<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://media.rss.com/style.xsl"?>
<rss xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom" xml:lang="en" version="2.0">
  <channel>
    <title><![CDATA[The Adversarial Podcast]]></title>
    <link>https://adversarial.com/podcast</link>
    <atom:link href="https://media.rss.com/lifeafterciso/feed.xml" rel="self" type="application/rss+xml"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <description><![CDATA[<p>Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the latest cybersecurity news. Each week, we discuss the most pressing headlines, offer candid commentary, and share unique insights from our extensive experience in the field.</p>]]></description>
    <generator>RSS.com 2026.721.95756</generator>
    <lastBuildDate>Wed, 05 Aug 2026 00:14:08 GMT</lastBuildDate>
    <language>en</language>
    <copyright><![CDATA[Adversarial Risk Management]]></copyright>
    <itunes:image href="https://media.rss.com/lifeafterciso/20240701_120752_3f35d45ef30eb4c980b513091b14518e.png"/>
    <podcast:guid>88b91b19-eee0-5d30-a480-bf5eb60b3e54</podcast:guid>
    <image>
      <url>https://media.rss.com/lifeafterciso/20240701_120752_3f35d45ef30eb4c980b513091b14518e.png</url>
      <title>The Adversarial Podcast</title>
      <link>https://adversarial.com/podcast</link>
    </image>
    <podcast:locked>yes</podcast:locked>
    <podcast:license>Adversarial Risk Management</podcast:license>
    <itunes:author>Jerry Perullo, Sounil Yu, Mario Duarte</itunes:author>
    <itunes:owner>
      <itunes:name>Jerry Perullo, Sounil Yu, Mario Duarte</itunes:name>
    </itunes:owner>
    <itunes:explicit>false</itunes:explicit>
    <itunes:type>episodic</itunes:type>
    <itunes:category text="Business"/>
    <itunes:category text="Technology"/>
    <podcast:medium>podcast</podcast:medium>
    <item>
      <title><![CDATA[S4E23 – AI Agents Escape Multiple Frontier Labs]]></title>
      <itunes:title><![CDATA[S4E23 – AI Agents Escape Multiple Frontier Labs]]></itunes:title>
      <description><![CDATA[<p>Chapters</p><p>00:00 Introduction to AI security challenges</p><p>02:05 Recent hacking incidents involving Hugging Face and Anthropic</p><p>04:01 How AI models find ways to cheat and bypass constraints</p><p>05:56 The challenge of containment and governance in AI safety</p><p>08:00 Lessons from recent AI security breaches</p><p>10:01 The role of human oversight in AI security testing</p><p>12:03 Cost and effectiveness of offensive AI security measures</p><p>13:54 Implications for critical infrastructure and national security</p><p>16:03 Policy and regulatory impacts on AI safety</p><p>17:52 Future strategies for AI containment and defense</p><p>20:11 Conclusion and key takeaways</p><p></p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://huggingface.co/blog/agent-intrusion-technical-timeline">HuggingFace: Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident</a></p><p>Hugging Face reconstructs an autonomous intrusion involving approximately 17,600 actions over a multiday campaign.</p><p><a target="_blank" rel="noopener noreferrer" href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic: Investigating three real-world incidents in our cybersecurity evaluations</a></p><p>After reviewing 141,006 cybersecurity-evaluation runs, Anthropic identified three incidents in which Claude reached real organizations through evaluation infrastructure that had been mistakenly connected to the internet. The incidents spanned six runs and three models. Anthropic reached two of the affected organizations, neither of which had detected the activity before being notified. Anthropic did not disclose token usage or inference costs for these intrusions.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses">Anthropic: Discovering cryptographic weaknesses with Claude</a></p><p>Anthropic reports that Claude Mythos Preview progressed from finding implementation flaws in cryptographic libraries to identifying mathematical weaknesses in cryptographic algorithms themselves.</p><p></p><p></p><p>Hosts: Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (CISO, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.whirlai.com/">https://www.whirlai.com/</a>)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/3045508</link>
      <enclosure url="https://content.rss.com/episodes/110710/3045508/lifeafterciso/2026_08_04_15_21_21_9db73ebd-5603-4c2e-8d56-a42cd9f693ea.mp3" length="63367670" type="audio/mpeg"/>
      <guid isPermaLink="false">f903feb6-a6eb-47b7-a487-369c0c43e946</guid>
      <itunes:duration>3960</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>23</itunes:episode>
      <podcast:episode>23</podcast:episode>
      <pubDate>Tue, 04 Aug 2026 05:40:06 GMT</pubDate>
      <podcast:transcript url="https://transcripts.rss.com/110710/3045508/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E22 – HuggingFace compromised by agentic attack, Gold Eagle program]]></title>
      <itunes:title><![CDATA[S4E22 – HuggingFace compromised by agentic attack, Gold Eagle program]]></itunes:title>
      <description><![CDATA[<p>00:00 The Adversarial Podcast</p><p>00:58 Hugging Face’s AI-driven incident disclosure </p><p>03:48 What makes an attack “AI-enabled” </p><p>06:04 Exploits, vulnerabilities, and bespoke code execution paths </p><p>10:03 AI attackers vs. AI defenders</p><p>11:19 Verification asymmetry: attackers vs. defenders</p><p>13:03 Detective controls, red teaming, and breach simulation </p><p>16:41 Why AI defenders matter </p><p>26:25 Gold Eagle / national coordination of vulnerability discovery</p><p> 28:25 The real bottleneck is remediation, not discovery </p><p>37:04 CMMC and the cost of certification </p><p>42:15 Is certification effective, or just paperwork? </p><p>48:09 Threat-based validation as a better model </p><p>51:36 Closing thoughts: the security arms race</p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://huggingface.co/blog/security-incident-july-2026"><em>Hugging Face Agentic Compromise</em></a></p><p>A security incident shows how agentic workflows and delegated access can create new paths for compromise. </p><p><a target="_blank" rel="noopener noreferrer" href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/"><em>Gold Eagle Initiative</em></a> </p><p>The White House launches a new effort to coordinate vulnerability discovery and response across the federal cybersecurity ecosystem. </p><p><a target="_blank" rel="noopener noreferrer" href="https://business.defense.gov/Engage/News/Article/4542563/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/"><em>CMMC Phase 2 Requirements</em></a> </p><p>The Department of War suspends CMMC Phase 2 requirements, reshaping the compliance timeline for defense contractors and the broader federal supply chain. </p><p></p><p>Hosts: Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>) </p><p>Mario Duarte (Founder, stealth startup) </p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/3009452</link>
      <enclosure url="https://content.rss.com/episodes/110710/3009452/lifeafterciso/2026_07_21_14_34_37_c2800132-5ca8-4b9c-8ec8-9be8ba62f3c7.mp3" length="50568506" type="audio/mpeg"/>
      <guid isPermaLink="false">49971178-39ad-4ce0-bcfa-8741a4da4140</guid>
      <itunes:duration>3160</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>22</itunes:episode>
      <podcast:episode>22</podcast:episode>
      <pubDate>Tue, 21 Jul 2026 07:56:59 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:txt purpose="ai-content">false</podcast:txt>
      <podcast:transcript url="https://transcripts.rss.com/110710/3009452/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E21 - Travel Security, AI Defense Matrix, Startup Security]]></title>
      <itunes:title><![CDATA[S4E21 - Travel Security, AI Defense Matrix, Startup Security]]></itunes:title>
      <description><![CDATA[<p>In this episode, Jerry, Mario, and Sounil delve into cybersecurity challenges related to travel, threat models, AI security, and best practices for startups. They explore practical strategies for managing security risks in a rapidly evolving digital landscape, emphasizing the importance of threat modeling, secure coding, and organizational priorities.</p><p></p><p>00:00 Intro</p><p>01:55 Travel Restrictions and Security Concerns</p><p>06:51 Burner Phones and Laptops: A Necessary Evil?</p><p>09:50 Threat Models and Espionage Risks</p><p>14:38 AI and Cybersecurity: New Frontiers</p><p>19:41 Listener Questions and Community Engagement</p><p>22:53 The Evolution of AI Security Frameworks</p><p>26:29 Understanding New Attack Surfaces in AI</p><p>28:56 The Role of Automation in Security</p><p>31:05 Challenges of Non-Technical Users in Security</p><p>33:53 Best Practices for Managing Credentials</p><p>38:16 Building Security from the Ground Up</p><p>41:52 Compliance vs. Security in Startups</p><p>48:02 Understanding Security Constructs</p><p>51:06 Prioritizing Security Controls</p><p>52:48 The Role of SAST in Security</p><p>59:38 AI and Vulnerability Management</p><p>01:02:15 Coordinating Vulnerability Disclosure</p><p></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2956439</link>
      <enclosure url="https://content.rss.com/episodes/110710/2956439/lifeafterciso/2026_07_01_06_41_04_7028ea6e-ca85-4c11-b85d-fd769596522b.mp3" length="63894299" type="audio/mpeg"/>
      <guid isPermaLink="false">cb2fd994-df69-4130-a1aa-f422fd064a4b</guid>
      <itunes:duration>3993</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>21</itunes:episode>
      <podcast:episode>21</podcast:episode>
      <pubDate>Wed, 01 Jul 2026 06:46:13 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:txt purpose="ai-content">false</podcast:txt>
      <podcast:transcript url="https://transcripts.rss.com/110710/2956439/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E20 - AI Executive Order, Project Glasswing Expanding, Cybersecurity Workforce]]></title>
      <itunes:title><![CDATA[S4E20 - AI Executive Order, Project Glasswing Expanding, Cybersecurity Workforce]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"><em>Promoting Advanced Artificial Intelligence Innovation and Security</em></a> </p><p>The White House EO pushes federal agencies toward AI-enabled cyber defense, frontier-model benchmarking, and a voluntary framework for trusted access to high-end AI systems. </p><p><a target="_blank" rel="noopener noreferrer" href="https://www.anthropic.com/news/expanding-project-glasswing"><em>Expanding Project Glasswing</em></a> </p><p>Anthropic is widening Project Glasswing beyond its first cohort, giving more trusted security teams access to Claude Mythos Preview while the industry works through how to scale vulnerability discovery, disclosure, and patching. <em>Securely testing on customer data</em> The crew digs into the practical problem of validating AI and security tools against real customer environments without turning sensitive data into test exhaust, training material, or cross-tenant risk. </p><p><a target="_blank" rel="noopener noreferrer" href="https://apple.news/AAHm4DC77Sj6ohZHGnFk_LA"><em>The cybersecurity workers employers want are in short supply — Axios</em></a> </p><p>Axios frames the cyber labor crunch around specialized, hands-on roles that employers want most, raising the question of whether AI changes the skills gap or just moves it up the stack. </p><p></p><p>Hosts: </p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>) </p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>) </p><p>Mario Duarte (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.whirlai.com/">https://www.whirlai.com/</a>) </p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2899960</link>
      <enclosure url="https://content.rss.com/episodes/110710/2899960/lifeafterciso/2026_06_09_08_22_46_cf190048-8fce-40e5-9377-54aa111c7369.mp3" length="63589607" type="audio/mpeg"/>
      <guid isPermaLink="false">2863cd45-808d-4d46-923d-55a721e359d0</guid>
      <itunes:duration>3974</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>20</itunes:episode>
      <podcast:episode>20</podcast:episode>
      <pubDate>Tue, 09 Jun 2026 08:23:00 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:txt purpose="ai-content">false</podcast:txt>
      <podcast:transcript url="https://transcripts.rss.com/110710/2899960/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E19 – Canvas hacked, Cloudflare layoffs, GitHub CVE rundown]]></title>
      <itunes:title><![CDATA[S4E19 – Canvas hacked, Cloudflare layoffs, GitHub CVE rundown]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer" href="https://www.cnn.com/2026/05/07/us/canvas-hack-strands-college-students-finals-week"><em>Canvas hack strands university students during finals week</em></a>. A Canvas cyberattack hit universities and K-12 schools during finals, locking students and teachers out of grades, assignments, lecture materials, and exams at the worst possible moment.</p><p><a target="_blank" rel="noopener noreferrer" href="https://blog.cloudflare.com/building-for-the-future/"><em>Building for the future.</em></a> Cloudflare says it is cutting more than 1,100 employees as it restructures around internal AI-driven workflows, even as the timing alongside earnings and a sharp stock reaction raises harder questions about the story investors were told.</p><p><a target="_blank" rel="noopener noreferrer" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854"><em>GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog</em></a>. Wiz breaks down a critical GitHub infrastructure flaw where an authenticated user could turn a normal git push into remote code execution on GitHub Enterprise Server, with <a target="_blank" rel="noopener noreferrer nofollow" href="http://GitHub.com">GitHub.com</a> mitigated and GHES customers urged to patch.</p><p><a target="_blank" rel="noopener noreferrer" href="https://almalinux.org/blog/2026-05-07-dirty-frag/"><em>Dirty Frag (CVE-2026-43284, CVE-2026-43500) Patches Released.</em></a> AlmaLinux shipped kernel patches for Dirty Frag, a pair of Linux kernel bugs in IPsec ESP and rxrpc paths that can give local attackers root, with public exploit code already available.</p><p></p><p>Hosts:</p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2816002</link>
