Secure By Dezign podcast artwork

PODCAST · technology

Secure By Dezign

Secure By Dezign is the AI Security Training Ground — a daily technical podcast for CISOs, security architects, and AI pentesters who refuse to be caught flat-footed by adversarial machine learning.Every episode dissects a real AI attack technique from first principles: the root vulnerability, step-by-step exploitation with working code, historical breaches, and actionable defenses you can deploy today. Topics include prompt injection, RAG poisoning, model inversion, adversarial ML, LLM jailbreaking, indirect prompt injection, agentic AI security, AI supply chain attacks, deepfake-powered BEC, zero-trust for ML infrastructure, and much more.Whether you're briefing a board, hardening a production LLM deployment, or building your own attack lab — Secure By Dezign gives you the technical depth to do it right.New episodes every weekday. No fluff. Just signal.

  1. 67

    Claude Mythos Project Glasswing Ai Safety Capabilities

    Episode 67: Claude Mythos Project Glasswing Ai Safety Capabilities

  2. 66

    Xss Cross Site Scripting Persistent Web Vulnerability

    Episode 66: Xss Cross Site Scripting Persistent Web Vulnerability

  3. 65

    Pass The Hash Credential Free Lateral Movement Windows

    Episode 65: Pass The Hash Credential Free Lateral Movement Windows

  4. 64

    Kubernetes Pod Escape Cloud Takeover

    Episode 64: Kubernetes Pod Escape Cloud Takeover

  5. 63

    Supply Chain Attacks Solarwinds Playbook Revisited

    Episode 63: Supply Chain Attacks Solarwinds Playbook Revisited

  6. 62

    Securing Hybrid Enterprise Layered Defense Architecture

    Episode 62: Securing Hybrid Enterprise Layered Defense Architecture

  7. 61

    Living Off The Land Lotl Attacks Weaponizing Built In Os Tools

    Episode 61: Living Off The Land Lotl Attacks Weaponizing Built In Os Tools

  8. 60

    Business Email Compromise Social Engineering Attack Deep Dive

    Episode 60: Business Email Compromise Social Engineering Attack Deep Dive

  9. 59

    Ssrf Pivoting Through Your Own Infrastructure

    Episode 59: Ssrf Pivoting Through Your Own Infrastructure

  10. 58

    Kerberoasting Extracting Service Account Credentials Active Directory

    Episode 58: Kerberoasting Extracting Service Account Credentials Active Directory

