

    Cybersecurity Across Europe: Partnerships, AI, and Emerging Threats with Peter Johnson - The 443 Podcast - Episode 371

    Recorded at WatchGuard’s EMEA Partner Conference, in Dubrovnik, Croatia, this episode of 443 – Security Simplified features Peter Johnson from Schwartz GmbH for a conversation on how cybersecurity priorities are evolving across Europe. Peter discusses the increasing complexity organizations face when balancing security, compliance, and operational efficiency, along with the challenges of supporting customers and partners with varying levels of cybersecurity maturity. The discussion also covers the growing influence of AI on both attackers and defenders, regional differences in security approaches, and the practical steps businesses can take to strengthen resilience against modern cyber threats.

  5. 374

    MSPs, Cyber Resilience, & the Human Side of Security w/James McMillan - The 443 Podcast - Episode 370

    Marc Laliberte and Corey Nachreiner recorded a special episode from WatchGuard’s EMEA Partner Conference in Dubrovnik, Croatia, featuring James McMillan, CTO of Redinet Limited. They discussed the evolving cybersecurity landscape for MSPs and businesses across Europe. James shares insights from his journey in IT and cybersecurity, the growing challenges organizations face as threats become more sophisticated, and why cyber resilience requires more than just technology. The conversation also explores how AI is changing security operations, the importance of building strong customer relationships, and what separates organizations that are proactively improving security from those struggling to keep pace.

  6. 373

    You Wouldn't Download a Shipment - The 443 Podcast - Episode 369

    This week on the podcast, we discuss a recent warning from the FBI about hacking leading to stolen shipments. Before that, we cover the Vercel software supply chain incident before discussing the Vect Ransomware-as-a-service turned accidental wiper.

  7. 372

    Cybersecurity in LATAM: SMB Risks, AI, and Regional Realities with Paul Harris - The 443 Podcast - Episode 368

    This week on the podcast, Marc and Corey sit down with Paul Harris, CEO of BGLA and Futurity Corp at WatchGuard's Impact Partner Conference in Tulum, to explore the evolving cybersecurity landscape across Latin America. Paul shares his journey from early days in cybersecurity to leading organizations in the region, while breaking down the biggest concerns facing LATAM SMBs today. The conversation also covers how AI is reshaping cybersecurity, the challenges of securing partners across diverse markets, and practical advice for business leaders looking to stay ahead of cyber risk in LATAM.

  8. 371

    A RedSun Rises - The 443 Podcast - Episode 367

    This week on the podcast we discuss RedSun, the latest researcher-disclosed zero-day in Microsoft Windows.  After that, we chat about a Europol-lead takedown of DDoS-for-hire services before ending with our thoughts on Microsoft's latest RDP security updates.

  9. 370

    Project Glasswing - The 443 Podcast - Episode 366

    This week on the podcast, we discuss Anthropic's Project Glasswing and what the Claude Mythos announcement means to cybersecurity. After that, we cover FrostArmada, a campaign from a Russian GRU-backed threat actor that has compromised tens of thousands of home networking routers. Finally we end with a chat about Google Chrome 146's new feature to protect against session hijacking.

  10. 369

    Claude Code Accidently Goes Open-Source - The 443 Podcast - Episode 365

    This week on the podcast, we cover the accidental Claude Code source code leak and what it means for users and the wider ecosystem. After that, we discuss the Axios supply chain compromise impacting users of a JavaScript library with over 100 million weekly downloads. We end with our thoughts on Browser Gate, the name given to allegations that Microsoft is illegally harvesting LinkedIn customer data for a competitive advantage.

  11. 368

    The US Ban on Foreign Routers - The 443 Podcast - Episode 364

    This week on the podcast, we discuss the US government's ban on foreign-manufactured consumer routers and its likely impact. After that, we cover a research post from Huntress on a recent phishing campaign leveraging OAuth Device Authentication flows to retain long-term access to compromised accounts. We end with a review of key takeaways from Google's Cloud Threat Horizons report for H1 2026.