      <enclosure url="https://content.rss.com/episodes/110710/2816002/lifeafterciso/2026_05_12_07_33_31_a13b338c-596b-4aa6-ba73-33ffa4d6e621.mp3" length="66437581" type="audio/mpeg"/>
      <guid isPermaLink="false">183c0210-ce1c-49ac-b57e-d6a02493ce1f</guid>
      <itunes:duration>4152</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>19</itunes:episode>
      <podcast:episode>19</podcast:episode>
      <pubDate>Tue, 12 May 2026 07:34:26 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2816002/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E18 – Mythos and TPRM, does SOC 2 really work?]]></title>
      <itunes:title><![CDATA[S4E18 – Mythos and TPRM, does SOC 2 really work?]]></itunes:title>
      <description><![CDATA[<p>00:34 - Introduction</p><p>03:33 - Enterprise Challenges</p><p>07:08 - End User and Browsers</p><p>21:55 - Vulnerability Metrics</p><p>40:37 - Approaching Leadership</p><p>42:09 - TPRM Discussion</p><p>46:40 - Sharing Findings</p><p>01:03:04 - Conclusion</p><p></p><p></p><p><strong>Mozilla: Anthropic’s Mythos found 271 security vulnerabilities in Firefox 150</strong></p><p>Anthropic’s Mythos found 271 zero-day vulnerabilities in Firefox 150 Mozilla let Anthropic’s Mythos loose on Firefox 150’s codebase, harvesting 271 shippable fixes in one sweep and forcing the security team to reckon with AI-scale fuzzing, triage, and patch velocity. <a target="_blank" rel="noopener noreferrer nofollow" href="https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150/">https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150/</a></p><p></p><p>Hosts:</p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2773954</link>
      <enclosure url="https://content.rss.com/episodes/110710/2773954/lifeafterciso/2026_04_28_08_48_01_bb7786b0-a681-406a-842c-e3e9dfbd7cbf.mp3" length="62818890" type="audio/mpeg"/>
      <guid isPermaLink="false">d8421290-d6f0-46d0-89e3-e5a744225140</guid>
      <itunes:duration>3926</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>18</itunes:episode>
      <podcast:episode>18</podcast:episode>
      <pubDate>Tue, 28 Apr 2026 08:48:18 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2773954/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E17 – Mythos, Delve's downfall, and supply chain attacks]]></title>
      <itunes:title><![CDATA[S4E17 – Mythos, Delve's downfall, and supply chain attacks]]></itunes:title>
      <description><![CDATA[<p>Project Glasswing (<a target="_blank" rel="noopener noreferrer nofollow" href="https://www.anthropic.com/glasswing">https://www.anthropic.com/glasswing</a>) Anthropic is letting AWS, Apple, Google, Microsoft, JPMorgan, Cisco, NVIDIA, and friends point Claude Mythos at their shared attack surface while backing it with $100M in credits and $4M for OSS security groups so blue teams can burn down latent vulns before the offense gets equivalent AI. </p><p>Inside the TeamPCP cascading supply chain attack (<a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reversinglabs.com/blog/teampcp-supply-chain-attack-spreads">https://www.reversinglabs.com/blog/teampcp-supply-chain-attack-spreads</a>) Hijacked Trivy GitHub Actions poisoned Docker images, stole CI secrets, and daisy-chained through Checkmarx workflows, npm packages, and VS Code extensions, seeding thousands of tenants with infostealers and proving CI creds are the new crown jewels. </p><p>Delve – Fake Compliance as a Service - Part I (<a target="_blank" rel="noopener noreferrer nofollow" href="https://substack.com/home/post/p-191342187">https://substack.com/home/post/p-191342187</a>) A report says Delve mass-produced fake SOC 2 artifacts and funneled them through shell auditors, leaving customers—from indie apps to a Nasdaq firm—waving fraudulent attestations that crater their legal compliance.</p><p></p><p>Hosts: Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2760210</link>
      <enclosure url="https://content.rss.com/episodes/110710/2760210/lifeafterciso/2026_04_23_07_05_27_2d898c9a-e357-4c01-8cdd-8004a59c2dbd.mp3" length="66208957" type="audio/mpeg"/>
      <guid isPermaLink="false">73c74712-c355-4318-a3ed-9086d944e130</guid>
      <itunes:duration>4138</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>17</itunes:episode>
      <podcast:episode>17</podcast:episode>
      <pubDate>Thu, 23 Apr 2026 07:05:45 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:txt purpose="ai-content">false</podcast:txt>
      <podcast:transcript url="https://transcripts.rss.com/110710/2760210/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Special RSAC episode with Cloudflare - Cybersecurity and AI, CISO/Board dynamics, future of cybersecurity]]></title>
      <itunes:title><![CDATA[Special RSAC episode with Cloudflare - Cybersecurity and AI, CISO/Board dynamics, future of cybersecurity]]></itunes:title>
      <description><![CDATA[<p>The Adversarial Podcast brings you a special episode in collaboration with Cloudflare's Security Signal Podcast.</p><p></p><p>0:39 - 3:33 AI Governance and Autonomy </p><p>6:26 - 8:49 Human in the Loop </p><p>9:17 - 11:40 Cybersecurity and AI </p><p>15:26 - 18:19 Resilience and Anti-Fragility </p><p>28:24 - 33:05 Threat Intelligence </p><p>33:31 - 36:50 Board and CISO Dynamics </p><p>41:09 - 42:35 Future of Cybersecurity </p><p>42:35 - 44:14 Books and Resources</p><p></p><p>Security Signal Podcast: <a target="_blank" rel="noopener noreferrer nofollow" href="https://podcasts.apple.com/us/podcast/security-signal/id1815513800">https://podcasts.apple.com/us/podcast/security-signal/id1815513800</a></p><p>Cloudflare; <a target="_blank" rel="noopener noreferrer nofollow" href="http://cloudflare.com/">http://cloudflare.com/</a></p><p></p><p>Hosts:</p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2733721</link>
      <enclosure url="https://content.rss.com/episodes/110710/2733721/lifeafterciso/2026_04_14_07_10_57_6868bbe4-408d-4a85-b73e-fbbde3ec4cbc.mp3" length="42849636" type="audio/mpeg"/>
      <guid isPermaLink="false">8f3624b5-b33e-4d2d-9ce8-11e3197e7576</guid>
      <itunes:duration>2678</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>16</itunes:episode>
      <podcast:episode>16</podcast:episode>
      <pubDate>Tue, 14 Apr 2026 07:14:16 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:txt purpose="ai-content">false</podcast:txt>
      <podcast:transcript url="https://transcripts.rss.com/110710/2733721/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E15 – RSAC, Iranian hackers, White House's Cyber Strategy and Cyber EOs, the Future of TPRM]]></title>
      <itunes:title><![CDATA[S4E15 – RSAC, Iranian hackers, White House's Cyber Strategy and Cyber EOs, the Future of TPRM]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer" href="https://www.reuters.com/technology/stryker-shares-fall-after-report-suspected-iran-linked-cyberattack-2026-03-11/"><em>Iran-linked hackers claim responsibility for attack on US medical device maker Stryker</em></a></p><p>Attackers tied to Iran say they hit Stryker, and investors punished the stock as the company scrambled to assess exposure.</p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://www.wsj.com/articles/trump-signs-executive-order-aimed-at-cybercrime-gangs-8267b630?mod=pro-cybersecurity_trendingnow_article_pos2&amp;tpl=cs"><em>Trump Signs Executive Order Aimed at Cybercrime Gangs</em></a></p><p>The President issued an order to tide together federal tools, international partners, and private-sector incentives for hunting down and disrupting ransomware crews.</p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf"><em>President Trump’s Cyber Strategy for America</em></a></p><p>The new national cyber strategy leans hard on resilience, collaboration with allies, and deterring Beijing through offensive-ready posture.</p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://www.linkedin.com/posts/activity-7436039954608136192-QpIt"><em>The future of third-party risk is NOT better questionnaires</em></a></p><p>The author argues that automation and better data sharing—not more paperwork—are what finally move the needle on vendor risk management.</p><p></p><p>Hosts:</p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2635496</link>
      <enclosure url="https://content.rss.com/episodes/110710/2635496/lifeafterciso/2026_03_17_06_33_43_912d707f-0aab-4e1b-b3c0-10d5de70f53f.mp3" length="67087925" type="audio/mpeg"/>
      <guid isPermaLink="false">504556b5-4d16-4104-8ffa-cc440f636531</guid>
      <itunes:duration>4192</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>15</itunes:episode>
      <podcast:episode>15</podcast:episode>
      <pubDate>Tue, 17 Mar 2026 06:48:59 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2635496/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E14 – Federal Gov vs. Anthropic, 40% layoff at Blocks due to AI]]></title>
      <itunes:title><![CDATA[S4E14 – Federal Gov vs. Anthropic, 40% layoff at Blocks due to AI]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer" href="https://www.anthropic.com/news/claude-code-security"><em>Claude Code Security research preview</em></a> Claude now reasons about code like a human researcher, re-checks its own findings for confidence, and surfaces patch suggestions in a dashboard while keeping humans in control—limited preview for Enterprise/Team customers plus expedited access for open-source maintainers. </p><p><a target="_blank" rel="noopener noreferrer" href="https://www.cbsnews.com/news/pentagon-anthropic-offer-ai-unrestricted-military-use-sources/"><em>Pentagon gives Anthropic a best-and-final offer</em></a> With a deadline looming, the Pentagon demanded full lawful-use access, threatening supply-chain risk and even a Defense Production Act push, but Anthropic stood firm on guardrails around mass surveillance and autonomous weapons. </p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://www.straitstimes.com/world/united-states/state-department-switches-to-openai-as-us-agencies-start-phasing-out-anthropic"><em>State Department and other agencies ditch Anthropic for OpenAI</em></a> State, Treasury, HHS, and others are dropping Claude after Trump’s directive to cancel Anthropic contracts, swapping in OpenAI’s GPT-4.1 for tools like StateChat as the broader federal boycott takes shape. </p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/"><em>New AirSnitch attack bypasses Wi-Fi encryption</em></a> AirSnitch leverages cross-layer identity desync to nullify client isolation on routers from Netgear to Cisco, giving nearby attackers full MitM access to intercept and tamper with otherwise encrypted traffic. </p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://reading.sh/your-password-managers-zero-knowledge-promise-is-broken-f4a4c581c4ab"><em>Your password manager’s “zero knowledge” promise is broken</em></a> ETH Zürich’s USENIX paper proves that malicious servers controlling Bitwarden/Dashlane/LastPass infrastructure can hijack everyday vault interactions and read users’ encrypted data despite the “zero knowledge” pitch. </p><p></p><p><a target="_blank" rel="noopener noreferrer" href="https://www.itnews.com.au/news/researchers-find-critical-vulnerabilities-in-cloud-based-password-managers-623661"><em>Researchers find critical vulnerabilities in cloud-based password managers</em></a> The ETH team demonstrated a dozen attacks on Bitwarden, seven on LastPass, six on Dashlane, and even a 1Password flaw, showing compromised servers—without exotic hardware—can view or rewrite entire vaults. </p><p></p><p>Hosts: </p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>) </p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>) </p><p>Mario Duarte (Founder, stealth startup) </p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2596344</link>
      <enclosure url="https://content.rss.com/episodes/110710/2596344/lifeafterciso/2026_03_03_07_08_02_1913a170-47c3-4ba1-a1e5-498a3bb36dde.mp3" length="59515758" type="audio/mpeg"/>
      <guid isPermaLink="false">ab64d1ae-ea07-498c-8de2-0f3a0f2c4a77</guid>
      <itunes:duration>3719</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>14</itunes:episode>
      <podcast:episode>14</podcast:episode>
      <pubDate>Tue, 03 Mar 2026 07:08:48 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2596344/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[S4E13 – Munich Security Conference, hiring AI specialists, Gemini used by criminals]]></title>