  11. 57

    Double Extortion Ransomware Anatomy Kill Chain

    Episode 57: Double Extortion Ransomware Anatomy Kill Chain

  12. 56

    Sql Injection 2025 Undying King Web Exploitation

    Episode 56: Sql Injection 2025 Undying King Web Exploitation

  13. 55

    Agentic Ai Exploitation Tool Abuse Goal Manipulation

    Episode 55: Agentic Ai Exploitation Tool Abuse Goal Manipulation

  14. 54

    Goal Misgeneralization Ai Pursues Wrong Objective

    Episode 54: Goal Misgeneralization Ai Pursues Wrong Objective

  15. 53

    Reward Hacking Manipulating Reinforcement Learning Systems

    Episode 53: Reward Hacking Manipulating Reinforcement Learning Systems

  16. 52

    Ml Framework Dependency Attacks Pytorch Tensorflow

    Episode 52: Ml Framework Dependency Attacks Pytorch Tensorflow

  17. 51

    Pickle File Attacks Weaponizing Ai Model Weights

    Episode 51: Pickle File Attacks Weaponizing Ai Model Weights

  18. 50

    Model Watermark Removal Destroying Ip Protection

    Episode 50: Model Watermark Removal Destroying Ip Protection

  19. 49

    Adversarial Examples Fooling Ai Imperceptible Perturbations

    Episode 49: Adversarial Examples Fooling Ai Imperceptible Perturbations

  20. 48

    Model Extraction Stealing Ai Models Api Queries

    Episode 48: Model Extraction Stealing Ai Models Api Queries

  21. 47

    Training Data Memorization Llm Leak Secrets

    Episode 47: Training Data Memorization Llm Leak Secrets

  22. 46

    Membership Inference Attacks Proving Data In Training Set

    Episode 46: Membership Inference Attacks Proving Data In Training Set

  23. 45

    Gradient Inversion Reconstructing Private Data From Model Updates

    Episode 45: Gradient Inversion Reconstructing Private Data From Model Updates

  24. 44

    Model Supply Chain Poisoning Trojan Horse Ai Pipeline

    Episode 44: Model Supply Chain Poisoning Trojan Horse Ai Pipeline

  25. 43

    Rag Poisoning Corrupting Knowledge Base Ai Trusts

    Episode 43: Rag Poisoning Corrupting Knowledge Base Ai Trusts

  26. 42

    Attacking Ml Api Gateways Behavioral Drift Model Poisoning

    Episode 42: Attacking Ml Api Gateways Behavioral Drift Model Poisoning

  27. 41

    Federated Learning Poisoning Weaponizing Collaborative Ai

    Episode 41: Federated Learning Poisoning Weaponizing Collaborative Ai

  28. 40

    Backdoor Attacks Trojaned Neural Networks

    Episode 40: Backdoor Attacks Trojaned Neural Networks

  29. 39

    Clean Label Poisoning Invisible Training Data Attack

    Episode 39: Clean Label Poisoning Invisible Training Data Attack

  30. 38

    Payload Splitting Bypassing Ai Filters

    Episode 38: Payload Splitting Bypassing Ai Filters

  31. 37

    Multi-Turn Manipulation: The Slow Burn Attack That Bypasses Every Single-Turn Defense

    How attackers weaponize conversational context to make LLMs forget their guardrails across multi-turn interactions — and how to build defenses that persist across the full conversation window.

  32. 36

    Invisible Commands: Visual Prompt Injection Against Multimodal LLMs

    When your image is the attack vector, every picture becomes a potential payload. Technical walkthrough of visual prompt injection against multimodal LLMs including GPT-4V and Gemini Vision.

  33. 35

    Building Your Own Vulnerable AI Agent: A Complete LangChain + Ollama Attack Lab

    Set up a local LLM agent with dangerous tools, then systematically exploit it with tool injection, privilege escalation, memory hijacking, and DoS. Full hands-on lab walkthrough.

  34. 34

    RAG Poisoning: Weaponizing Vector Databases to Hijack LLM Outputs

    Your trusted knowledge base is an injection surface — here's how attackers exploit it. Hands-on lab covering document poisoning, embedding manipulation, and retrieval hijacking.

  35. 33

    Building Your AI Attack Lab: Local LLM Pentesting from Zero to Pwned

    Your airgapped playground for prompt injection, jailbreaking, and system prompt extraction. No API keys, no rate limits, no excuses. Complete setup and attack walkthrough with Ollama.

  36. 32

    Token Smuggling: When Your Tokenizer Becomes the Attack Vector

    Exploiting the gap between human-readable text and machine tokenization to bypass every filter you've built. Covers homoglyph attacks, whitespace injection, and tokenizer-aware defenses.

  37. 31

    Jailbreaking LLMs: The Art of Breaking AI Safety at Scale

    Why your carefully aligned model is one clever prompt away from chaos. Covers DAN variants, many-shot jailbreaking, adversarial suffixes, and the cat-and-mouse dynamics of safety alignment.

  38. 30

    Indirect Prompt Injection: Weaponizing the Web Against Your AI

    When your LLM trusts external content, attackers don't need access to your users — they just need a webpage. Technical walkthrough of indirect prompt injection with real-world exploitation chains.

  39. 29

    Budgeting for AI Security: Where CISOs Should Invest in 2026

    A strategic allocation framework for securing AI systems while demonstrating ROI to the board — including tooling prioritization, build vs. buy decisions, and budget defense strategies.

