Security Weekly Podcast Network (Audio)
Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape. Tune in for in-depth panel discussions, expert guest interviews, and breaking news on the latest hacking techniques, vulnerabilities, and industry trends. Stay informed and secure with the most trusted voices in cybersecurity!
Preventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and Kai - Galina Antova, Todd Sorrel, John Hurley - BSW #463
Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn’t end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how?
Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are...
Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612
Victorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-612
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398
AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns...
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474
Interview with Dan Meacham, CISO at Legendary Entertainment
Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CISO at Marsh.
Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out!<...
Mythos Writes the Exploit. Atlas Writes the Response. - Harman Kaur - SWN #611
Most enterprise AI today is a conversation — it summarizes, suggests, recommends. Harman unpacks what changes when AI actually executes across endpoints, and the governance problem that creates. Where does the human stay in the loop, and where do they get out of the way?
This segment is sponsored by Tanium. Visit https://securityweekly.com/tanium to learn more about them!
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-611
Hacking All The Devices, with AI? - Rob Allen - PSW #941
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do.
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
In the security news this week:
Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as...Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462
The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios?
Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not...
Fibonacci, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's, Aaran Leyland - SWN #610
Fibonacci and the Unhappy Number, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's battery, Aaran Leyland, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-610
Applying Zero Trust Principles to Agents - Kieran Human - ASW #397
Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface.
Resources
https://www.threatlocker...Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473
Interview with Rob Allen from Threatlocker
Safely enabling agentic AI for Businesses
OpenClaw was the wakeup call and businesses wanted to know how to block it. “Easy,” Rob Allen said, “it’s already blocked if you’re using Threatlocker.” Now that things have settled down a bit, those same businesses want to allow their employees to experiment with agents. We discuss how they can do it safely.
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
Topic Segment
For this week’s topic segment...
Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able and More - SWN #609
Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able, Robo-Tips, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-609
Rejoice In The Nostalgia - PSW #940
In the security news this week:
Cursor opens your repo, the repo opens you If you want the good model I'm going to need to see your ID Flock's a Flocking mess Defender was supposed to be the chosen one Side stepping Secure boot - twice SonicWall: a LAMP stack in a fancy case Macs don't get viruses, part infinity Flipper One, but why not Nix? NetScaler is back in the room Borrowing phone's good reputation USB and how to make Windows download stuff A KVM with the expensive letters removed Five steps to stop the webcam creeps...Preventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461
Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creates a new challenge for IT and security teams: How do you enable AI to assist productivity without compromising security?
Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss how zero trust principles can prevent an AI breakout. Rather than relying solely on the AI tool's built-in safeguards, organizations can choose to enforce security policies...
Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608
The Secret Word is Meow, Red Agent, GitHub, evoooo1bot, Hatman, DecryptAds, Copilot, Aaran Leyland, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-608
Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396
All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to operators. This type of work is especially useful to orgs that deal with petabytes of data and thousands of systems. And, as Kiran notes, it's important to keep that scale from blowing up your budget or turning triage into a procession of false positives.
Ideally, this kind of threat intel that's paying attention to attack...
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - Joe Hladik - ESW #472
Interview with Jon Hladik - ChatMate
Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user’s chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the capability researchers at Rubrik Zero Labs were able to demonstrate in a recent study designed to test the bounds of LLM security.
Join Joe Hladik, Head of Rubrik Zero Labs, as he breaks down the discovery of "Remote Prompt Execution," a novel vulnerability class that en...
Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More - SWN #607
Famous Mathematician feuds, Delta Flight 591, Lazarus, Akira, Computer History, Zoom, Clones, LiteLLM, Josh Marpet, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-607
The Breached WiFi AI Ports... What? - PSW #939
In the security news this week:
North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale Phishing-resistant MFA Goodbye SMS and voice authentication Cornflake RAT and Chaco Shell The NPM worm Hundreds of compromised packages AI lowers the barrier to mass exploitation Rethinking “secure enough” Back to basics: know what's on your network Get off my PCI lawnVisit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-939
Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Greg Baker, Ihab Shraim, Lynn Dohm - BSW #460
As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company’s IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem?
Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team’s research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security prac...
Squirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606
Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-606
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395
Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task.
And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and...
Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471
Interview 1: Robin Macfarlane from RRMac Associats
The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility
In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why?
We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape.<...