      <itunes:title><![CDATA[S4E13 – Munich Security Conference, hiring AI specialists, Gemini used by criminals]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer" class="c-link" href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use"><strong>GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</strong></a> Google’s threat team distills red-team learnings from sophisticated experimentation as it hardens defenses and anticipates adversarial AI backdoors.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="http://backdoors.New"><strong>New</strong></a><a target="_blank" rel="noopener noreferrer" class="c-link" href="https://news.bloomberglaw.com/privacy-and-data-security/new-trump-cyber-strategy-prompts-companies-to-mull-legal-limits"><strong> Trump Cyber Strategy Prompts Companies to Mull Legal Limits</strong></a> The administration’s aggressive cyber doctrine is forcing firms to reconsider how far they can legally follow the offensive playbook.</p><p><a target="_blank" rel="noopener noreferrer" class="c-link" href="https://www.cfr.org/articles/the-trump-administrations-cyber-strategy-fundamentally-misunderstands-chinas-threat"><strong>The Trump Administration’s Cyber Strategy Fundamentally Misunderstands China’s Threat | Council on Foreign Relations</strong></a> CFR analysis warns that the new strategy oversimplifies China’s capabilities and risks misaligning priorities.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cybersecuritydive.com/news/cisa-cybersecurity-division-reorganization/812155/"><strong>CISA will shutter some missions to prioritize others.</strong></a> CISA’s Cybersecurity Division is reorganizing to better match a layered threat-response posture.</p><p><a target="_blank" rel="noopener noreferrer" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network"><strong>Google TIG disrupts “world’s largest residential proxy network”</strong></a><strong> </strong>The threat-intel team dismantled a sprawling residential proxy operation that was selling access to anonymized traffic, curbing a major enabler of fraud and abuse.</p><p></p><p>Hosts: Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>) </p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>) </p><p>Mario Duarte (Founder, stealth startup) </p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2557545</link>
      <enclosure url="https://content.rss.com/episodes/110710/2557545/lifeafterciso/2026_02_18_07_30_14_ac67c134-5d4e-409d-aa37-b0b7a68fa9dd.mp3" length="70015729" type="audio/mpeg"/>
      <guid isPermaLink="false">83f7c348-6c43-4133-82c4-1240f30bbb1c</guid>
      <itunes:duration>4375</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <pubDate>Wed, 18 Feb 2026 07:37:19 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2557545/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E12 – Curl shuts down bug bounty program, most expensive security control that gave zero security]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E12 – Curl shuts down bug bounty program, most expensive security control that gave zero security]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer nofollow" href="https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/"><strong>The end of the curl bug bounty program. </strong></a>Curl’s creator Daniel Stenberg announced the shutdown of the project’s bug-bounty program because overwhelming volumes of low-quality and AI-generated reports, coupled with bad-faith security submissions, impose excessive mental and time costs while providing little real improvement to the software.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.federalreserve.gov/newsevents/pressreleases/files/bcreg20251118a1.pdf"><strong>Changing Federal Reserve Regulations. </strong></a>The memo directs Federal Reserve supervisory staff to shift toward a more risk-focused, judgment-driven, and proportionate supervisory model that prioritizes material financial risks, relies more on other regulators’ and firms’ internal audit work, reduces procedural and duplicative oversight, and sharpens the clarity and impact of supervisory findings and enforcement.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reddit.com/r/cybersecurity/comments/1qcbufo/whats_the_most_expensive_security_control_youve"><strong>Reddit: "What is the most expensive security control you added that gave zero security."</strong></a><strong> </strong>An online discussion thread about security controls.</p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2523620</link>
      <enclosure url="https://content.rss.com/episodes/110710/2523620/lifeafterciso/2026_02_05_09_58_01_3c8a2fbb-5ab9-486d-b57e-5101d1bbf3c8.mp3" length="74975233" type="audio/mpeg"/>
      <guid isPermaLink="false">40a7b812-a02f-4a83-96a3-9e1c6235dfb7</guid>
      <itunes:duration>4685</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <pubDate>Thu, 05 Feb 2026 09:58:47 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2523620/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E11 – Iran Internet blackout, threat intelligence briefings, cyber framework alignment]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E11 – Iran Internet blackout, threat intelligence briefings, cyber framework alignment]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro </p><p>01:40 Iran's Internet blackout </p><p>48:06 U.S. Weighs Expanding Private Companies’ Role in Cyberwarfare </p><p>57:35 Aligning cybersecurity programs to frameworks</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.npr.org/2026/01/15/nx-s1-5678567/iran-internet-blackout-starlink"><strong>There's an internet blackout in Iran. How are videos and images getting out? </strong></a>During Iran’s nationwide internet blackout imposed amid widespread anti-government protests, some citizens have been using Elon Musk’s Starlink satellite service to bypass state-controlled communication blackouts and share information with the outside world despite government efforts to restrict or jam such access.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/articles/lawmakers-to-restart-efforts-to-revive-lapsed-cyber-intel-bill-4153a2ac"><strong>Lawmakers to Restart Efforts to Revive Lapsed Cyber Intel Bill.</strong></a><strong> </strong>U.S. lawmakers are preparing to revive and reauthorize the lapsed Cybersecurity Information Sharing Act, a key bill that facilitates sharing of cyber threat intelligence between the federal government and the private sector, with bipartisan momentum to include it in broader funding legislation as concerns grow about rising cyber threats and gaps left by the law’s expiration.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.nytimes.com/2026/01/14/us/politics/us-cyberwarfare-private-companies.html"><strong>U.S. Weighs Expanding Private Companies’ Role in Cyberwarfare. </strong></a>The U.S. administration is considering a significant shift in cyber strategy that would allow private companies, beyond their current contractor roles, to directly participate in offensive cyber operations against foreign adversaries—a move that would require new legal authorities and raises legal, ethical and oversight concerns.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/vulnerabilities-threats/should-our-security-controls-be-more-like-north-korea-or-norway-"><strong>Should Our Security Controls Be More Like North Korea or Norway?</strong></a><strong> </strong>Security programs work better when they resemble Norway’s balanced, trust-based model rather than North Korea’s heavy-handed, surveillance-first approach.</p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2471673</link>
      <enclosure url="https://content.rss.com/episodes/110710/2471673/lifeafterciso/2026_01_20_07_59_22_59399523-10d6-4374-8657-0a00d2383ae5.mp3" length="72354629" type="audio/mpeg"/>
      <guid isPermaLink="false">dd31e735-0b41-4200-b51a-680cb009e741</guid>
      <itunes:duration>4522</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <pubDate>Tue, 20 Jan 2026 07:22:59 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2471673/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E10 – AI impact on cyber jobs, SOC 2 fraud, CISA polygraph failure]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E10 – AI impact on cyber jobs, SOC 2 fraud, CISA polygraph failure]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/articles/cloudy-outlook-for-cyber-jobs-as-ai-fills-security-gaps-2128b2cf"><strong>Cloudy Outlook for Cyber Jobs as AI Fills Security Gaps.</strong></a><strong> </strong>Cybersecurity hiring growth slowed to 7% in 2025 amid flat budgets and economic uncertainty, with firms shifting spend toward AI automation over expanding teams.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.prnewswire.com/news-releases/coupang-inc-cpng-class-period-expanded-in-pending-investor-securities-lawsuit---hagens-berman-302656622.html"><strong>Coupang, Inc. (CPNG) Class Period Expanded in Pending Investor Securities Lawsuit - Hagens Berman</strong></a><strong>. </strong>Hagens Berman expanded a securities class action against Coupang over alleged cybersecurity misstatements after massive data breach disclosures and losses.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bleepingcomputer.com/news/security/jaguar-land-rover-wholesale-volumes-down-43-percent-after-cyberattack/?mod=djemCybersecruityPro&amp;tpl=cs"><strong>Jaguar Land Rover wholesale volumes down 43% after cyberattack.</strong></a><strong> </strong>Jaguar Land Rover’s September 2025 cyberattack cut Q3 wholesale volumes 43%, disrupted production, cost £196 million, and triggered UK government intervention.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/articles/security-chiefs-plan-new-uses-for-ai-in-2026-04978acf?mod=djemCybersecruityPro&amp;tpl=cs"><strong>Security Chiefs Plan New Uses for AI in 2026. </strong></a>Security leaders say AI sharply improved their defenses in 2025 and they plan to expand its use in 2026 for tasks like spotting vulnerabilities and automating identity checks.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.politico.com/news/2025/12/21/cisa-acting-director-madhu-gottumukkala-polygraph-investigation-00701996"><strong>Acting CISA director failed a polygraph. Career staff are now under investigation. </strong></a>CISA’s acting director failed a polygraph, triggering a DHS investigation and suspension of multiple career staff accused of misleading leadership.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/posts/troyjfine_details-have-emerged-regarding-a-widespread-activity-7415043499676483584-nI5Z"><strong>Possible instances of SOC 2 Fraud. </strong></a>A whistleblower exposed an alleged SOC 2 fraud scheme where automation platforms and audit firms rubber-stamped fake compliance reports at scale.</p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2459832</link>
      <enclosure url="https://content.rss.com/episodes/110710/2459832/lifeafterciso/2026_01_14_15_20_09_253cdccf-abc0-4f61-9de3-99a1926cb46b.mp3" length="64204425" type="audio/mpeg"/>
      <guid isPermaLink="false">5d9ee5bd-e00f-41a7-9ea6-168465ffeb39</guid>
      <itunes:duration>4012</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <pubDate>Wed, 14 Jan 2026 09:14:58 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2459832/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E09 – New Pentagon CIO, age verification in Australia, Microsoft overhauls bug bounty program]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E09 – New Pentagon CIO, age verification in Australia, Microsoft overhauls bug bounty program]]></itunes:title>
      <description><![CDATA[<p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/world/us/trump-administration-turning-private-firms-cyber-offensive-2025"><strong>Nation Cyber Strategy Forthcoming</strong></a> The Trump administration is preparing a new national cyber strategy that increasingly relies on private companies to conduct offensive cyber operations on behalf of the U.S. government. </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://defensescoop.com/2025/12/18/kirsten-davies-dod-cio-dow-confirmed-senate/"><strong>Kirsten Davies Confirmed as Pentagon CIO</strong></a> The U.S. Senate confirmed Kirsten Davies as the Department of Defense’s Chief Information Officer, placing her in charge of modernizing and securing the Pentagon’s vast IT infrastructure. </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.tomshardware.com/tech-industry/cyber-security/north-korean-infiltrator-caught-working-in-amazon-it-department-thanks-to-lag-110ms-keystroke-input-raises-red-flags-over-true-location"><strong>North Korean IT Worker Caught Inside Amazon</strong></a> A North Korean operative was discovered working remotely in Amazon’s IT department after analysts flagged suspicious keystroke latency suggesting the employee was operating from overseas. </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bbc.com/news/articles/cwyp9d3ddqyo"><strong>Australia Bans Social Media for Children Under 16</strong></a> Australia passed a landmark law banning children under 16 from social media platforms, reigniting global debate over age verification, surveillance, and online privacy. </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://therecord.media/venezuela-state-oil-company-blames-cyberattack-on-us"><strong>Venezuela Blames Cyberattack on the U.S. After Tanker Seizure</strong> </a>Venezuela’s state oil company accused the United States of launching a cyberattack following tanker seizures, with disruptions severe enough that the company’s main website remains offline. </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.microsoft.com/en-us/msrc/blog/2025/12/in-scope-by-default"><strong>Microsoft Overhauls Bug Bounty Program</strong> </a>Microsoft revamped its bug bounty program to make all vulnerabilities “in scope by default,” addressing long-standing complaints from security researchers about unclear reward boundaries. </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/tech/ai/this-buzzy-cyber-startup-wants-to-take-on-dangerous-ai-threat-c0916a3a"><strong>Kevin Mandia Launches Armadin</strong> </a>Former Mandiant CEO Kevin Mandia unveiled Armadin, a startup offering AI-powered red-teaming services designed to stress-test AI systems against emerging threats. </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://arstechnica.com/security/2025/12/microsoft-will-finally-kill-obsolete-cipher-that-has-wreaked-decades-of-havoc/"><strong>Microsoft Finally Kills a Long-Broken Cipher.</strong></a> Microsoft announced it will disable an obsolete cryptographic cipher that has been exploited for decades, closing a long-standing security hole across Windows systems. </p><p></p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2409968</link>