  12. 367

    Cybersecurity Analyst & Investigations Lead, Kristen Yang - The 443 Podcast - Episode 363

    In this episode, Corey Nachreiner interviews WatchGuard Cybersecurity Analyst and Threat Emulation & Investigations Lead, Kristen Yang, about the path into cybersecurity, the evolution from threat hunting to leading investigations, and the realities of defending against modern attacks. They explore today’s threat landscape, incident response mistakes, red teaming lessons, MITRE ATT&CK, AI in security, and the skills analysts need most, plus a rapid-fire round to close things out.

  13. 366

    Stryker's Network Disruption - The 443 Podcast - Episode 362

    This week on the podcast, we cover the cyber attack that managed to wipe more than 200,000 resources off of the medical technology giant Syryker's network. After that, we review a research post on a good chrome extension gone bad. We end by discussing a recent Microsoft threat intelligence post on how North Korean-backed threat actors have operationalize AI for job scams.

  14. 365

    Hackerbot-Claw Crosses the Line - The 443 Podcast - Episode 361

    This week on the podcast, we chat about an OpenClaw bot that moved beyond vulnerability research and into malicious activity. Before that, we cover an AI-discovered vulnerability in the pac4j-jwt authentication library before ending with a discussion on an upcoming California law designed to help make age verification in the digital age easier, but with massive consequences.

  15. 364

    Cisco's SD-WAN 0-Day - The 443 Podcast - Episode 360

    This week on the podcast, we discuss the recently disclosed and patched 0-Day vulnerability in Cisco's Catalyst SD-WAN Controller which has been under active exploit for 3 years. After that, we cover the latest open source supply chain attack involving a self-propagating worm targeting AI tools. We end with a discussion about another social engineering campaign targeting job hunters in the software development world.

  16. 363

    WatchGuard's Internet Security Report 2025 H2 - The 443 Podcast - Episode 359

    This week on the podcast, we cover the WatchGuard Threat Lab's Internet Security Report for the second half of 2025. In this episode, we cover the latest trends for malware at both the network perimeter and endpoint, network attacks, and the top malicious domains from the period before ending with some tips everyone can use to defend their networks.

  17. 362

    OpenClaw as a Security Threat

    This week on the podcast, we discuss OpenClaw, the open source chatbot that has exploded in popularity since launching late last year, and some of the risk it introduces to organizations. Before that, we chat about Ring's Super Bowl advertisement that caused a stir before ending with a Google Threat Intelligence Group report on advanced threat actor AI usage.

  18. 361

    Moltbook Data Exposure

    This week on the podcast, we cover a recent supply chain compromise involving the popular text editor Notepad++. After that, we discuss a recent vulnerability report in the Moltbook AI social network before ending with a deep-dive review of a recent remote code execution vulnerability in the N8N automation platform.

  19. 360

    ChatGPT Oopsies Series of Information

    This week on the podcast, we cover a Politico report detailing a security lapse at CISA in the United States involving sensitive data and a public version of ChatGPT. Following that, we dive into a couple of vulnerabilities recently resolved in the SolarWinds Web Help Desk application. Finally, we end with some closure on a story about two Coalfire penetration testers who were arrested several years ago for completing a penetration test in Iowa.

  20. 359

    Uncovering A Mass VPN Phishing Campaign - The 443 Podcast - Episode 355

    This week on the podcast, we cover some first-hand research from the WatchGuard Threat Lab on a phishing campaign targeting users of nearly every major VPN vendor. After that, we discuss two recently resolved vulnerabilities in the Fortinet FortiSIEM application, then end with research from Varonis on a new attack flow against Copilot called RePrompt.

  21. 358

    React2Shell - The 443 Podcast - Episode 352

    This week on the podcast, we discuss the recently disclosed React2Shell vulnerability affecting a wide array of web applications. Before that, we review a new phishing campaign that uses a newly coined ConsentFix technique before discussing a security misstep from Home Depot.

