The Cyber Threat Perspective cover art

All Episodes

The Cyber Threat Perspective — 217 episodes

#
Title
1

Episode 181: AI Zero Days (Google Threat Intelligence Report)

2

Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry

3

Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained

4

Episode 178: Internal Security Controls That Actually Frustrate Attackers

5

Episode 177: Claude Mythos — What It Actually Does, What It Doesn't, and What Your Organization Should Do Now

6

Episode 176: Cybersecurity Advice That Sounds Smart But Fails in Practice

7

Episode 175: NetTools - The Free Active Directory Swiss Army Knife for IT Admins & Pen Testers

8

Episode 174: Web Application Penetration Testing Tools & Techniques with Jordan

9

Episode 173: How to Find Insecure Active Directory Permissions with ADeleg

10

Episode 172: The biggest security blind spots in Midsized companies

11

Episode 171: The future of pentesting with AI

12

Episode 170: The Evasive Adversary

13

Episode 169: Malicious Browser Extensions

14

Episode 168: Do you need a web app pen test?

15

Episode 167: TLS and SSL vulnerabilities - do they matter?

16

Episode 166: Why Your Pentest Didn’t Make You Safer

17

Episode 165: What to expect on your API Pentest

18

Episode 164: Offensive Security in the Age of AI: What Has Changed

19

Episode 163: The Vendor Security Trap: Are You Losing Control?

20

Episode 162: Before the Breach How Attackers Profile Your Organization

21

Episode 161: The Evolution of Pentesting Going Into 2026

22

Episode 160: Should You Alert Your SOC Before a Pentest?

23

Episode 159: How to Break Into Cybersecurity in 2026

24

Episode 158: How to get kicked out of AWS by the FBI

25

Episode 157: AppSec Findings in 2025

26

Episode 156: Post-Exploitation Tactics That Still Work in 2025

27

Episode 155: How We Use AI Offensively

28

Episode 154: Pentesting on a Budget for IT Admins

29

Episode 153: How to Prove Your Security Works Before Attackers Do

30

(replay) Common Pentest Findings That Shouldn't Exist in 2025

31

Episode 152: What is Offensive Security?

32

Episode 151: Tool Time - PingCastle for Defenders

33

Episode 150: How to Use Pentest Findings to Justify Your Next Security Spend

34

Episode 149: Building a Security Stack That Works A Practitioner’s Perspective

35

Episode 148: Securing Windows: Common Misconfigurations That Give Attackers The Advantage

36

Episode 147: When to Accept the Risk

37

Episode 146: What Are the Security Implications of AI?

38

Episode 145: What To Do Minute 1 When Incident Response Arrives

39

Episode 144: How Cyber Threat Actors Are Using AI

40

Episode 143: Stop Wasting Money on Pentests - Do This First

41

Episode 142: How Active Directory Certificates Become Active Threats

42

Episode 141: Are You Making These Windows Security Mistakes

43

Episode 140: Financial Services Cybersecurity Challenges & How to Address Them - Part 2

44

Episode 139: Financial Services Cybersecurity Challenges & How to Address Them - Part 1

45

(Replay) How We Evade Detection During Internal Pentests

46

Episode 138: The 7 Questions Every Security Leader Should Ask After a Pentest

47

Episode 137: Common Pentest Findings That Shouldn’t Exist in 2025

48

Episode 136: A day in the life of an External Penetration Tester

49

(Replay) How To Harden Active Directory To Prevent Cyber Attacks - Webinar

50

Episode 135: We Couldn’t Get In...And That’s a Good Thing, Or Is It?

51

Episode 134: Preventing Data Breaches: Strategies to Mitigate Initial Compromise

52

Episode 133: How Cyber Attackers Steal Credentials & Hijack Sessions

53

Episode 132: Reviewing the Mandiant M-Trends 2025 Report

54

(Replay) How To Defend Against Lateral Movement

55

Episode 131: DMARC & PCI 4.0 Compliance - Is your Organization Compliant?