      <enclosure url="https://content.rss.com/episodes/110710/2409968/lifeafterciso/2025_12_24_06_50_41_def7c849-ebc1-45ac-972c-8fac96fec972.mp3" length="66822939" type="audio/mpeg"/>
      <guid isPermaLink="false">c24b9023-28a3-48d3-a889-f6066449417b</guid>
      <itunes:duration>4176</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <pubDate>Wed, 24 Dec 2025 06:55:09 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2409968/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E08 – Shai-Hulud worm strikes again, critical React vuln, CrowdStrike insider threat]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E08 – Shai-Hulud worm strikes again, critical React vuln, CrowdStrike insider threat]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>02:33 Shai Hulud 2.0</p><p>17:12 Max severity React vulnerability</p><p>29:23 CrowdStrike catches insider feeding information to hackers</p><p>46:24 Anthropic disruptes AI-orchestrated cyber campaign</p><p>52:35 Uncertain economy takes effect on cyber teams</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack"><strong>Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact</strong></a></p><p>Researchers report that Shai-Hulud 2.0 is an ongoing npm supply-chain worm that has compromised hundreds of packages and tens of thousands of GitHub repositories and siphoned secrets through CI/CD pipelines.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.trendmicro.com/en_us/research/25/l/critical-react-server-components-vulnerability.html"><strong>Critical React Server Components Vulnerability CVE-2025-55182</strong></a></p><p>React vulnerability React Server Components (RSC) — tracked as CVE-2025-55182 — is a critical (CVSS 10.0) flaw that allows unauthenticated attackers to execute arbitrary code on servers just by sending a crafted HTTP request to vulnerable packages.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bleepingcomputer.com/news/security/crowdstrike-catches-insider-feeding-information-to-hackers/"><strong>CrowdStrike catches insider feeding information to hackers</strong></a></p><p>CrowdStrike caught an insider who had secretly shared screenshots of internal systems with hackers linked to Scattered Lapsus$ Hunters — though the company says no breach of its infrastructure occurred and no customer data was compromised.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://business.comcast.com/enterprise/resources/reports/2025-comcast-business-cybersecurity-threat-report"><strong>Comcast's 2025 Cybersecurity Threat Report</strong></a></p><p>Comcast Business’s 2025 Cybersecurity Threat Report finds that over the 12-month period ending May 31, 2025 the company recorded <strong>34.6 billion cyber events</strong> — including 4.7 billion phishing attempts, 9.7 billion “drive-by” compromise attacks, 44,000 DDoS attacks, and 19.5 billion resource-development activities.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.anthropic.com/news/disrupting-AI-espionage"><strong>Disrupting the first reported AI-orchestrated cyber espionage campaign</strong></a></p><p>Anthropic reports disrupting what it assesses to be the first large-scale, AI-orchestrated cyber espionage campaign, in which a Chinese state-linked group jailbroke Claude Code to autonomously conduct reconnaissance, exploit vulnerabilities, and exfiltrate data across dozens of global targets with minimal human involvement.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/articles/uncertain-economy-takes-toll-on-cybersecurity-teams-9e26d00f"><strong>Uncertain Economy Takes Toll on Cybersecurity Teams</strong></a></p><p>Economic uncertainty has hit corporate cyber operations: Artico Search and IANS Research report that cybersecurity budgets rose just 4% in 2025 (a five-year low), hiring growth slowed to 7% (down from 12% in 2024), and many security-teams are grappling with tighter budgets, fewer hires, and slower wage growth.</p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2380214</link>
      <enclosure url="https://content.rss.com/episodes/110710/2380214/lifeafterciso/2025_12_09_23_47_53_76f79b02-9a01-4602-8576-b83a45c223b9.mp3" length="59432713" type="audio/mpeg"/>
      <guid isPermaLink="false">b61142e5-3b1a-4a47-a982-7e96ef51934d</guid>
      <itunes:duration>3714</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <pubDate>Tue, 09 Dec 2025 23:48:22 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2380214/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E07 – The password is "Louvre", AI ransomware, Nevada stands up to ransomware]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E07 – The password is "Louvre", AI ransomware, Nevada stands up to ransomware]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>01:50 Louvre password</p><p>08:54 Trump budget cuts</p><p>20:35 Google AI threat report</p><p>36:56 Nevada didn’t pay ransom</p><p>48:25 Moved the needle</p><p>58:38 L3Harris Trenchant boss stole exploits, sold to Russia</p><p>62:00 Ransomware remediation firm employees go rogue</p><p>63:40 Cybersecurity Is A Digital Identity Problem And We Must Deal With It</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://cybernews.com/news/louvre-password-heist/"><strong>The password for the Louvre’s video surveillance system was “Louvre”</strong></a></p><p>The Louvre Museum reportedly had a video-surveillance server password of simply <strong>“LOUVRE”</strong> as early as 2014..</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cnbc.com/2025/11/07/trump-government-budget-cuts-cybersecurity-hacking-risks.html"><strong>Trump budget cuts, agency gutting, leave Americans and economy at greater risk of being hacked, experts warn</strong></a></p><p>Budget cuts under Donald Trump’s administration are slashing funding and staff at key federal cybersecurity agencies like CISA, increasing the risk of U.S. vulnerability to cyberattacks.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools"><strong>GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog</strong></a></p><p>Adversaries are now deploying AI-enabled malware (such as self-modifying code) and exploiting underground AI tool markets across the full attack lifecycle.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://thenevadaindependent.com/article/report-nevada-didnt-pay-ransom-in-statewide-cyberattack-spent-1-5m-on-response"><strong>Nevada didn’t pay ransom in statewide cyberattack, spent $1.5M on response</strong></a></p><p>The State of Nevada did not pay the ransom after a statewide cyberattack, opting instead to spend approximately $1.5 million on response efforts.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://techcrunch.com/2025/11/03/how-an-ex-l3-harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia/"><strong>How an ex-L3Harris boss stole and sold cyber exploits to Russia</strong></a></p><p>A former L3Harris division boss admitted to stealing eight zero-day exploits from network and selling them to a Russian cyber-tool broker.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://chicago.suntimes.com/the-watchdogs/2025/11/02/crytpo-cryptocurrency-crime-chicago-digital-mint-ransom-ransomware-hack"><strong>Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says</strong></a></p><p>A Chicago-based ransomware response firm is under indictment after employees allegedly conducted five ransomware attacks of their own.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.forbes.com/sites/davidbirch/2025/11/04/cybersecurity-is-a-digital-identity-problem-and-we-must-deal-with-it"><strong>Cybersecurity Is A Digital Identity Problem And We Must Deal With It</strong></a></p><p>Cybersecurity failures increasingly stem from weak or mis-managed digital identities, and organizations must shift their focus from endpoints to identity-first strategies.</p><p></p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2321485</link>
      <enclosure url="https://content.rss.com/episodes/110710/2321485/lifeafterciso/2025_11_11_09_12_13_ac4be2ee-194c-456c-95e7-370a289e098e.mp3" length="70704944" type="audio/mpeg"/>
      <guid isPermaLink="false">65d33edf-bf7b-4375-bf31-e36e82aed252</guid>
      <itunes:duration>4419</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <pubDate>Tue, 11 Nov 2025 09:14:29 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2321485/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E06 – F5 Breach, AWS Outage, Risk Management vs. Security Engineering]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E06 – F5 Breach, AWS Outage, Risk Management vs. Security Engineering]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro </p><p>00:50 AWS Outage </p><p>20:48 F5 Breach </p><p>41:06 Risk Management vs. Security Engineering </p><p>58:19 Moving the Needle Part 3</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://finance.yahoo.com/news/potentially-catastrophic-breach-cyber-firm-020013433.html"><strong>F5 Hack Blamed on China</strong></a></p><p>Chinese state-backed hackers allegedly breached U.S. cybersecurity firm F5, gaining year-long access to its systems and BIG-IP source code, prompting security fears and causing the company to warn of revenue impacts and falling shares.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://aws.amazon.com/message/101925/"><strong>AWS Outage</strong></a></p><p>A race condition in Amazon DynamoDB’s DNS management system caused widespread outages across the US-EAST-1 region on October 19–20, 2025, disrupting DynamoDB, EC2, NLB, and multiple dependent AWS services until recovery was completed the next afternoon.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://sveoti.net/the-ciso-dilemma-risk-management-vs-security-engineering/"><strong>The CISO Dilemma: Risk Management vs. Security Engineering</strong></a></p><p>This post argues that quantitative risk management (QRM) in cybersecurity is a deceptive comfort mechanism that lets executives rationalize insecurity, urging CISOs to reject financialized “risk buy-downs” and instead demand true security engineering and systemic architectural integrity.</p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2295035</link>
      <enclosure url="https://content.rss.com/episodes/110710/2295035/lifeafterciso/2025_10_28_05_16_23_a3fabba7-c4bd-4a39-99bb-6575af29b38a.mp3" length="69320246" type="audio/mpeg"/>
      <guid isPermaLink="false">58d9b6aa-c80e-4152-945a-0e838e589a27</guid>
      <itunes:duration>4332</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <pubDate>Tue, 28 Oct 2025 05:17:09 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2295035/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E05 – Oracle Zero-Day, US cyber info sharing law expires, UK government guarantor for Jaguar attack]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E05 – Oracle Zero-Day, US cyber info sharing law expires, UK government guarantor for Jaguar attack]]></itunes:title>
      <description><![CDATA[<p>00:00 Highlight</p><p>03:44 Oracle E-Business Suite Zero-Day</p><p>14:49 UK government to be guarantor for Jaguar Land Rover cyberattack</p><p>25:54 "Moved the needle" Part 2</p><p>48:18 12 Security Problems Practitioners Want Solved</p><p>1:02:53 National Risk of Losing the CISA 2015 Act?</p><p></p><p><strong>Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign</strong></p><p>Mandiant and Google Threat Intelligence Group uncovered a large-scale CL0P-linked extortion campaign exploiting a zero-day (CVE-2025-61882) in Oracle E-Business Suite to steal data from organizations before patches were released.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation">https://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation</a></p><p></p><p><strong>UK government to be guarantor for Jaguar Land Rover loan as it recovers from cyberattack</strong></p><p>The UK government is guaranteeing a £1.5 billion loan to Jaguar Land Rover to support its recovery and supply chain after a major cyberattack forced the automaker to halt production earlier this month.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://therecord.media/jaguar-land-rover-loan-guarantor-cyberattack">https://therecord.media/jaguar-land-rover-loan-guarantor-cyberattack</a></p><p></p><p><strong>12 Security Problems Practitioners Want Solved</strong></p><p>Leen and Lockstep Ventures released a “Requests for Security Startups” report outlining twelve practitioner-driven problem areas—from preventative security and identity sprawl to AI-native assistants and continuous compliance—calling for builders to create practical, AI-powered, and workflow-integrated solutions that solve real security pain points.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.leen.dev/beyond-the-noise">https://www.leen.dev/beyond-the-noise</a></p><p></p><p><strong>When Cyber Visibility Fades: The National Risk of Losing the CISA 2015 Act—and How Organizations Can Stay Secure Without It</strong></p><p>The expiration of the Cybersecurity Information Sharing Act of 2015 has reduced national cyber visibility and weakened public–private threat intelligence sharing, prompting experts to warn that organizations must strengthen internal risk management and collaboration to stay secure.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.carson-saint.com/when-cyber-visibility-fades-the-national-risk-of-losing-the-cisa-2015-act-and-how-organizations-can-stay-secure-without-it">https://www.carson-saint.com/when-cyber-visibility-fades-the-national-risk-of-losing-the-cisa-2015-act-and-how-organizations-can-stay-secure-without-it</a></p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2270015</link>
      <enclosure url="https://content.rss.com/episodes/110710/2270015/lifeafterciso/2025_10_14_06_28_26_c626a70a-5d36-47a3-9248-66ac745d978e.mp3" length="67898349" type="audio/mpeg"/>
      <guid isPermaLink="false">b81268e6-6b61-42dc-b82b-4423adbee39f</guid>