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-605
When AI Commits Felonies - PSW #938
This week:
When you are not at summer camp you can't read about it The Fettle continues Using the CFAA against AI Social contracts are not security models VSCode extentions, again Bugtraq is back! NVIDA, LVFS, and unraveling AI infrastructure More routers that come with backdoors Do we care about LPE? Even more AI that finds vulnerabilities When AI breaks its own guardtailsVisit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-938
Say Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459
This week, we air our thirteenth pre-recorded segment called “Say Easy, Do Hard”. Inspired by my co-host, Jason Albuquerque, we discuss “Performance Through People”. Greg Hoffman joined us a few weeks back to discuss his new book. This week, we dig into his five disciplines of Performance Through People and do the hard part.
Visit https://www.securityweekly.com/bsw for all the latest episodes!
Show Notes: https://securityweekly.com/bsw-459
Randomness, Grey, Deepseek, Sonicwall, Spice, CaptiveCrunch, eBay, and Aaran Leyland - SWN #604
Randomness, 50 Shades of Grey, Deepseek, Sonicwall, Spice Weasels, CaptiveCrunch, eBay, Aaran Leyland, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-604
Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394
There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research into the success, quality, and failures of LLM-generated security patches. Notably, they saw scenarios across a spectrum from robust, effective patches to patches that changed the software's behavior to patches that introduced new vulns to patches that didn't even fix the original vuln while also introducing a new vuln.
<...AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470
Interview with Andrew Dunbar, CISO at Shopify
After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world.
Andrew's Resources:
https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-modelInterview with Kern Smith
Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing...
Rogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603
Rogue AI, the Bar, Breaches, BMC, More Hugging Face, Helmuth von Multke, Ike, Shieldfont, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-603
Sandwich Hats - PSW #937
In the security news:
2.2 million cars, one shared Bluetooth key JFrog tries to spin an AI 0-day into a win Sextortion scammers recycling ShinyHunters' leaks The first hack ever, from 1966 Prompt injection as a service, $150 a month Cisco's mystery "static credential" BMCs still on the internet, still handing out hashes Scattered Spider duo sentenced over the TfL hack Air-gapped data sneaking out over the video cable A ghost in the network DNS poisoning checks into hotel WiFi Microsoft's cut-rate cybersecurity AI Learning to trust USB drives again Agentic pentesting shows up just in time for Black Hat Microsoft...Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458
Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote?
Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type.
Segment 1 Resources:
https://www.PredictableProfits.com
Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat
<...Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet and More - SWN #602
Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet, and More on the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-602
Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393
Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known security threats. Mert Saltimaz talks about the background of the project, how orgs can use it as they bring more LLMs into their environment, and how the project intends to grow. Importantly, we also talk about the security controls and designs that orgs can build around the systems and data that models interact with in...
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469
Segment 1 - Interview with O'Shea Bowens
What do we really know about "AI Network Protocols"? Network security is about to get popular all over again.
Generative AI caused a disruptive explosion across all of tech and every company’s roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other?
Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O’Shea Bowen joins us to answ...
Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland - SWN #601
Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News.
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-601
Fixing Vulns Is Harder Than Finding Them - PSW #936
In the news this week:
InfraTrust and knowing what to patch Adversary in the middle triggered command injection Exploitarium again FreeRDP comes with free vulnerabilities AI breaking out of sandboxes on its own Wordpress RCE DMA dangers Nightmware eclypse is at it again Fortisandbox Turning AI to the dark side more prompt injection Secure boot is broken, still and again...Visit https://www.securityweekly.com/psw for all the latest episodes!
Show Notes: https://securityweekly.com/psw-936
AI's Disruption as Cybersecurity’s Economics Are Broken, Compounding Security Debt - Ben Gilliland - BSW #457
America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American history?
Ben Gilliland, author of the upcoming book Breaking the Compact, joins Business Security Weekly to discuss why business leaders need to be prepared for the upcoming AI disruption. The impact of AI, which has not fully materialized, goes far beyond security and job displacement. It will impact our economy, our privacy, and our way of life. The...
LegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - Kieran Human - SWN #600
Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More.
Segment Resources:
Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
Visit https://www.securityweekly.com/swn for all the latest episodes!
Show Notes: https://securityweekly.com/swn-600
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system.
<...AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468
Interview with Keith Hollender, CEO and Co-Founder of Arcova
Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem
As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.
In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity...