All Episodes
Three Buddy Problem — 193 episodes
AI Doomers, Death Cults, and a Million-Dollar WeChat Worm Exploit
Three Secret AI Civilizations Rose and Fell. Nobody Checked the Logs.
A Thousand Agents Walk Into Hugging Face
Inside the EncroChat law-enforcement implant, Irregular's AI sandbox failure
A tiny 12 KB Windows backdoor, one victim, and a dead domain
Inside OpenAI's Black Hat Confession
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click’ Exploits, and Magnets of Threats
Validin's Kenneth Kinion on What Separates Useful Threat Intel From Noise
OpenAI's models breached Hugging Face, reward hacking ethics, benchmarking fast16
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen
US Gov Takes the Wheel: Who Gets to Use the Best AI?
Katie Moussouris on the Anthropic Export-Control Mess
Mythos, Fable, and Anthropic's Big Trust Problem
Fast16, Fanny, and Stuxnet: Cyber Paleontology Redux
Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited
Aaron Portnoy on Pwn2Own, the End of Easy Bugs, and AI-Fueled Offense
Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code
Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap
Federico Kirschbaum on XBOW, AI Hackers, and the Future of Pen Testing
Jordan Wiens on AI, Offense vs. Defense, and the Dying CTF Pipeline
The AI-powered 10x patch tsunami has arrived. Now what?
The disappointing death of big-game APT reporting
Cracking the Fast16 sabotage malware mystery
Mark Dowd on AI hacking, exploit chains, zero-day sales
The Angry Spark APT Mystery: A Year-Long Backdoor, One Victim, Zero Attribution
The Claude Mythos, Project Glasswing Shockwave
LLMs writing exploits, engineers losing skills, and a case for the generative OS
Jeremy Banon: Personal Exec Compromise as Corporate Incident
Google's Cyber Disruption Unit; Coruna is Triangulation, US Bans Foreign-Made Routers
The greatest APT hunter of all time, Apple's exploit kit problem, Microsoft FedRAMP mess
Handala wiper attacks, APT28 implant devs are back, Signal's verification problems
Trenchant, Peter Williams, and the proliferation of a Shadow Brokers-level iOS exploit framework
Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery
Threat Hunter Greg Linares on the modern ransomware playbook
War in Iran, Anthropic v Pentagon, Trenchant zero-day sanctions, AI stock market shocks
GitLab doxxes North Korea .gov hackers; fresh Ivanti zero-days; AI addiction and human purpose
Palo Alto and the uncomfortable politics of APT attribution
From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks
A destructive cyberattack in Poland raises NATO 'red-line' questions
Cheap, AI-generated zero-days and the real meaning of ‘advanced’ malware
Google Pixel 'zero-click' exploit caused by AI, mysterious Poland grid attacks, China bans US cybersecurity software
Hamid Kashfi on the situation in Iran; Did cyber cause Venezuela blackouts?
A special mailbag episode with book recommendations
Quiet Wins, Loud Failures: A Year-End Cybersecurity Reckoning
What's behind US gov push to 'privatize' offensive cyber operations?
Legal corruption, React2Shell exploitation, dual-use AI risks
APTs pounce on React2Shell; BRICKSTORM backdoors; .gov surveillance
Shai-Hulud 2.0, Russia GRU Intrusions, and Microsoft’s Regulatory Capture
Gemini 3 reactions, Fortinet/Chrome zero-days, a Cloudflare monoculture and a billion-dollar crypto twist
Anthropic Claude Code automating APT hacks, KnownSec leak, Chinese buses with remote access
LIVE from Ring0 COUNTERMEASURE: Google v FFmpeg, Ransomware Turncoats, Samsung 0days
OpenAI’s Dave Aitel talks Aardvark, economics of bug-hunting with LLMs
Apple’s iOS forensics freeze, WhatsApp zero-click, China outs NSA
JAGS LABScon 2025 keynote: Steps to an ecology of cyber
Apple Exploit-Chain Bounties, Wireless Proximity Exploits and Tactical Suitcases
Chris Eng on lessons learned from the NSA, @Stake, Veracode, and 20 years in cybersecurity
Oracle cl0p ransomware crisis, EU drone sightings, Cisco bootkit fallout
Cisco firewall zero-days and bootkits in the wild
Live at LABScon: Aurora Johnson and Trevor Hilligoss on China's 'internet toilets'
Live at LABScon: Visi Stark shares memories of creating the APT1 report
Live at LABScon: Lindsay Freeman on tracking Wagner Group war crimes
Can Apple's New Anti-Exploit Tech Stop iPhone Spyware Attacks?
Salt Typhoon IOCs, Google floats ‘cyber disruption unit’, WhatsApp 0-click
Zero-day reality check: iOS exploits, MAPP in China and the hack-back temptation
On AI’s future, security’s failures, and what comes next...
Live from Black Hat: Brandon Dixon parses the AI security hype
Rethinking APT Attribution: Dakota Cary on Chinese Contractors and Espionage-as-a-Service
Microsoft Sharepoint security crisis: Faulty patches, Toolshell zero-days
Train brake hack, GRU sanctions, Wagner war crimes, Microsoft's Chinese ‘digital escorts’
How did China get Microsoft's zero-day exploits?
Who’s hacking who? Ivanti 0-days in France, China outs 'Night Eagle' APT
Israel-Iran cyberwar: Predatory Sparrow, vanishing crypto, destructive bank hacks
Cyber flashpoints in Israel-Iran war, the 'magnet of threats', Mossad drone swarms
Mikko Hypponen talks drone warfare, APT naming schemes
The dark hole of 'friendlies' and Western APTs
Russia hacks Ukraine war supply lines, Signal blocks Windows screenshots, BadSuccessor vuln disclosure debate
A Coinbase breach with bribes, rogue contractors and a $20M ransom demand
JAGS keynote: The intricacies of wartime cyber threat intelligence
Signalgate redux, OpenAI's Aardvark, normalizing cyber offense
Thomas Rid joins the show: AI consciousness, TP-Link's China connection, trust in hardware security
China doxxes NSA, CVE's funding crisis, Apple's zero-day troubles
NSA director fired, Ivanti's 0day screw-up, backdoor in robot dogs
Signalgate and ID management hiccups, PuzzleMaker and Chrome 0days, Lab Dookhtegan returns
China exposing Taiwan hacks, Paragon spyware and WhatsApp exploits, CISA budget cuts
A half-dozen Microsoft zero-days, Juniper router backdoors, advanced bootkit hunting
Revisiting the Lamberts, i-Soon indictments, VMware zero-days
Lazarus ByBit $1.4B heist was supply chain attack on developer
North Korea's biggest ever crypto heist: $1.4B stolen from Bybit
An 'extremely sophisticated' iPhone hack; Google flags major AMD microcode bug
Unpacking the UK government's secret iCloud backdoor demand
Inside the DeepSeek AI existential crisis, Chinese 'backdoor' in medical devices
Death of the CSRB, zero-days storms at the edge, Juniper router backdoors
Inside the PlugX malware removal operation, CISA takes victory lap and another Fortinet 0day
Hijacking .gov backdoors, Ivanti 0days and a Samsung 0-click vuln
US Treasury hacked via BeyondTrust, MISP and the threat actor naming mess
Palo Alto network edge device backdoor, Cyberhaven browser extension hack, 2024 research highlights
US government's VPN advice, dropping bombs on ransomware gangs
Surveillance economics, Turla and Careto, and the AI screenshots nobody asked for
Inside the Turla Playbook: Hijacking APTs and fourth-party espionage
Volexity’s Steven Adair on Russian Wi-Fi hacks, memory forensics, appliance 0days and network inspectability
Sid Trivedi on the RSA Innovation Sandbox $5 million investment gambit
Russian APT weaponized nearby Wi-Fi networks in DC, new macOS zero-days, DOJ v Chrome
What happens to CISA now? Is deterrence in cyber possible?
Mysterious rebooting iPhones, EDR vendors spying on hackers, Bitcoin 'meatspace' attacks
The Sophos kernel implant, 'hack-back' implications, CIA malware in Venezuela
Fortinet 0days, Appin hack-for-hire exposé, crypto heists, Russians booted from Linux kernel
ESET Israel wiper malware, China's Volt Typhoon response, Kaspersky sanctions and isolation
Typhoons and Blizzards: Cyberespionage and national security on front burner
Careto returns, IDA Pro pricing controversy, crypto's North Korea problem
Exploding beepers, critical CUPS flaws, Windows Recall rebuilt for security
Ep13: The Consolation of Threat Intel (JAG-S LABScon keynote)
Ep12: Security use-cases for AI chain-of-thought reasoning
Ep11: Cyberwarfare takes an ominous turn
Ep10: Volt Typhoon zero-day, Russia's APT29 reusing spyware exploits, Pavel Durov's arrest
Ep9: The blurring lines between nation-state APTs and the ransomware epidemic
Ep8: Microsoft's zero-days and a wormable Windows TCP/IP flaw known to China
Ep7: Crowd2K and the kernel, PKFail supply chain failures, Paris trains sabotage and Russian Olympic attacks
Ep6: After CrowdStrike chaos, should Microsoft kick EDR agents out of Windows kernel?
