PODCAST · technology
Secure By Dezign
by Pax
Secure By Dezign is the AI Security Training Ground — a daily technical podcast for CISOs, security architects, and AI pentesters who refuse to be caught flat-footed by adversarial machine learning.Every episode dissects a real AI attack technique from first principles: the root vulnerability, step-by-step exploitation with working code, historical breaches, and actionable defenses you can deploy today. Topics include prompt injection, RAG poisoning, model inversion, adversarial ML, LLM jailbreaking, indirect prompt injection, agentic AI security, AI supply chain attacks, deepfake-powered BEC, zero-trust for ML infrastructure, and much more.Whether you're briefing a board, hardening a production LLM deployment, or building your own attack lab — Secure By Dezign gives you the technical depth to do it right.New episodes every weekday. No fluff. Just signal.
-
67
Claude Mythos Project Glasswing Ai Safety Capabilities
Episode 67: Claude Mythos Project Glasswing Ai Safety Capabilities
-
66
Xss Cross Site Scripting Persistent Web Vulnerability
Episode 66: Xss Cross Site Scripting Persistent Web Vulnerability
-
65
Pass The Hash Credential Free Lateral Movement Windows
Episode 65: Pass The Hash Credential Free Lateral Movement Windows
-
64
Kubernetes Pod Escape Cloud Takeover
Episode 64: Kubernetes Pod Escape Cloud Takeover
-
63
Supply Chain Attacks Solarwinds Playbook Revisited
Episode 63: Supply Chain Attacks Solarwinds Playbook Revisited
-
62
Securing Hybrid Enterprise Layered Defense Architecture
Episode 62: Securing Hybrid Enterprise Layered Defense Architecture
-
61
Living Off The Land Lotl Attacks Weaponizing Built In Os Tools
Episode 61: Living Off The Land Lotl Attacks Weaponizing Built In Os Tools
-
60
Business Email Compromise Social Engineering Attack Deep Dive
Episode 60: Business Email Compromise Social Engineering Attack Deep Dive
-
59
Ssrf Pivoting Through Your Own Infrastructure
Episode 59: Ssrf Pivoting Through Your Own Infrastructure
-
58
Kerberoasting Extracting Service Account Credentials Active Directory
Episode 58: Kerberoasting Extracting Service Account Credentials Active Directory
-
57
Double Extortion Ransomware Anatomy Kill Chain
Episode 57: Double Extortion Ransomware Anatomy Kill Chain
-
56
Sql Injection 2025 Undying King Web Exploitation
Episode 56: Sql Injection 2025 Undying King Web Exploitation
-
55
Agentic Ai Exploitation Tool Abuse Goal Manipulation
Episode 55: Agentic Ai Exploitation Tool Abuse Goal Manipulation
-
54
Goal Misgeneralization Ai Pursues Wrong Objective
Episode 54: Goal Misgeneralization Ai Pursues Wrong Objective
-
53
Reward Hacking Manipulating Reinforcement Learning Systems
Episode 53: Reward Hacking Manipulating Reinforcement Learning Systems
-
52
Ml Framework Dependency Attacks Pytorch Tensorflow
Episode 52: Ml Framework Dependency Attacks Pytorch Tensorflow
-
51
Pickle File Attacks Weaponizing Ai Model Weights
Episode 51: Pickle File Attacks Weaponizing Ai Model Weights
-
50
Model Watermark Removal Destroying Ip Protection
Episode 50: Model Watermark Removal Destroying Ip Protection
-
49
Adversarial Examples Fooling Ai Imperceptible Perturbations
Episode 49: Adversarial Examples Fooling Ai Imperceptible Perturbations
-
48
Model Extraction Stealing Ai Models Api Queries
Episode 48: Model Extraction Stealing Ai Models Api Queries
-
47
Training Data Memorization Llm Leak Secrets
Episode 47: Training Data Memorization Llm Leak Secrets
-
46
Membership Inference Attacks Proving Data In Training Set
Episode 46: Membership Inference Attacks Proving Data In Training Set
-
45
Gradient Inversion Reconstructing Private Data From Model Updates
Episode 45: Gradient Inversion Reconstructing Private Data From Model Updates
-
44
Model Supply Chain Poisoning Trojan Horse Ai Pipeline
Episode 44: Model Supply Chain Poisoning Trojan Horse Ai Pipeline
-
43
Rag Poisoning Corrupting Knowledge Base Ai Trusts
Episode 43: Rag Poisoning Corrupting Knowledge Base Ai Trusts
-
42
Attacking Ml Api Gateways Behavioral Drift Model Poisoning
Episode 42: Attacking Ml Api Gateways Behavioral Drift Model Poisoning
-
41
Federated Learning Poisoning Weaponizing Collaborative Ai
Episode 41: Federated Learning Poisoning Weaponizing Collaborative Ai
-
40
Backdoor Attacks Trojaned Neural Networks
Episode 40: Backdoor Attacks Trojaned Neural Networks
-
39
Clean Label Poisoning Invisible Training Data Attack
Episode 39: Clean Label Poisoning Invisible Training Data Attack
-
38
Payload Splitting Bypassing Ai Filters
Episode 38: Payload Splitting Bypassing Ai Filters
-
37
Multi-Turn Manipulation: The Slow Burn Attack That Bypasses Every Single-Turn Defense
How attackers weaponize conversational context to make LLMs forget their guardrails across multi-turn interactions — and how to build defenses that persist across the full conversation window.