  22. 357

    The Botnet that Topped Cloudlfare's Domain Charts - The 443 Podcast - Episode 354

    This week on the podcast, we cover the Kimwolf botnet, a collection of compromised IOT devices that at one point grew so large that it's command and control domain beat out Google.com as the most popular domain on the internet. After that, we discuss yet another devious take on ClickFix style phishing before ending with coverage from Cisco TALOS on another threat actor targeting edge networking equipment.

  23. 356

    2025 Ends With a Bang - The 443 Podcast - Episode 353

    This week on the podcast, we cover a wave of attacks against network edge equipment and internet-exposed systems including an update on the recently patched Firebox 0-Day. After that, we cover two stories on browser extensions siphoning off data and making unwanted modifications to victim’s web browsing activity.

  24. 355

    WatchGuard's 2026 Cybersecurity Predictions - The 443 Podcast Episode 351

    This week on the podcast, we go through all six of our cybersecurity predictions for 2026. For each prediction, we'll discuss the trends behind them, why we think they'll hit next year, and some takeaways for people and organizations on how to react to them in the coming year.

  25. 354

    OWASP Top 10 2025 Edition - The 443 Podcast - Episode 350

    This week on the podcast, we cover OWASP’s update to the top 10 web application security weaknesses and its changes from the 2021 list. We also cover a recently uncovered adversary-in-the-middle campaign that’s pushing malicious software updates to targeted systems. We conclude with our opinions on Microsoft’s latest AI features, which are coming to Windows.

  26. 353

    2025 Security Predictions Recap - 443 Podcast - Episode 349

    This week on the podcast, we review our 2025 security predictions and grade ourselves on our accuracy. We recap all 6 predictions for 2025 from multi-modal AI being used to create entire attack chains to the CISO role becoming the least desirable role in business, and follow up on this year's news to see if they hit or not.

  27. 352

    October Ransomware Update - The 443 Podcast - Episode 348

    This week on the podcast, we have our resident ransomware expert, Ryan Estes, on to give an update on the latest in the ransomware ecosystem. We cover a few recent changes to operators, extortion techniques, and business impact from ransomware attacks in recent months.

  28. 351

    What's Going On at Salesforce? - The 443 Podcast - Episode 347

    This week on the podcast, we discuss the wave of extortion attacks targeting companies that use Salesforce. After that, we discuss Discord's breach involving their customer support application. Finally, we dive deep into the recent Oracle E-Business Suite zero day vulnerability and how attackers chained together multiple low-severity findings into a critical issue.

  29. 350

    An AI/ML Deep Dive with Luke Wolcott - The 443 Podcast - Episode 346

    This week on the podcast, we bring on WatchGuard's head of MDR data science Luke Wolcott to discuss the evolution of machine learning and artificial intelligence in cybersecurity. We dive into the differences in common (and uncommon) machine learning models, the pros and cons of supervised vs unsupervised learning, and why some of the coolest things happening in AI aren't the ones you hear about in the news.

  30. 349

    How GitHub Plans to Fix the Supply Chain - The 443 Podcast - Episode 345

    This week on the podcast, we discuss Cisco's recent zero-day vulnerabilities before covering a Microsoft Threat Intelligence post on a phishing campaign that abuses SVG files. After that, we review GitHub's proposed changes for securing the open source software supply chain.

  31. 348

    One Token to Rule Them All - The 443 Podcast - Episode 344

    This week on the podcast, we cover a vulnerability in Entra ID that could have allowed attackers to gain Global Admin access to any and all Entra ID tenants. After that, we discuss the Shai Hulud NPM worm that ran rampant over the last week, infecting hundreds of packages. Finally, we end with a quick reminder to WatchGuard Firebox customers to update their devices to the latest firmware to resolve CVE-2025-9242z

  32. 347

    Should Microsoft Be More Accountable for Security?