      <itunes:duration>4243</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <pubDate>Tue, 14 Oct 2025 06:53:49 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2270015/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E04 – "Moving the needle" awards, effect of H-1B changes on cyber industry, Salesloft aftermath]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E04 – "Moving the needle" awards, effect of H-1B changes on cyber industry, Salesloft aftermath]]></itunes:title>
      <description><![CDATA[<p>00:00 Highlight </p><p>00:43 Intro </p><p>06:40 "Moved the needle" awards </p><p>37:05 Scattered Lapsus$ and Jaguar Hack </p><p>44:39 One Token to Rule Them All - Entra pwned </p><p>1:02:21 H-1B visa changes and their effect on the cyber industry</p><p></p><p><strong>Scattered Lapsus$ and Jaguar Hack</strong></p><p>Jaguar Land Rover has extended its production pause until October after a cyberattack crippled its IT systems. The company is struggling to recover operations at Range Rover plants.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/business/jaguar-land-rover-extends-production-pause-until-october-following-cyberattack-0e39b7e8?mod=djemCybersecruityPro&amp;tpl=cs">https://www.wsj.com/business/jaguar-land-rover-extends-production-pause-until-october-following-cyberattack-0e39b7e8</a></p><p></p><p><strong>One Token to Rule Them All</strong></p><p>A deep dive into how attackers can obtain Global Admin across <strong>all</strong> Entra ID tenants using Actor tokens — the mechanics, prerequisites, and mitigation strategies.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/">https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/</a></p><p></p><p><strong>What to Know About Changes to the H-1B Visa Program</strong></p><p>The U.S. is proposing major H-1B visa changes, including a <strong>$100,000 annual fee per visa starting in 2026</strong>, a move aimed at prioritizing higher-wage hires but likely to hit startups and global tech talent hard.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/us-news/h1b-visa-changes-explained-45b818e9?mod=djemCybersecruityPro&amp;tpl=cs">https://www.wsj.com/us-news/h1b-visa-changes-explained-45b818e9?mod=djemCybersecruityPro</a></p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="http://githoundexplore.com/">http://githoundexplore.com/</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2245571</link>
      <enclosure url="https://content.rss.com/episodes/110710/2245571/lifeafterciso/2025_09_30_08_01_11_84657647-9402-4ab7-9aa3-a68ce35d7373.mp3" length="76223388" type="audio/mpeg"/>
      <guid isPermaLink="false">7e50d0a3-296d-4d6e-b8e2-f3b58fc0dbf0</guid>
      <itunes:duration>4763</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <pubDate>Tue, 30 Sep 2025 08:03:25 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2245571/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E03 – Fumbled NPM Attack, Entering the AI Browser Market, Salesloft breach]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E03 – Fumbled NPM Attack, Entering the AI Browser Market, Salesloft breach]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>03:10 NPM supply chain attack leaves attackers empty handed</p><p>24:44 Why is Atlassian buying a browser company?</p><p>37:20 Apple's new Memory Integrity Enforcement</p><p>52:56 Salesloft breach leads to downstream hacks</p><p></p><p><strong>Hackers left empty-handed after massive NPM supply-chain attack</strong></p><p>Hackers briefly compromised popular NPM packages like <em>chalk</em> and <em>debug-js</em>, infecting ~10% of cloud environments, but despite the massive supply-chain reach they only netted about $600 in stolen cryptocurrency.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bleepingcomputer.com/news/security/hackers-left-empty-handed-after-massive-npm-supply-chain-attack/">https://www.bleepingcomputer.com/news/security/hackers-left-empty-handed-after-massive-npm-supply-chain-attack/</a></p><p></p><p><strong>Why is Atlassian Buying a Browser Company?</strong></p><p>Atlassian is buying The Browser Company (makers of Arc and Dia) for $610M to gain control of the browser channel, secure its AI agent (Rovo) distribution, and enter the emerging “enterprise browser” market, even though success is uncertain against Google and Microsoft.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://nextword.substack.com/p/why-is-atlassian-buying-a-browser">https://nextword.substack.com/p/why-is-atlassian-buying-a-browser</a></p><p></p><p><strong>Memory Integrity Enforcement: A complete vision for memory safety in Apple devices</strong></p><p>Apple’s new <strong>Memory Integrity Enforcement (MIE)</strong> brings always-on hardware-software memory safety to iPhone 17, making advanced spyware exploits far harder.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://security.apple.com/blog/memory-integrity-enforcement/">https://security.apple.com/blog/memory-integrity-enforcement/</a></p><p></p><p><strong>Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks</strong></p><p>Hackers exploited Salesloft’s Drift–Salesforce integration to steal OAuth tokens and exfiltrate sensitive Salesforce data, tracked as UNC6395.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bleepingcomputer.com/news/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacks/">https://www.bleepingcomputer.com/news/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacks/</a></p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (Founder, https://githoundexplore.com)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2217329</link>
      <enclosure url="https://content.rss.com/episodes/110710/2217329/lifeafterciso/2025_09_16_04_48_32_e05571c3-2492-4780-a416-4edbdc1cb32b.mp3" length="66530079" type="audio/mpeg"/>
      <guid isPermaLink="false">fc290c08-0b07-406d-9b42-64b1d70a0f59</guid>
      <itunes:duration>4158</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <pubDate>Tue, 16 Sep 2025 05:06:11 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2217329/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E02 - Cyber acquisitions and raises, 95% of GenAI pilots failing, Zelle's alleged security lapses]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E02 - Cyber acquisitions and raises, 95% of GenAI pilots failing, Zelle's alleged security lapses]]></itunes:title>
      <description><![CDATA[<p>00:00 Introduction &amp; BlackHat</p><p>02:06 Cybersecurity in Schools</p><p>18:53 Black Hat Conference Highlights</p><p>34:02 New York sues Zelle</p><p>44:48 Trends in Cybersecurity Mergers and Acquisitions</p><p>1:02:44 95% of generative AI pilots at companies are failing</p><p>1:08:53 Prompt injection with poisoned calendar invites</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://therecord.media/darpa-ai-code-competition-winner-def-con"><strong>DARPA announces $4 million winner of AI code review competition at DEF CON</strong></a></p><p>DARPA announced Team Atlanta as the winner of its two-year competition among researchers to create the best artificial intelligence systems that can find and fix vulnerabilities.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://ag.ny.gov/press-release/2025/attorney-general-james-sues-company-behind-zelle-enabling-widespread-fraud"><strong>Attorney General James Sues Company Behind Zelle for Enabling Widespread Fraud</strong></a></p><p>New York today <a target="_blank" rel="noopener noreferrer nofollow" href="https://ag.ny.gov/sites/default/files/court-filings/people-of-the-state-of-new-york-v-early-warning-services-llc-complaint-2025.pdf">sued Early Warning Services,</a> a company owned and controlled by a group of the largest banks in the United States that was tasked with developing and operating the electronic payment platform Zelle, for failing to protect its users from massive amounts of fraud.</p><p></p><p><strong>Cyber Acquisitions</strong></p><ul><li><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-announces-agreement-to-acquire-cyberark--the-identity-security-leader">Palo Alto / CyberArk</a></li><li><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-to-acquire-onum/">CrowdStrike / Onum</a></li><li><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.okta.com/newsroom/press-releases/okta-with-axiom-security--delivering-robust-privileged-access-fo/">Okta / Axiom</a></li><li><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.armis.com/newsroom/press/armis-raises-200m-at-4-2b-valuation-as-growth-soars-eyes-ipo/">Armis raises millions at $5B valuation</a></li></ul><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/"><strong>MIT report: 95% of generative AI pilots at companies are failing</strong></a></p><p>A recent MIT‑commissioned study—highlighted in Fortune on August 18, 2025—reveals that approximately 95% of generative AI pilot programs at companies failed to deliver any measurable return on investment or financial uplift. The core issue appears to be not the AI itself, but poor integration into existing workflows and misaligned use cases, with only about 5% of pilots achieving rapid revenue growth by focusing sharply on specific pain points.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wired.com/story/google-gemini-calendar-invite-hijack-smart-home/"><strong>Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home</strong></a></p><p>Security researchers demonstrated that a poisoned Google Calendar invite could indirectly prompt-inject Google’s Gemini, causing it to control smart-home devices.</p><p></p><p><strong>Hosts:</strong></p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (https://tillsongalloway.com)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2198884</link>
      <enclosure url="https://content.rss.com/episodes/110710/2198884/lifeafterciso/2025_09_04_03_53_25_5e76bb15-5a64-476b-b72e-366f3f75c8ac.mp3" length="73422643" type="audio/mpeg"/>
      <guid isPermaLink="false">d7b6fc5c-b551-4acd-b007-c33c3e8b6a0b</guid>
      <itunes:duration>4588</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <pubDate>Thu, 04 Sep 2025 03:57:46 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2198884/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast S4E01 - Trump's AI Action Plan, Chip Security Act, receiving gifts from vendors]]></title>
      <itunes:title><![CDATA[Adversarial Podcast S4E01 - Trump's AI Action Plan, Chip Security Act, receiving gifts from vendors]]></itunes:title>
      <description><![CDATA[<p>00:00 Introduction &amp; BlackHat </p><p>03:14 AI Action Plan Overview </p><p>13:30 Chip Security Act </p><p>20:48 Government led AI-ISAC? </p><p>23:16 UK government considering banning public sector ransomware payments </p><p>28:14 Microsoft probing if Chinese hackers learned SharePoint flaws through alert </p><p>42:07 Ethics in Vendor Relationships – Gifts for meetings</p><p></p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf"><strong>America's AI Action Plan</strong></a></p><p>“America’s AI Action Plan,” released by the Trump administration, outlines a roadmap with over 90 federal actions across three pillars—accelerating AI innovation, building U.S. AI infrastructure, and asserting international AI leadership through exports and technology alliances.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.thefai.org/posts/the-chip-security-act-a-bipartisan-solution-to-chip-smuggling"><strong>The Chip Security Act: A Bipartisan Solution to Chip Smuggling</strong></a></p><p>The Chip Security Act, introduced by U.S. lawmakers, mandates that export‑controlled AI chip makers (like NVIDIA) embed on‑chip location‑verification mechanisms to ensure devices go only where they’re authorized—aiming to deter smuggling (especially to China) without deploying intrusive GPS or kill switches.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/pulse/why-government-led-ai-isac-missed-opportunity-errol-weiss-2wake/"><strong>Why a Government-Led AI-ISAC is a Missed Opportunity</strong></a></p><p>Errol Weiss argues that an AI‑ISAC led by the U.S. government, as proposed in the July 2025 White House AI Action Plan, represents a missed opportunity, because government-led initiatives tend to be bureaucratic, slow, less innovative, struggle to win private-sector trust and buy‑in, risk duplicating existing ISAC efforts, and may be perceived as politically biased—undermining effective, rapid, cross-industry intelligence sharing</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/world/uk/uk-plans-ban-public-sector-bodies-paying-ransom-cyber-criminals-2025-07-22/"><strong>UK plans to ban public sector bodies from paying ransom to cyber criminals</strong></a></p><p>The UK government is set to ban public sector bodies and operators of critical national infrastructure from paying ransom demands to cyber criminals, as part of a wider package also mandating mandatory reporting for other organisations planning to pay, aimed at dismantling the ransomware business model and protecting essential services from dangerous disruptions.</p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/technology/microsoft-probing-if-chinese-hackers-learned-sharepoint-flaws-through-alert-2025-07-25/"><strong>Microsoft probing if Chinese hackers learned SharePoint flaws through alert, Bloomberg News reports</strong></a></p><p>Microsoft is investigating whether a leak from its Microsoft Active Protections Program (MAPP)—which provides early vulnerability alerts to security partners—may have enabled Chinese-aligned hackers (Linen Typhoon, Violet Typhoon, and Storm-2603) to exploit critical zero‑day flaws in on-premises SharePoint servers before Microsoft fully patched the software, fueling a global espionage and ransomware campaign.</p><p></p><p>Hosts:</p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway (https://tillsongalloway.com)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2143786</link>
      <enclosure url="https://content.rss.com/episodes/110710/2143786/lifeafterciso/2025_07_30_08_23_15_b59b62b6-db27-4c33-a9d7-94fd2074d0d8.mp3" length="49681598" type="audio/mpeg"/>
      <guid isPermaLink="false">8b30a893-8af8-4abb-999e-ea1c87204fa3</guid>
      <itunes:duration>3105</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <pubDate>Wed, 30 Jul 2025 08:24:03 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2143786/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 27 - Is AI necessary for cyber investment? Microsoft moving away from kernel-based AV; Moonlighting and Fake IT workers]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 27 - Is AI necessary for cyber investment? Microsoft moving away from kernel-based AV; Moonlighting and Fake IT workers]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>3:23 Cybersecurity stocks: why now might be the time to buy?</p><p>8:55 AI in cyber investment and business</p><p>29:28 Microsoft is moving antivirus providers out of the Windows kernel</p><p>34:29 New AI Malware PoC Reliably Evades Microsoft Defender</p><p>37:08  VSCode Fork; Putting Millions at Risk</p><p>43:39 Extensions turn Trojan and infect 2.3M Chrome and Edge users</p><p>54:20 US government takes down major North Korean ‘remote IT workers’ operation</p><p>1:06:06 Phishing Training Doesn't Work</p><p></p><p><strong>Cybersecurity stocks: why now might be the time to buy?</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://moneyweek.com/investments/tech-stocks/buy-cybersecurity-stocks">https://moneyweek.com/investments/tech-stocks/buy-cybersecurity-stocks</a></p><p></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://a16z.com/newsletter/december-2024-enterprise-newsletter-ai-is-driving-a-shift-towards-outcome-based-pricing/"><strong>AI Is Driving A Shift Towards Outcome-Based Pricing</strong></a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.technologyreview.com/2025/07/01/1119498/cloudflare-will-now-by-default-block-ai-bots-from-crawling-its-clients-websites/"><strong>Cloudflare will now, by default, block AI bots from crawling its clients’ websites </strong></a></p><p></p><p><strong>Microsoft is moving antivirus providers out of the Windows kernel</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.theverge.com/news/692637/microsoft-windows-kernel-antivirus-changes">https://www.theverge.com/news/692637/microsoft-windows-kernel-antivirus-changes</a></p><p></p><p><strong>New AI Malware PoC Reliably Evades Microsoft Defender</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/endpoint-security/ai-malware-poc-evades-microsoft-defender">https://www.darkreading.com/endpoint-security/ai-malware-poc-evades-microsoft-defender</a></p><p></p><p><strong>Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork; Putting Millions at Risk</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44">https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44</a></p><p></p><p><strong>Massive browser hijack: extensions turn Trojan and infect 2.3M Chrome and Edge users</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://cybernews.com/security/chrome-edge-hijacked-by-eighteen-malicious-extensions">https://cybernews.com/security/chrome-edge-hijacked-by-eighteen-malicious-extensions</a></p><p></p><p><strong>US government takes down major North Korean ‘remote IT workers’ operation</strong> <a target="_blank" rel="noopener noreferrer nofollow" href="https://techcrunch.com/2025/06/30/us-government-takes-down-major-north-korean-remote-it-workers-operation/">https://techcrunch.com/2025/06/30/us-government-takes-down-major-north-korean-remote-it-workers-operation/</a></p><p></p><p><strong>We've All Been Wrong: Phishing Training Doesn't Work</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/endpoint-security/phishing-training-doesnt-work">https://www.darkreading.com/endpoint-security/phishing-training-doesnt-work</a></p><p></p><p>Hosts:</p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (Founder, stealth startup)</p><p>Producer: Tillson Galloway</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2115257</link>
      <enclosure url="https://content.rss.com/episodes/110710/2115257/lifeafterciso/2025_07_15_04_28_44_d3b14ba2-9476-45ae-9471-525b403691ba.mp3" length="73759256" type="audio/mpeg"/>
      <guid isPermaLink="false">e04afd8a-1434-4854-b965-7ad8844a26c1</guid>
      <itunes:duration>4609</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>27</itunes:episode>
      <podcast:episode>27</podcast:episode>
      <pubDate>Tue, 15 Jul 2025 05:11:42 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2115257/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 26 - US Treasury's Cybersecurity Failures, SEC scraps proposed cybersecurity rules, what makes AI Security different]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 26 - US Treasury's Cybersecurity Failures, SEC scraps proposed cybersecurity rules, what makes AI Security different]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>03:17 Banks call out US Treasury's cybersecurity failures</p><p>28:54 SEC scraps proposed cybersecurity rules</p><p>38:05 What makes AI Security different</p><p></p><p><strong>Banks Challenge Treasury on Cybersecurity Failures</strong>. A coalition of major U.S. banking associations—including the American Bankers Association, Bank Policy Institute, MFA, and SIFMA—has publicly challenged the U.S. Treasury and OCC to adopt private-sector cybersecurity standards, decentralize sensitive data, enforce rapid breach notifications, and streamline data collection following high-profile email breaches at federal regulators. <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.theglobaltreasurer.com/2025/06/10/banking-groups-demand-regulator-cybersecurity-standards/">https://www.theglobaltreasurer.com/2025/06/10/banking-groups-demand-regulator-cybersecurity-standards/</a></p><p><strong>SEC scraps proposed cybersecurity rules for investment advisers, market participants. </strong>The U.S. Securities and Exchange Commission (SEC) has scrapped proposed cybersecurity regulations targeting investment advisers, funds, and market participants. The withdrawal reflects pushback from the financial industry, which cited concerns over compliance burdens and regulatory overlap. Critics argue the move weakens oversight as cyber threats continue to rise across the financial sector. <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cybersecuritydive.com/news/sec-withdraw-cyber-rules-investment-advisers-funds/750786/">https://www.cybersecuritydive.com/news/sec-withdraw-cyber-rules-investment-advisers-funds/750786/</a></p><p><strong>Exclusive: New Microsoft Copilot flaw signals broader risk of AI agents being hacked—‘I would be terrified’. </strong>A newly discovered vulnerability in Microsoft’s Copilot platform—dubbed “Echoleak”—allows malicious actors to extract private user data from AI agent interactions. The flaw underscores the broader risks associated with AI-powered assistants, particularly as they become more deeply embedded in enterprise workflows. Experts warn this class of attacks could signal a new era of AI exploitation. <a target="_blank" rel="noopener noreferrer nofollow" href="https://fortune.com/2025/06/11/microsoft-copilot-vulnerability-ai-agents-echoleak-hacking/">https://fortune.com/2025/06/11/microsoft-copilot-vulnerability-ai-agents-echoleak-hacking/</a></p><p></p><p>Hosts:</p><ul><li>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</li><li>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</li><li>Mario Duarte (Founder, stealth startup)</li></ul><p>Producer: Tillson Galloway (https://tillsongalloway.com)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2096071</link>
      <enclosure url="https://content.rss.com/episodes/110710/2096071/lifeafterciso/2025_07_01_05_38_19_c8d791b7-2a21-4519-b489-0777daa3172b.mp3" length="57075161" type="audio/mpeg"/>
      <guid isPermaLink="false">d2f24188-bec1-4754-a066-55ffb1287029</guid>
      <itunes:duration>3567</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>26</itunes:episode>
      <podcast:episode>26</podcast:episode>
      <pubDate>Tue, 01 Jul 2025 06:48:57 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2096071/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 25 – From CISOs to Entrepreneurs, Trump changes to Biden's Cyber EOs, banks ask SEC to drop disclosure requirements]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 25 – From CISOs to Entrepreneurs, Trump changes to Biden's Cyber EOs, banks ask SEC to drop disclosure requirements]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>04:15 Our journeys from CISOs to Entreprenuers</p><p>23:48 Trump changes Biden's Cyber EOs</p><p>28:40 States rebuff proposed federal ban on AI laws</p><p>36:43 Vanta bug exposes customers' data to other customers</p><p>49:12 SentinelOne outage</p><p>52:53 Banking groups ask SEC to drop incident disclosure requirements</p><p>1:00:37 Cybersecurity teams generate average $36M in business growth</p><p>1:03:50 Cybersecurity Companies Want to Go Public. The Market Isn’t Letting Them</p><p></p><p><strong>Trump Cybersecurity Fact Sheet</strong> President Trump announced a reprioritization of U.S. cybersecurity efforts, shifting away from prior frameworks and emphasizing national defense and economic resilience. <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.whitehouse.gov/fact-sheets/2025/06/fact-sheet-president-donald-j-trump-reprioritizes-cybersecurity-efforts-to-protect-america/">https://www.whitehouse.gov/fact-sheets/2025/06/fact-sheet-president-donald-j-trump-reprioritizes-cybersecurity-efforts-to-protect-america/</a></p><p><strong>Vanta Bug Exposed Customer Data</strong> A software flaw in Vanta's platform briefly exposed sensitive compliance data between customers. <a target="_blank" rel="noopener noreferrer nofollow" href="https://techcrunch.com/2025/06/02/vanta-bug-exposed-customers-data-to-other-customers/">https://techcrunch.com/2025/06/02/vanta-bug-exposed-customers-data-to-other-customers/</a></p><p><strong>SentinelOne Outage</strong> A major backend outage at SentinelOne disrupted security operations for numerous customers. <a target="_blank" rel="noopener noreferrer nofollow" href="https://apple.news/AuaqeFPP8QUyoOwuAwvRBkA">https://apple.news/AuaqeFPP8QUyoOwuAwvRBkA</a></p><p><strong>States Push Back on Federal AI Law Ban</strong> U.S. states are resisting a federal proposal to ban state-level AI regulation, citing sovereignty and innovation concerns. <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/articles/states-rebuff-proposed-federal-ban-on-ai-laws-6dde3ce6?mod=procyber_lead_pos1&amp;tpl=cs">https://www.wsj.com/articles/states-rebuff-proposed-federal-ban-on-ai-laws-6dde3ce6?mod=procyber_lead_pos1&amp;tpl=cs</a></p><p><strong>Banking Groups Oppose SEC Cyber Rule</strong> Banking associations urged the SEC to drop mandatory cyber incident disclosure rules, citing risk to financial stability. <a target="_blank" rel="noopener noreferrer nofollow" href="https://ecency.com/hive-167922/@justmythoughts/banking-groups-ask-sec-to">https://ecency.com/hive-167922/@justmythoughts/banking-groups-ask-sec-to</a></p><p><strong>Cybersecurity Teams “Drive $36M in Growth”</strong> A report claims cybersecurity teams deliver $36M in business value annually—an assertion met with industry skepticism. <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.infosecurity-magazine.com/news/cybersecurity-teams-business-growth/">https://www.infosecurity-magazine.com/news/cybersecurity-teams-business-growth/</a></p><p><strong>Cybersecurity IPO Market Frozen</strong> Despite strong interest, cybersecurity companies are unable to go public due to investor hesitation and market volatility. <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/articles/cybersecurity-companies-want-to-go-public-the-market-isnt-letting-them-60bfe663?mod=procyber_feat2_regulation-risk_pos2">https://www.wsj.com/articles/cybersecurity-companies-want-to-go-public-the-market-isnt-letting-them-60bfe663</a></p><p></p><p>Hosts:</p><ul><li>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</li><li>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</li><li>Mario Duarte (Founder, stealth startup)</li></ul><p>Producer: Tillson Galloway (https://tillsongalloway.com)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2075758</link>
      <enclosure url="https://content.rss.com/episodes/110710/2075758/lifeafterciso/2025_06_16_04_53_36_cfe02584-7bec-4fec-a578-46706010ee0f.mp3" length="68591608" type="audio/mpeg"/>
      <guid isPermaLink="false">994becca-0737-425c-8058-c191a0558672</guid>
      <itunes:duration>4286</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>25</itunes:episode>
      <podcast:episode>25</podcast:episode>
      <pubDate>Mon, 16 Jun 2025 04:54:55 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2075758/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 24 – Global Lumma takedown, Coinbase employee bribed, malicious MCP integrations and NPM packages]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 24 – Global Lumma takedown, Coinbase employee bribed, malicious MCP integrations and NPM packages]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>02:49 Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals</p><p>14:29 Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom</p><p>26:24 Fake OpenAI MCP Integration</p><p>32:25 Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials</p><p>36:03 Destructive malware available in NPM repo went unnoticed for 2 years</p><p>48:10 Sam &amp; Jony introduce io</p><p>58:23 Discussion: how risky are local admin rights?</p><p></p><p></p><p><strong>Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals</strong></p><p>In May 2025, an international coalition led by Microsoft, the U.S. Department of Justice, Europol, and Japan's Cybercrime Control Center dismantled the Lumma Stealer malware operation.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wired.com/story/lumma-stealer-takedown-disrupted/">https://www.wired.com/story/lumma-stealer-takedown-disrupted/</a></p><p></p><p><strong>Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom</strong></p><p>Hackers bribed overseas Coinbase customer support agents to steal sensitive user data, leading to a breach prompting a $20M ransom, which Coinbase refused, instead offering a $20M bounty for information leading to the attackers' arrest.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cnbc.com/2025/05/15/coinbase-says-hackers-bribed-staff-to-steal-customer-data-and-are-demanding-20-million-ransom.html">https://www.cnbc.com/2025/05/15/coinbase-says-hackers-bribed-staff-to-steal-customer-data-and-are-demanding-20-million-ransom.html</a></p><p></p><p><strong>Fake OpenAI MCP Integration</strong></p><p>A fake OpenAI MCP integration was found by a security researcher, showing the importance of security in emerging technologies.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/feed/update/urn:li:activity:7331118878384615424/">https://www.linkedin.com/feed/update/urn:li:activity:7331118878384615424/</a></p><p></p><p><strong>Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials</strong></p><p>Three malicious npm packages targeting macOS users of the AI-powered code editor Cursor have infected over 3,200 developers by harvesting credentials.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html">https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html</a></p><p></p><p><strong>Destructive malware available in NPM repo went unnoticed for 2 years</strong></p><p>A destructive malware campaign infiltrated the npm ecosystem for over two years, with malicious packages disguised as legitimate tools targeting popular JavaScript frameworks.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://arstechnica.com/information-technology/2025/05/destructive-malware-available-in-npm-repo-went-unnoticed-for-2-years/">https://arstechnica.com/information-technology/2025/05/destructive-malware-available-in-npm-repo-went-unnoticed-for-2-years/</a></p><p></p><p><strong>Sam &amp; Jony introduce io</strong></p><p>OpenAI has announced the acquisition of Jony Ive's AI hardware startup, io.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://openai.com/sam-and-jony/">https://openai.com/sam-and-jony/</a></p><p></p><p>Hosts:</p><ul><li>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</li><li>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</li><li>Mario Duarte (Founder, stealth startup)</li></ul><p>Producer: Tillson Galloway (https://tillsongalloway.com)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2046377</link>
      <enclosure url="https://content.rss.com/episodes/110710/2046377/lifeafterciso/2025_05_27_06_33_48_3389708d-9355-4d29-a5b3-5ceddb04d22f.mp3" length="62649900" type="audio/mpeg"/>
      <guid isPermaLink="false">2bcb9c8f-b9c8-4ea2-aad6-b3e43b94c5dc</guid>
      <itunes:duration>3915</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>24</itunes:episode>
      <podcast:episode>24</podcast:episode>
      <pubDate>Tue, 27 May 2025 06:44:27 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2046377/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 23 – Crowdstrike layoffs, RSA Innovation Sandbox, new Pentagon CIO]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 23 – Crowdstrike layoffs, RSA Innovation Sandbox, new Pentagon CIO]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>00:44 Sounil's RSA Innovation Sandbox experience</p><p>5:00 5% staffing cuts at Crowdstrike, AI cited as a factor</p><p>16:00 Trump picks private sector veteran as Pentagon CIO</p><p>32:41 Messaging app used by Trump official suspends operations after reported hack</p><p>49:52 An open letter to third-party suppliers</p><p>59:32 Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support</p><p>1:04:42 Discussion: delivering secret keys stored in PDFs for password managers</p><p></p><p>Hosts:</p><p>Jerry Perullo (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarial.com/">https://adversarial.com/</a>)</p><p>Sounil Yu (Founder, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.knostic.ai/">https://www.knostic.ai/</a>)</p><p>Mario Duarte (CISO, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.aembit.io/">https://www.aembit.io/</a>)</p><p></p><p><strong>Stories</strong></p><p><strong>5% staffing cuts at Crowdstrike, AI cited as a factor</strong></p><p>CrowdStrike is laying off 5% of its workforce, citing AI-driven changes in industry operations as a driving factor.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cnbc.com/2025/05/07/crowdstrike-announces-5percent-job-cuts-says-ai-reshaping-every-industry.html">https://www.cnbc.com/2025/05/07/crowdstrike-announces-5percent-job-cuts-says-ai-reshaping-every-industry.html</a></p><p></p><p><strong>Trump picks private sector veteran as Pentagon CIO</strong></p><p>Former President Trump has nominated a private-sector executive to serve as the new Chief Information Officer for the Department of Defense.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://therecord.media/trump-picks-private-sector-veteran-for-dod-cio-position">https://therecord.media/trump-picks-private-sector-veteran-for-dod-cio-position</a></p><p></p><p><strong>Messaging app used by Trump official suspends operations after reported hack</strong></p><p>A secure messaging app used by a Trump official has suspended service following a reported cyberattack.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cnbc.com/2025/05/05/signal-telemessage-hack-trump-waltz.html">https://www.cnbc.com/2025/05/05/signal-telemessage-hack-trump-waltz.html</a></p><p></p><p><strong>An open letter to third-party suppliers</strong></p><p>JPMorgan has issued an open letter urging its third-party suppliers to prioritize stronger cybersecurity and operational resilience.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.jpmorgan.com/technology/technology-blog/open-letter-to-our-suppliers">https://www.jpmorgan.com/technology/technology-blog/open-letter-to-our-suppliers</a></p><p></p><p><strong>Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support</strong></p><p>Microsoft is now enabling passkeys by default for new accounts, expanding passwordless access to over 15 billion users.</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html">https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2027941</link>
      <enclosure url="https://content.rss.com/episodes/110710/2027941/lifeafterciso/2025_05_14_06_50_29_9b2cd4c7-3bc3-4e2b-91ad-dea8491c0f62.mp3" length="66366811" type="audio/mpeg"/>
      <guid isPermaLink="false">086eaa06-ead7-4ae4-99fb-6326c1e49853</guid>
      <itunes:duration>4147</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>23</itunes:episode>
      <podcast:episode>23</podcast:episode>
      <pubDate>Wed, 14 May 2025 06:51:33 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2027941/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 22 – RSA Conference is here, Verizon's 2025 Data Breach Investigations Report, China names alleged US hackers]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 22 – RSA Conference is here, Verizon's 2025 Data Breach Investigations Report, China names alleged US hackers]]></itunes:title>
      <description><![CDATA[<p>00:00 Intro</p><p>00:31 RSA conference</p><p>14:38 Verizon's 2025 DBIR report</p><p>37:55 Security of "Sign in with Google/Microsoft"</p><p>1:02:50 China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents</p><p></p><p><strong>RSA Links:</strong></p><p>Innovation Sandbox: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.rsaconference.com/usa/programs/innovation-sandbox">https://www.rsaconference.com/usa/programs/innovation-sandbox</a></p><p>Professional Association of CISOs: <a target="_blank" rel="noopener noreferrer nofollow" href="https://theciso.org/">https://theciso.org/</a></p><p>Pitch for Charity:<strong> </strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.okta.com/newsroom/press-releases/pitch-for-charity/">https://www.okta.com/newsroom/press-releases/pitch-for-charity/</a></p><p></p><p><strong>Verizon's 2025 Data Breach Investigations Report </strong></p><p>This year's Verizon DBIR (Data Breach Investigations Report) has been released, which covers the latest techniques that lead to incidents and breaches.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.verizon.com/business/resources/reports/dbir/?cmp=knc:ggl:ac:ent:ea:na:8888855284_ds_cid_71700000082349844_ds_agid_58700006959928987&amp;utm_term=verizon%20cyber%20attack&amp;utm_medium=cpc&amp;utm_source=google&amp;utm_campaign=GGL_BND_Security_Phrase&amp;utm_content=Enterprise&amp;gad_source=1&amp;gbraid=0AAAAABymyRHv-0n3kNU-QuoE3Nkc3OwK_&amp;gclid=Cj0KCQjwzrzABhD8ARIsANlSWNNyufGRl3UMqLGJGceFgcZOJeGK__S_-Gb_Hqgmpyyt9lbcnxjMdhgaAjVNEALw_wcB&amp;gclsrc=aw.ds">https://www.verizon.com/business/resources/reports/dbir</a></p><p></p><p><strong>China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents</strong></p><p>"China accused the United States National Security Agency (NSA) on Tuesday of launching 'advanced' cyberattacks during the Asian Winter Games in February, targeting essential industries."</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/technology/cybersecurity/chinas-harbin-says-us-launched-advanced-cyber-attacks-winter-games-2025-04-15/">https://www.reuters.com/technology/cybersecurity/chinas-harbin-says-us-launched-advanced-cyber-attacks-winter-games-2025-04-15/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/2004746</link>
      <enclosure url="https://content.rss.com/episodes/110710/2004746/lifeafterciso/2025_04_28_08_28_01_41282bc1-8671-43ec-beac-7b2e377ea1ed.mp3" length="66790204" type="audio/mpeg"/>
      <guid isPermaLink="false">0a8af7ff-9ac1-48a1-b397-7cf4b6154cf9</guid>
      <itunes:duration>4174</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>22</itunes:episode>
      <podcast:episode>22</podcast:episode>
      <pubDate>Mon, 28 Apr 2025 08:28:32 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/2004746/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 21 – Chris Krebs & Sentinel One's clearances revoked, Oracle hack, how Goldberg got added to Signal chat]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 21 – Chris Krebs & Sentinel One's clearances revoked, Oracle hack, how Goldberg got added to Signal chat]]></itunes:title>
      <description><![CDATA[<p>⬇️ See below for timestamps/summaries/references for each topic</p><p>00:00 Highlight/theme</p><p>23:05 Intro</p><p>06:56 White House revokes Chris Krebs and SentinelOne's security clearances</p><p>16:55 How Jeffrey Goldberg got added to the White House Signal group chat</p><p>26:48 DOGE staffer provided tech support to cybercrime ring</p><p>39:29 China Acknowledged Role in U.S. Infra Hacks</p><p>51:56 Oracle under fire for its handling of security incidents</p><p>54:51 Hackers Spied on 100 US Bank Regulators’ Emails for Over a Year</p><p></p><p><strong>Fact Sheet: President Donald J. Trump Addresses Risks from Chris Krebs and Government Censorship</strong></p><p>President Trump has revoked the security clearance of Chris Krebs and his associates, citing concerns over Krebs’ alleged misuse of authority at CISA.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.whitehouse.gov/fact-sheets/2025/04/fact-sheet-president-donald-j-trump-addresses-risks-from-chris-krebs-and-government-censorship/">https://www.whitehouse.gov/fact-sheets/2025/04/fact-sheet-president-donald-j-trump-addresses-risks-from-chris-krebs-and-government-censorship/</a></p><p></p><p><strong>How the Atlantic’s Jeffrey Goldberg got added to the White House Signal group chat</strong></p><p>An internal investigation revealed that Mike Waltz accidentally added <em>Atlantic</em> editor Jeffrey Goldberg to a Signal group chat discussing classified military plans due to a months-old contact-saving error.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.theguardian.com/us-news/2025/apr/06/signal-group-chat-leak-how-it-happened">https://www.theguardian.com/us-news/2025/apr/06/signal-group-chat-leak-how-it-happened</a></p><p></p><p><strong>DOGE staffer 'Big Balls' provided tech support to cybercrime ring, records show</strong></p><p>A member of DOGE previously provided network support to a cybercrime group through his company.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/world/us/doge-staffer-big-balls-provided-tech-support-cybercrime-ring-records-show-2025-03-26/">https://www.reuters.com/world/us/doge-staffer-big-balls-provided-tech-support-cybercrime-ring-records-show-2025-03-26/</a></p><p></p><p><strong>In Secret Meeting, China Acknowledged Role in U.S. Infrastructure Hacks</strong></p><p>​In a confidential meeting, Chinese officials tacitly acknowledged responsibility for a series of cyberattacks on U.S. critical infrastructure, including ports, water utilities, and airports.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/politics/national-security/in-secret-meeting-china-acknowledged-role-in-u-s-infrastructure-hacks-c5ab37cb">https://www.wsj.com/politics/national-security/in-secret-meeting-china-acknowledged-role-in-u-s-infrastructure-hacks-c5ab37cb</a></p><p></p><p><strong>Oracle Appears to Admit Breach of 2 'Obsolete' Servers</strong></p><p>​Oracle has acknowledged that a hacker accessed two outdated servers containing encrypted or hashed credentials.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/cyberattacks-data-breaches/oracle-breach-2-obsolete-servers">https://www.darkreading.com/cyberattacks-data-breaches/oracle-breach-2-obsolete-servers</a></p><p></p><p><strong>Hackers Spied on 100 US Bank Regulators’ Emails for Over a Year</strong></p><p>​Hackers infiltrated the email systems of over 100 U.S. bank regulators at the Office of the Comptroller of the Currency, accessing 150,000+ messages from 2023-2025.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bloomberg.com/news/articles/2025-04-08/hackers-spied-on-100-bank-regulators-emails-for-over-a-year">https://www.bloomberg.com/news/articles/2025-04-08/hackers-spied-on-100-bank-regulators-emails-for-over-a-year</a></p><p></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1987650</link>