56

Episode 130: Using Deception Technology to Detect Cyber Attacks

57

Episode 129: How to Analyze Threat Reports for Defenders

58

Episode 128: The Most Common External Pen Test Findings—And How to Fix Them

59

Episode 127: SaaS Supply Chain Attacks - How to Stay Secure

60

Episode 126: Typosquatting - How and Why It Works and How to Defend Against It

61

Episode 125: Whose Job Is Harder? Red or Blue

62

(Replay) How To Monitor Your Attack Surface

63

Episode 124: MFA != Secure

64

Episode 123: Insecure Active Directory Protocols

65

Episode 122: AI/ChatGPT Interviews a Web Pen Tester!!

66

Episode 121: How We Evade Detection During Internal Pentests

67

Episode 120: Demystifying Pentests: What Every Organization Needs to Know

68

Episode 119: Lessons Natural Disasters Can Teach Us About Cybersecurity

69

(Replay) Tales From The Trenches

70

(Replay) Email Spoofing: From Basics to Advanced Techniques and Solutions

71

(Replay) Windows and Active Directory Hardening

72

Episode 118: 2025 - A CISO's Perspective with Mike Whitt

73

Episode 117: Why Do Pentests Cost So Much?

74

Episode 116: Painfully Persistent Problems - Weak Passwords

75

Episode 115: How to understand and address risk w/ Robert McElroy

76

Episode 114: Making Penetration Test Results Actionable

77

Episode 113: Phishing with Malicious RDP Files

78

Episode 112: Key Insights From The Microsoft Digital Defense Report 2024

79

(Replay) How To Actually Protect Credentials

80

Episode 111: Red Team Tools (OST) Managing Open-Source Threats

81

(Replay) Vulnerability Management Deep Dive

82

Episode 110: AD Security Workshop Preview

83

Episode 109: Current State of Pentesting - Internal and External

84

Episode 108: New tales from the trenches!

85

Episode 107: How To Defend Against Lateral Movement

86

(Replay) DNS Security

87

Episode 106: An Overview of Cyber Risk

88

Episode 105: How to Monitor Your Attack Surface

89

Episode 104: How To Get Into Cyber For First Responders

90

Episode 103: Email Spoofing

91

Episode 102: The Global CrowdStrike Outage

92

Episode 101: Infostealers - 10,000 Victims a Day

93

(Replay) How We Hack Medical Devices To Save Lives

94

Episode 100: The OpenSSH RegreSSHion Vulnerability

95

Episode 99: Tool Time - OneDriveEnum & AD Miner

96

Episode 98: Current State of M365 Attacks: Initial Access

97

Episode 97: Current State of M365 Attacks: Enumeration

98

Episode 96: How to Harden Active Directory to Prevent Cyber Attacks

99

Episode 95: Navigating the Legal Maze of Cybersecurity with Alexander Boyd

100

Episode 94: Defending Against Ransomware Part 2

101

Episode 93: Defending Against Ransomware Part 1

102

Episode 92: Cybersecurity Training and Certification Advice

103

Episode 91: The 2024 Verizon Data Breach Investigations Report

104

Episode 90: Transforming Your Security - Insights from Coaching a Collegiate Cyber Defense Team

105

Episode 89: How to Actually Protect Credentials

106

Episode 88: Budgeting for Security: Optimizing Penetration Testing Investments

107

Episode 87: Pentesting Challenges and How to Overcome Them

108

Episode 86: The XZ Backdoor

109

Episode 85: Tool Time - DarkGPT

110

Episode 84: How We Hack Medical Devices to Save Lives

111

Episode 83 - Defense in Depth

112

Ep82 - DFIR For IT & Security Leadership

113

Ep81 - Pentesting Misconceptions

114

Ep 80: Low-Cost, High-Impact Security

115

Episode 79: Bug Bounties

116

Episode 78: Tales from the Trenches

117

Episode 77: DNS Security

118

Episode 76: Windows & Active Directory Hardening

119

Episode 75: Assume Breach - Extracting Maximum Value From Offensive Security Testing