    This week on the podcast, we cover a massive software supply chain compromise involving widely-used NPM packages. After that we discuss an increase in social engineering attacks called ClickFix. Finally, we end with a discussion of Senator Wyden's recent letter to the FTC demanding Microsoft being held accountable for "gross cybersecurity negligence" and whether his claims have any merit.

  33. 346

    Does Security Training Work?

    This week on the podcast, we discuss a recently published research study from UC San Diego on the effectiveness on security awareness training on phishing prevention. After that, we discuss a security researcher's work on identifying vulnerabilities in four separate employee webapps at Intel. Finally, we end with our analysis of a Ponemon Institute research report called The State of File Security.

  34. 345

    The 2025 Cost of a Breach Report

    This week on the podcast, we discuss key findings from IBM and the Ponemon Institute's 2025 Cost of a Breach Report, including a deep analysis of AI impacts in cybersecurity. Before that, we cover Norway's claim that Russian-aligned hackers opened a floodgate in one of their dams. We also discuss a vulnerability in Microsoft 365 Copilot that allowed the AI to delete its own audit logs.

  35. 344

    Is Zero Trust a Total Bust?

    This week on the podcast, we discuss key findings from a DefCon presentation from researchers at AmberWolf titled ZeroTrust, Total Bust and what it means for Zero Trust Network Access. After that, we review a new vulnerability in the FortiWeb WAF before ending with a quick update from Google Project Zero on a new vulnerability disclosure policy.

  36. 343

    What We Know About the Sonicwall SSLVPN Attacks

    This week on the podcast, we discuss some recent research into a new zero day vulnerability in the popular WinRAR utility under active exploit. After that, we give a round up on everything we know about the SonicWall SSLVPN attacks from the last few weeks before ending with a review of a new ChatGPT vulnerability.

  37. 342

    Clorox vs Cognizant

    This week, we discuss the SharePoint ToolShell vulnerabilities that recently received an out-of-cycle patch from Microsoft. After that, we cover some research into a Chrome and Edge extension malware campaign that impacted 2.3 million victims. Finally, we end by discussing a lawsuit from Clorox against their offshore helpdesk provider Cognizant stemming from a security incident 2 years ago.

  38. 341

    Outing Chinese Semiconductor Cyber Spies

    This week on the podcast, Corey Nachreiner and guest host, Ryan Estes, from WatchGuard’s malware analysis team, cover the cybersecurity news for last week. We chat about AI-based site cloaking tools on the underground, how Domain Tools found potentially unwanted executables hiding in DNS TXT records, and a Chinese state-sponsored set of targeted phishing campaigns going after the Taiwanese semiconductor industry and its supply chain. Join us to learn more and discuss how we can protect ourselves from similar threats. 

  39. 340

    Exploring Endpoint Threats with WatchGuard’s Q1 2025 Internet Security Report.

    This week on the podcast, Corey Nachreiner and guest host, Ryan Estes, from WatchGuard’s malware analysis team, explore WatchGuard’s recently released Q1 Internet Security Report (ISR). As always with the ISR, we highlight the top malware, network attacks, and malicious domains that our products see, but with our guest host, the author of the Endpoint section, we dive much deeper into all the threats arriving a our customers’ endpoint. Listen in for the latest threat landscape trends and some practical tips to stay safe from the most recent threats.

  40. 339

    Rewind: Microsoft Kernel Shift, GPT-4o Threats, and Scattered Spider Update

    First, we look back at Microsoft’s major shift to remove endpoint protection from the Windows kernel. When we first covered it, it was a proposed change—now it's happening, and the implications are big. Next, we revisit a segment on GPT-4o and how generative AI is fueling the next wave of social engineering attacks. It's smarter, faster, and more convincing than ever. And finally, a refresher on the arrest of a Scattered Spider leader. While that made headlines, the group's activity hasn’t slowed down, they're still very much on the radar, as we discussed just last week.