Ep5: CrowdStrike's faulty update shuts down global networks
Ep4: The AT&T mega-breach, iPhone mercenary spyware, Microsoft zero-days
Ep3: Dave Aitel joins debate on nation-state hacking responsibilities
Ep2: A deep-dive on disrupting and exposing nation-state malware ops
Ep1: The Microsoft Recall debacle, Brad Smith and the CSRB, Apple Private Cloud Compute
Cris Neckar on the early days of securing Chrome, chasing browser exploits
Costin Raiu joins the XZ Utils backdoor investigation
Katie Moussouris on building a different cybersecurity businesses
Costin Raiu: The GReAT exit interview
Danny Adamitis on an 'unkillable' router botnet used by Chinese .gov hackers
Allison Miller talks about CISO life, protecting identities at scale
Rob Ragan on the excitement of AI solving security problems
Seth Spergel on venture capital bets in cybersecurity
Dan Lorenc on fixing the 'crappy' CVE ecosystem
Cisco Talos researcher Nick Biasini on chasing APTs, mercenary hackers
Allison Nixon on disturbing elements in cybercriminal ecosystem
Dakota Cary on China's weaponization of software vulnerabilities
Abhishek Arya on Google's AI cybersecurity experiments
Dr Sergey Bratus on the 'citizen science' of hacking
DARPA's Perri Adams on CTF hacking, new $20M AI Cyber Challenge
Ryan Hurst on tech innovation and unsolved problems in security
Jason Chan on Microsoft's security problems, layoffs and startups
GitHub security chief Mike Hanley on secure coding, AI and SBOMs
Jason Shockey, Chief Information Security Officer, Cenlar FSB
Federico Kirschbaum on a life in the Argentina hacking scene
Kymberlee Price reflects on life at the MSRC, hacker/vendor engagement, bug bounties
OpenSSF GM Omkhar Arasaratnam on open-source software security
Serial entrepreneur Rishi Bhargava on building another cybersecurity company
Claude Mandy on CISO priorities, data security principles
Sidra Ahmed Lefort dishes on VC investments and cyber uncertainties
Paul Roberts on wins and losses in the 'right to repair' battle
Katie Moussouris on where bug bounties went wrong
Robinhood CSO Caleb Sima on a career in the security trenches
Charlie Miller on hacking iPhones, Macbooks, Jeep and Self-Driving Cars
JAG-S on big-game malware hunting and a very mysterious APT
Chainguard's Dan Lorenc gets real on software supply chain problems
Vinnie Liu discusses a life in the offensive security trenches
Down memory lane with Snort and Sourcefire creator Marty Roesch
Subbu Rama, co-founder and CEO, BalkanID
Project Zero's Maddie Stone on the surge in zero-day discoveries
Prof. Mohit Tiwari on the future of securing data at scale
Google's Shane Huntley on zero-days and the nation-state threat landscape
Lamont Orange, CISO, Netskope
Haroon Meer on the business of cybersecurity
Tony Pepper, co-founder and CEO, Egress
Microsoft's Justin Campbell on offensive security research
Costin Raiu on the .gov mobile exploitation business
Amanda Gorton, co-founder and CEO, Corellium
Intel's Venky Venkateswaran on hardware-enabled security
Sounil Yu on SBOMs, software supply chain security
Algirde Pipikaite, Centre for Cybersecurity, World Economic Forum
Josh Schwartz on red-teaming and proactive security engineering
Michael Laventure, threat detection and response, Netflix
Google's Heather Adkins on defenders playing the long game
Collin Greene, head of product security, Facebook
Alex Matrosov on the state of security at the firmware layer
Charles Nwatu, Security Technology & Risk, Netflix
Doug Madory on the mysterious AS8003 global routing story
Crossbeam CISO Chris Castaldo on securing the start-up
Shubs Shah on finding riches (and lessons) from bug bounty hacking
Fahmida Rashid, Executive Editor, VentureBeat
Microsoft's David Weston on the surge in firmware attacks
Lena Smart, CISO, MongoDB
Patrick Howell O'Neill, Cybersecurity Editor, MIT Technology Review
Nico Waisman, Head of Privacy & Security, Lyft
Ron Brash on the water plant hacks and the state of ICS security
Throwback: Zero-day exploit broker Chaouki Bekrar
Selena Larson, Intelligence Analyst, Dragos
Fredrick Lee, Chief Security Officer, Gusto
Zack Whittaker, Security Editor, TechCrunch
Jason Chan, VP, Information Security, Netflix
Matt Honea, Senior Director, Cybersecurity, Guidewire
Andy Greenberg, Senior Writer, Wired
Brooke Pearson, Security Awareness, Uber