120

Episode 74: Soft Skills and Mental Health For Security Professionals

121

Episode 73: Password Spraying Inside & Out

122

Episode 72: Vulnerability Management Deep Dive

123

Episode 71: A CISO's Perspective on Offensive Security Services

124

Episode 70: Future Trends in Penetration Testing Part 2

125

Episode 69: Future Trends in Penetration Testing Part 1

126

Episode 68: The evolution of penetration testing TTPs

127

Episode 67: A Day In The Life: External Penetration Testing

128

(Replay) HACKERS: How we GET IN and how to STOP US

129

Episode 66: The DevSec Divide: Breaking Down Barriers for Better Security

130

11/2023 Cyber Threat Recap: Okta, Octo Temptest, Smishing

131

Episode 65: Unsecured Credentials and Where To Find Them

132

Episode 64: A Day In The Life: Web Application Penetration Testing

133

Episode 63: A Day in The Life: Internal Penetration Testing

134

Episode 62: What Makes a Great Penetration Test Report?

135

Episode 61: How to Mitigate Social Engineering Attacks

136

Episode 60: Cybersecurity Hot Takes

137

Episode 59: Offensive TTPs and Tooling Trends

138

Episode 58: How To Identify and Mitigate Insecure Windows Services

139

Episode 57: Find and FIX AD CS Vulnerabilities Using Locksmith with Jake and Sam

140

Episode 56: Vulnerabilities & Severity - Explain It To Me Like I'm 5

141

Episode 55: What If Your EDR Doesn't Detect or Respond?

142

Episode 54: Misconfigured and Dangerous Logon Scripts

143

Episode 53: How to Defend and Mitigate PowerShell Attacks

144

Episode 52: How to Prepare for an External Penetration Test

145

Episode 51: Security Automation with PowerShell

146

Episode 50: How Attackers Use PowerShell

147

Episode 49: Scoping Offensive Security Engagements

148

Episode 48: Authentication done right!

149

Episode 47: How to Sharpen your Sword as a Pentester

150

Episode 46: Reducing Active Directory Security Risks from a Hackers Perspective

151

Episode 45: Our Most Common External Pen Test Findings

152

Episode 44: Should penetration testers know how to code?

153

Episode 43: Hacking for Good - Insights and Inspiration with John Hammond

154

Episode 42: OSINT - What You Don't Know Can Hurt You

155

Episode 41: Security Assessment vs Pentest Which is More Impactful and Why

156

Episode 40: How Attackers Target Law Firms and How To Detect & Prevent It

157

Episode 39: Pentesting Certifications Tier List Part 2

158

Episode 38: Pentesting Certifications Tier List Part 1

159

Episode 37: Offensive Security Testing Part 5 - Wireless Pentesting

160

Episode 36: Pentest vs Purple Team vs Red Team

161

Episode 35: Getting Into Pentesting Without an IT Background

162

Episode 34: The State of Web Application Penetration Testing

163

Episode 33: Reflections on Privacy Law and Privacy Issues

164

Episode 32: Our Favorite Pentesting Tools: PingCastle

165

Episode 31: Pentesting War Stories

166

Episode 30: LastPass DataBreach Updates

167

Episode 29: Critical Vulnerabilities You WON’T Find Using Nessus

168

Episode 28: BurpSuite 2023 Roadmap - Huge Improvements!