  41. 338

    Lessons From The M&S Breach

    This week, we discuss a phishing technique that uses a powerful and risky Microsoft 365 configuration setting. After that, we round up everything we know about the Marks & Spencer breach from April and the lessons that all MSPs can learn from it. After that, we quickly cover a new series of vulnerabilities in a popular Bluetooth chipset that could let attackers gain full control over your headphones.

  42. 337

    Social Engineering an LLM

    This week on the podcast, we cover a recent blog post from Google's Threat Intelligence Group on a financially motiviated threat actor's latest techniques for stealing data. After that, we dive into the Model Context Protocol (MPC) that organizations have been rapidly adopting to add functionality to their AI deployments and all of the security risks that it introduces.

  43. 336

    AI Applications in Cybersecurity with Adam Winston

    This week on the podcast, recent guest Adam Winston hops back on to continue our discussion on Artificial Intelligence in cybersecurity. This week, we focus on how attackers are using AI, what to worry about and what not to lose sleep over, and guidance for evaluating AI for use within your own organization.

  44. 335

    Signal and TeleMessage

    This week on the podcast, we cover Coinbase's recent filing with the SEC that described an insider threat event that lead to a ransomware extortion. After that, we discuss dive in to Signal and other secure messaging apps, how they protect communications, and how other apps can undermine those protections.

  45. 334

    2025 Ransomware Update with Ryan Estes

    This week on the podcast, we bring on Ryan Estes from the WatchGuard Threat Lab to discuss the latest trends in ransomware operations. Ryan is an expert in ransomware analysis and currently owns the data behind WatchGuard's public Ransomware Tracker on the WatchGuard Security Center.

  46. 333

    AI and Compliance with Adam Winston

    This week on the podcast, we bring in Adam Winston, former CSO of ActZero and current Field CTO for Managed Services at WatchGuard to discuss automating the SOC with AI. We cover the history of AI in SecOps, the good and bad applications of AI and Machine Learning, what the future looks like, and how compliance might impact our ability to get there.

  47. 332

    The CVE Near-Death Experience

    This week on the podcast, we discuss how the CVE program was granted an 11th hour temporary reprieve after the program's steward, MITRE, originally announced their contract had not been renewed. After that, we cover the recent cyberattack against 4chan that took it offline and resulted in leaked moderator information and source code. We end with a quick discussion on a post-exploitation technique being used in the wild against Fortinet FortiGate devices.

  48. 331

    Revoking Security Clearances as Punishment

    This week on the podcast, we discuss a recent White House executive order that revoked the security clearances of former CISA chief Christopher Krebs as well as all other employees at SentinelOne and the implications that brings to our industry. Before that, we give a quick update on the Oracle Cloud breach from a few weeks back that Oracle has finally confirmed. We end with our thoughts on a few Microsoft Windows AI features that just launched in early preview and how they might impact data privacy and security.

  49. 330

    Lucid, the Phishing-as-a-Service Platform

    This week on the podcast, we discuss a recent threat intelligence report on the Chinese Phishing-as-a-Service platform Lucid. Before that, we cover the alleged Oracle Cloud breach before reviewing the Singapore Shared Responsibility Framework, designed to combat financial scams.

  50. 329

    Github Actions Supply Chain Attacks

    This week, we discuss a recent cascading supply chain attack involving multiple Github actions workflows that nearly succeeded in compromising a popular Coinbase application. Before that, we discuss a novel way to download malware onto an endpoint by abusing a web browser's caching feature. Additionally, we cover an FBI alert on file converter malware scams.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cyber security headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into easily understood and actionable insights.

HOSTED BY

Secplicity

CATEGORIES

Frequently Asked Questions

How many episodes does The 443 - Security Simplified have?

The 443 - Security Simplified currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is The 443 - Security Simplified about?

Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cyber security headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into...

How often does The 443 - Security Simplified release new episodes?

The 443 - Security Simplified has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to The 443 - Security Simplified?

You can listen to The 443 - Security Simplified on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts The 443 - Security Simplified?

The 443 - Security Simplified is created and hosted by Secplicity.
URL copied to clipboard!