  40. 28

    Securing AI Training Data Pipelines: A Practitioner's Guide to Protecting Your Model's Foundation

    Your model is only as trustworthy as the data that built it. A practitioner's guide to defending every stage of the ML data pipeline — from ingestion to labeling to preprocessing.

  41. 27

    AI Vendor Risk Management: What CISOs Must Demand Before Signing the Contract

    The executive playbook for vetting AI suppliers in an era of opaque models and expanding attack surfaces. What contractual, technical, and audit controls CISOs must demand.

  42. 26

    AI Security Posture Management: Navigating the Emerging Standards Landscape in 2026

    A practitioner's guide to implementing AI-SPM frameworks before regulatory mandates force your hand — covering emerging standards, tooling, and continuous posture assessment.

  43. 25

    AI Model Watermarking and IP Protection: Defending Your Neural Networks from Theft

    Technical strategies for embedding, detecting, and enforcing ownership claims in production ML systems — including robustness testing against removal attacks.

  44. 24

    AI Governance Frameworks: From Policy to Practice

    Building enforceable AI governance that survives first contact with production systems. Covers NIST AI RMF, EU AI Act, ISO 42001, and practical implementation strategies.

  45. 23

    AI Risk Assessment Frameworks for CISOs: Building Board-Ready Governance

    From technical threat models to boardroom presentations: a strategic blueprint for enterprise AI governance that earns budget and executive buy-in.

  46. 22

    AI Risk Assessment Frameworks for CISOs: Building Board-Ready Governance in the Age of Machine Learning

    A strategic playbook for translating AI security risks into boardroom language and defensible governance frameworks — including FAIR quantification for ML-specific threats.

  47. 21

    Securing AI APIs: Beyond Rate Limiting — A Defense-in-Depth Architecture for the LLM Era

    Why your API gateway's rate limiter is just the bouncer, not the security system. Defense-in-depth architecture for the LLM era — from auth to output filtering to abuse detection.

  48. 20

    AI Risk Assessment Frameworks for CISOs: Enterprise Governance Playbook

    A strategic playbook for quantifying, communicating, and mitigating AI risk at the enterprise level — with frameworks CISOs can present to any board.

  49. 19

    Model Inversion Attacks: How Adversaries Extract Your Training Data from LLMs

    When your AI becomes an unwitting data exfiltration tool. Technical breakdown of model inversion, membership inference, and training data extraction attacks with defensive countermeasures.

  50. 18

    The Silent Siphon: How AI Chatbots Become Enterprise Data Exfiltration Vectors

    Your helpful AI assistant might be the most sophisticated insider threat you've ever deployed. A technical walkthrough of how enterprise chatbots become data exfiltration vectors.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Secure By Dezign is the AI Security Training Ground — a daily technical podcast for CISOs, security architects, and AI pentesters who refuse to be caught flat-footed by adversarial machine learning.Every episode dissects a real AI attack technique from first principles: the root vulnerability, step-by-step exploitation with working code, historical breaches, and actionable defenses you can deploy today. Topics include prompt injection, RAG poisoning, model inversion, adversarial ML, LLM jailbreaking, indirect prompt injection, agentic AI security, AI supply chain attacks, deepfake-powered BEC, zero-trust for ML infrastructure, and much more.Whether you're briefing a board, hardening a production LLM deployment, or building your own attack lab — Secure By Dezign gives you the technical depth to do it right.New episodes every weekday. No fluff. Just signal.

HOSTED BY

Pax

Produced by Mark Franklin

CATEGORIES

Frequently Asked Questions

How many episodes does Secure By Dezign have?

Secure By Dezign currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Secure By Dezign about?

Secure By Dezign is the AI Security Training Ground — a daily technical podcast for CISOs, security architects, and AI pentesters who refuse to be caught flat-footed by adversarial machine learning.Every episode dissects a real AI attack technique from first principles: the root vulnerability,...

How often does Secure By Dezign release new episodes?

Secure By Dezign has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Secure By Dezign?

You can listen to Secure By Dezign on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Secure By Dezign?

Secure By Dezign is created and hosted by Pax.
URL copied to clipboard!