169

Episode 27: Password Myths Misconceptions and Lies

170

Episode 26: Cloud Security Quick Wins For Defenders

171

Episode 25: What To Do Before You Get A Pentest

172

Episode 24: Active Directory Security Quick Wins For Defenders

173

Episode 23: Offensive Security Testing Part 4 - External Pentesting

174

Episode 22: Yet Another LastPass Breach

175

Episode 21 - SecurIT360 Offensive Security Christmas Special

176

Episode 20 - ChatGPT: The Future of Infosec with AI

177

Episode 19: Staying Frosty Sharp over the Holidays

178

Episode 18: An introduction to Burp Suite

179

Episode 17: Abusing WSUS for Lateral Movement

180

Episode 16: OWASP API Hacking and DevSec with Matt Tesauro

181

Episode 15: Pentesting Certifications - which to get and why

182

Episode 14: Offensive Security Testing Part 3 - Web App Pentesting

183

Episode 13: Offensive Security Testing Part 2 - Mobile Pentesting

184

Episode 12: Law Firm Security Challenges Live at LegalSec22

185

Episode 11: Offensive Security Testing Part 1 - Internal Pentesting

186

Episode 10: Web Application Threats in the Modern Landscape

187

Episode 9: Breaking In Or Branching Out: How To Get A Job In Cybersecurity

188

Episode 8: Hackers: How we get in and how to stop us

189

9-16-22 Week in Review: Uber Hacked, Teams Cleartext Tokens, Intermittent Ransomware Encryption

190

Episode 7: How to Make Threat Actors Cry

191

9-9-22 Week in Review: New EvilProxy Phishing Service and Linux Malware

192

Episode 6: 5 Ways to Get More Value out of your External Penetration Test

193

9-2-22 Week in Review: Okta Phishing, BEC Analysis, LNK Attacks

194

Episode 5: Common High Risk Findings on Internal Penetration Tests & How to Mitigate Them

195

8-26-22 Week in Review: LastPass Breach, Office 365 Abuse, DevSecOps

196

Episode 4: 7 Awesome Ways to Show Off Your Skills as a Pentester

197

8-19-22 Week in Review: Password Snooping, Supply Chain, Cl0p Ransomware

198

Episode 3: It's a Trap! Avoid These 4 Common Pentesting Mistakes

199

8-12-22 Week in Review: BumbleBee Malware & High Profile Phishing Attacks

200

Episode 2: How to Find Passwords on Network Shares Before Attackers Do

201

8-5-22 Week in Review: Evasive Phishing, Tricky Malware and Initial Access Brokers

202

Episode 1: Takeaways from the 2022 Verizon Data Breach Investigations Report

203

July 29th Week in Review: Intergalactic Planetary Phishing, ISOs & LNKs, Ransomware & Extortion

204

July 22nd 2022 CTP Week in Review: RIP Macros, Bad Luck BlackCat, Mr. Eagle

205

July 15th 2022 CTP Week in Review: Macros, Coin Miners, Rustomware, Cookie Phishing

206

July 8th 2022 CTP Week in Review: Office Macros - BRC4 - QNAPWorm - Leaky S3 Buckets - Prevention Over Response

207

July 1st 2022 CTP Week in Review: LNK Malware - LockBit 3.0 Bug Bounty - PwnKit Exploitation In The Wild

208

June 24th 2022 CTP Week In Review: DFSCoerce, Ransomware in OneDrive & PowerShell Forever

209

June 17th 2022 CTP Week In Review: BlackCat - LockBit 2.0 - Saitama DNS Tunneling - Exposed Travis CI Logs

210

June 10th 2022 CTP Week in Review: Dogwalk - Qakbot - Follina - ESXi Ransomware

211

June 3rd 2022 – Cyber Threat Perspective – Week in Review

212

Threat Intel Flash Briefing May 31st 2022 - Follina - CVE-2022-30190

213

May 27th 2022 – Cyber Threat Perspective – Week in Review

214

May 20th, 2022 - Cyber Threat Perspective - Week in Review

215

May 13th, 2022 - Cyber Threat Perspective - Week in Review

216

May 6th, 2022 - Cyber Threat Perspective - Week in Review

217

Threat Intel Flash Briefing - Kerberos Relaying to Local SYSTEM