-
36
Invisible Commands: Visual Prompt Injection Against Multimodal LLMs
When your image is the attack vector, every picture becomes a potential payload. Technical walkthrough of visual prompt injection against multimodal LLMs including GPT-4V and Gemini Vision.
-
35
Building Your Own Vulnerable AI Agent: A Complete LangChain + Ollama Attack Lab
Set up a local LLM agent with dangerous tools, then systematically exploit it with tool injection, privilege escalation, memory hijacking, and DoS. Full hands-on lab walkthrough.
-
34
RAG Poisoning: Weaponizing Vector Databases to Hijack LLM Outputs
Your trusted knowledge base is an injection surface — here's how attackers exploit it. Hands-on lab covering document poisoning, embedding manipulation, and retrieval hijacking.
-
33
Building Your AI Attack Lab: Local LLM Pentesting from Zero to Pwned
Your airgapped playground for prompt injection, jailbreaking, and system prompt extraction. No API keys, no rate limits, no excuses. Complete setup and attack walkthrough with Ollama.
-
32
Token Smuggling: When Your Tokenizer Becomes the Attack Vector
Exploiting the gap between human-readable text and machine tokenization to bypass every filter you've built. Covers homoglyph attacks, whitespace injection, and tokenizer-aware defenses.
-
31
Jailbreaking LLMs: The Art of Breaking AI Safety at Scale
Why your carefully aligned model is one clever prompt away from chaos. Covers DAN variants, many-shot jailbreaking, adversarial suffixes, and the cat-and-mouse dynamics of safety alignment.
-
30
Indirect Prompt Injection: Weaponizing the Web Against Your AI
When your LLM trusts external content, attackers don't need access to your users — they just need a webpage. Technical walkthrough of indirect prompt injection with real-world exploitation chains.
-
29
Budgeting for AI Security: Where CISOs Should Invest in 2026
A strategic allocation framework for securing AI systems while demonstrating ROI to the board — including tooling prioritization, build vs. buy decisions, and budget defense strategies.
-
28
Securing AI Training Data Pipelines: A Practitioner's Guide to Protecting Your Model's Foundation
Your model is only as trustworthy as the data that built it. A practitioner's guide to defending every stage of the ML data pipeline — from ingestion to labeling to preprocessing.
-
27
AI Vendor Risk Management: What CISOs Must Demand Before Signing the Contract
The executive playbook for vetting AI suppliers in an era of opaque models and expanding attack surfaces. What contractual, technical, and audit controls CISOs must demand.
-
26
AI Security Posture Management: Navigating the Emerging Standards Landscape in 2026
A practitioner's guide to implementing AI-SPM frameworks before regulatory mandates force your hand — covering emerging standards, tooling, and continuous posture assessment.
-
25
AI Model Watermarking and IP Protection: Defending Your Neural Networks from Theft
Technical strategies for embedding, detecting, and enforcing ownership claims in production ML systems — including robustness testing against removal attacks.
-
24
AI Governance Frameworks: From Policy to Practice
Building enforceable AI governance that survives first contact with production systems. Covers NIST AI RMF, EU AI Act, ISO 42001, and practical implementation strategies.
-
23
AI Risk Assessment Frameworks for CISOs: Building Board-Ready Governance
From technical threat models to boardroom presentations: a strategic blueprint for enterprise AI governance that earns budget and executive buy-in.
-
22
AI Risk Assessment Frameworks for CISOs: Building Board-Ready Governance in the Age of Machine Learning
A strategic playbook for translating AI security risks into boardroom language and defensible governance frameworks — including FAIR quantification for ML-specific threats.
-
21
Securing AI APIs: Beyond Rate Limiting — A Defense-in-Depth Architecture for the LLM Era
Why your API gateway's rate limiter is just the bouncer, not the security system. Defense-in-depth architecture for the LLM era — from auth to output filtering to abuse detection.
-
20
AI Risk Assessment Frameworks for CISOs: Enterprise Governance Playbook
A strategic playbook for quantifying, communicating, and mitigating AI risk at the enterprise level — with frameworks CISOs can present to any board.
-
19
Model Inversion Attacks: How Adversaries Extract Your Training Data from LLMs
When your AI becomes an unwitting data exfiltration tool. Technical breakdown of model inversion, membership inference, and training data extraction attacks with defensive countermeasures.
-
18
The Silent Siphon: How AI Chatbots Become Enterprise Data Exfiltration Vectors
Your helpful AI assistant might be the most sophisticated insider threat you've ever deployed. A technical walkthrough of how enterprise chatbots become data exfiltration vectors.
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Secure By Dezign is the AI Security Training Ground — a daily technical podcast for CISOs, security architects, and AI pentesters who refuse to be caught flat-footed by adversarial machine learning.Every episode dissects a real AI attack technique from first principles: the root vulnerability, step-by-step exploitation with working code, historical breaches, and actionable defenses you can deploy today. Topics include prompt injection, RAG poisoning, model inversion, adversarial ML, LLM jailbreaking, indirect prompt injection, agentic AI security, AI supply chain attacks, deepfake-powered BEC, zero-trust for ML infrastructure, and much more.Whether you're briefing a board, hardening a production LLM deployment, or building your own attack lab — Secure By Dezign gives you the technical depth to do it right.New episodes every weekday. No fluff. Just signal.
HOSTED BY
Pax
CATEGORIES
Loading similar podcasts...