      <enclosure url="https://content.rss.com/episodes/110710/1987650/lifeafterciso/2025_04_15_06_13_50_5f8407c3-97e8-4e59-85a0-bfcff7734078.mp3" length="65847680" type="audio/mpeg"/>
      <guid isPermaLink="false">783bedbe-65f1-4237-893f-73d8290cddff</guid>
      <itunes:duration>4115</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>21</itunes:episode>
      <podcast:episode>21</podcast:episode>
      <pubDate>Tue, 15 Apr 2025 06:27:58 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1987650/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[Adversarial Podcast Ep. 20 – corporate espionage among SaaS companies, DC's Signal snafu, where is the cyber market going?]]></title>
      <itunes:title><![CDATA[Adversarial Podcast Ep. 20 – corporate espionage among SaaS companies, DC's Signal snafu, where is the cyber market going?]]></itunes:title>
      <description><![CDATA[<p>⬇️ See below for timestamps/summaries/references for each topic</p><p>00:00 Highlight/theme</p><p>00:28 Intro</p><p>02:15 Unicorn startup allegedly cultivated spy to steal trade secrets from competitor</p><p>18:19 Google Strikes $32 Billion Deal for Cybersecurity Startup Wiz</p><p>33:35 Trump Administration accidentally sends war plans to reporter via Signal</p><p>47:20 GitHub action supply chain attack</p><p>53:55 Oracle under fire for its handling of security incidents</p><p></p><p><strong>Rippling Alleges Deel Cultivated Spy, Orchestrated Trade-Secret Theft Against Competitor</strong></p><p>Rippling has filed a lawsuit alleging that $12 billion HR-tech company Deel orchestrated a months-long corporate espionage campaign involving a planted spy within Rippling.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.rippling.com/blog/lawsuit-alleges-12-billion-unicorn-deel-cultivated-spy-orchestrated-long-running-trade-secret-theft-corporate-espionage-against-competitor">https://www.rippling.com/blog/lawsuit-alleges-12-billion-unicorn-deel-cultivated-spy-orchestrated-long-running-trade-secret-theft-corporate-espionage-against-competitor</a></p><p></p><p><strong>Google Strikes $32 Billion Deal for Cybersecurity Startup Wiz</strong></p><p>Google has agreed to acquire cybersecurity startup Wiz for $32 billion in cash, marking its largest acquisition ever and the biggest tech deal of 2025 so far. </p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/business/deals/alphabet-back-in-deal-talks-for-cybersecurity-startup-wiz-41cd3090?st=uQ8bmN&amp;reflink=article_copyURL_share">https://www.wsj.com/business/deals/alphabet-back-in-deal-talks-for-cybersecurity-startup-wiz-41cd3090?st=uQ8bmN&amp;reflink=article_copyURL_share</a></p><p></p><p><strong>The Trump Administration Accidentally Texted Me Its War Plans</strong></p><p>In the article, journalist Jeffrey Goldberg reveals that he was accidentally included in a Signal group chat by senior members of the Trump administration—specifically Pete Hegseth, the Secretary of Defense—who shared detailed plans for a military strike on Houthi targets in Yemen. </p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.theatlantic.com/politics/archive/2025/03/trump-administration-accidentally-texted-me-its-war-plans/682151/">https://www.theatlantic.com/politics/archive/2025/03/trump-administration-accidentally-texted-me-its-war-plans/682151/</a></p><p></p><p><strong>Supply Chain Attack on GitHub Action</strong></p><p>Wiz discovered a supply chain attack on the GitHub Action reviewdog/action-setup@v1, likely leading to the compromise of tj-actions/changed-files, resulting in widespread CI secret leakage and highlighting the risks of unpinned actions.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup">https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup</a></p><p></p><p><strong>Oracle hacked</strong></p><p>Oracle has informed clients of a second recent cybersecurity breach in which a hacker accessed an old system and stole customer log-in credentials, some of which date back to 2024, according to Bloomberg News. </p><p>Latest: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/technology/cybersecurity/oracle-tells-clients-second-recent-hack-log-in-data-stolen-bloomberg-news-2025-04-02/">https://www.reuters.com/technology/cybersecurity/oracle-tells-clients-second-recent-hack-log-in-data-stolen-bloomberg-news-2025-04-02/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1972471</link>
      <enclosure url="https://content.rss.com/episodes/110710/1972471/lifeafterciso/2025_04_04_04_37_18_b52bbc53-6300-4daa-b775-621a531b6be9.mp3" length="56642573" type="audio/mpeg"/>
      <guid isPermaLink="false">2dcbc7d0-a939-47d7-a48a-c79312486ceb</guid>
      <itunes:duration>3540</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>20</itunes:episode>
      <podcast:episode>20</podcast:episode>
      <pubDate>Fri, 04 Apr 2025 05:03:29 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1972471/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 19 – AI-Powered Cybercrime, CISO job market, the BYOL elephant in the room]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 19 – AI-Powered Cybercrime, CISO job market, the BYOL elephant in the room]]></itunes:title>
      <description><![CDATA[<p>⬇️ See below for timestamps/summaries/references for each topic</p><p>00:00 Highlight/theme</p><p>00:37 Intro</p><p>01:37 Malvertising campaign leads to info stealers hosted on GitHub</p><p>11:59 Wall Street is worried it can't keep up with AI-powered cybercriminals</p><p>24:02 What Really Happened With the DDoS Attacks That Took Down X</p><p>28:34 Bring-your-own-laptop policies</p><p>40:41 Are WAFs useful or are they just another TPRM box to check?</p><p>46:59 Is the CISO job market warming up?</p><p></p><p><strong>Malvertising campaign leads to info stealers hosted on GitHub</strong></p><p>Microsoft Threat Intelligence uncovered a large-scale malvertising campaign in December 2024, affecting nearly one million devices globally. The attack originated from illegal streaming sites embedding malvertising redirectors, which funneled users to GitHub-hosted malware, with additional payloads delivered via Discord and Dropbox. This multi-stage attack leveraged info stealers like Lumma and Doenerium, along with remote monitoring tools, using advanced evasion techniques to steal system and browser data while maintaining persistence on compromised devices.</p><p>📖 References:<a target="_blank" rel="noopener noreferrer nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/"> https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/</a></p><p></p><p><strong>Wall Street is worried it can't keep up with AI-powered cybercriminals</strong></p><p>A survey by Accenture found that 80% of bank cybersecurity executives believe generative AI is enabling cybercriminals faster than banks can respond. While banks invest billions in cybersecurity, they struggle to keep pace due to strict regulations and the rapid advancement of AI-powered scams that target customers, employees, and vendors. Cybercriminals exploit generative AI to craft sophisticated attacks, infiltrate supply chains, and identify vulnerabilities, making third-party risk a major concern for financial institutions.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.businessinsider.com/banks-ai-cybersecurity-threats-hackers-generative-ai-2025-3">https://www.businessinsider.com/banks-ai-cybersecurity-threats-hackers-generative-ai-2025-3</a></p><p></p><p><strong>What Really Happened With the DDoS Attacks That Took Down X</strong></p><p>X experienced intermittent outages due to a series of DDoS attacks, which Elon Musk attributed to Ukrainian IP addresses, though cybersecurity experts argue that IP attribution alone is unreliable. Analysts suggest the attacks targeted improperly secured X origin servers, allowing a botnet of compromised cameras and DVRs to bypass Cloudflare protection. While a pro-Palestinian group claimed responsibility, experts emphasize that the attack’s true origin remains unclear due to the decentralized nature of botnets and the use of obfuscation techniques.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wired.com/story/x-ddos-attack-march-2025/">https://www.wired.com/story/x-ddos-attack-march-2025/</a></p><p></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1946153</link>
      <enclosure url="https://content.rss.com/episodes/110710/1946153/lifeafterciso/2025_03_18_19_38_24_57500b8c-e1fc-440e-b9fc-7c792d0d8a63.mp3" length="49612500" type="audio/mpeg"/>
      <guid isPermaLink="false">ecd458b6-8b0d-4acf-af3f-34cd8af3781e</guid>
      <itunes:duration>3100</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>19</itunes:episode>
      <podcast:episode>19</podcast:episode>
      <pubDate>Tue, 18 Mar 2025 06:19:18 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1946153/transcript" type="text/vtt"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 18 - CISA cuts, North Koreans steal $1.5B in crypto, planning for RSA Conference]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 18 - CISA cuts, North Koreans steal $1.5B in crypto, planning for RSA Conference]]></itunes:title>
      <description><![CDATA[<p>00:00 Highlight</p><p>00:28 Intro</p><p>3:41 What's getting cut at CISA?</p><p>19:01 USCYBERCOM told to stop planning offensive attacks against Russia</p><p>27:54 ByBit hacked for $1.5B in cryptocurrency</p><p>40:01 CISO discussion: How to regain trust after a cyber breach</p><p>49:17 CISO discussion: Data security for GenAI tools</p><p>58:43 How to get the most out of RSA Conference</p><p></p><p>💰 <strong>Budget cuts hit CISA</strong>, and election security programs might be first on the chopping block. The team debates whether these cuts were expected, what they mean for cybersecurity, and whether some programs were outside CISA’s core mission in the first place.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.scworld.com/perspective/a-sober-look-at-the-recent-cuts-at-cisa">https://www.scworld.com/perspective/a-sober-look-at-the-recent-cuts-at-cisa</a></p><p></p><p>⚔️ <strong>A sudden shift in cyber warfare strategy</strong>—USCYBERCOM has reportedly been asked to halt offensive cyber operations against Russia. The guys discuss what this means for national security, cyber deterrence, and whether it signals a political deal in the making.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.nbcnews.com/politics/trump-administration/defense-secretary-pete-hegseth-orders-halt-offensive-cyber-operations-rcna194435">https://www.nbcnews.com/politics/trump-administration/defense-secretary-pete-hegseth-orders-halt-offensive-cyber-operations-rcna194435</a></p><p></p><p>💸 <strong>A massive crypto heist exposes software supply chain vulnerabilities.</strong> North Korean attackers allegedly compromised a JavaScript library to drain $1.5 billion. The team breaks down what happened, what it means for the future of crypto security, and whether cybercriminals will use the same techniques elsewhere.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://docsend.com/view/s/rmdi832mpt8u93s7">https://docsend.com/view/s/rmdi832mpt8u93s7</a></p><p></p><p>🔄 <strong>When a company gets hacked, how do CISOs rebuild trust?</strong> The conversation explores the difference between <em>trust</em> and <em>transparency</em>, why some companies handle breaches better than others, and what lessons CISOs can learn from past incidents.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.csoonline.com/article/3825447/how-cisos-can-rebuild-trust-after-a-security-incident.html">https://www.csoonline.com/article/3825447/how-cisos-can-rebuild-trust-after-a-security-incident.html</a></p><p></p><p>🤖 <strong>GenAI tools want access to everything—but should security teams allow it?</strong> The team debates whether CISOs should fight the inevitable, or if they should negotiate smarter ways to control AI access while still allowing business teams to benefit.</p><p></p><p>🎟️ <strong>RSA Conference survival guide!</strong> How do you maximize networking, avoid vendor overload, and make sure the week is productive?</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1925434</link>
      <enclosure url="https://content.rss.com/episodes/110710/1925434/lifeafterciso/2025_03_04_08_34_02_17e8cf41-b5d1-4749-928e-04fc35ff3947.mp3" length="64382317" type="audio/mpeg"/>
      <guid isPermaLink="false">e7ee6687-f106-4d13-8a88-02b3cc74cf9d</guid>
      <itunes:duration>4023</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>18</itunes:episode>
      <podcast:episode>18</podcast:episode>
      <pubDate>Tue, 04 Mar 2025 13:06:42 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1925434/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 17 - 2025 CISO Compensation Survey, Okta layoffs and employee value, TLS inspection]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 17 - 2025 CISO Compensation Survey, Okta layoffs and employee value, TLS inspection]]></itunes:title>
      <description><![CDATA[<p>⬇️ See below for timestamps/summaries/references for each topic</p><p>00:00 Highlight/theme </p><p>00:37 Intro </p><p>1:21 Hitch Partners survey of CISOs </p><p>13:34 Dangling S3 buckets </p><p>24:35 Update on Cybersecurity Innovation Executive Order </p><p>32:58 Cyber stocks - NET and CRWD at all-time highs </p><p>44:07 Okta lays off 180 employees, including security engineers </p><p>55:47 Is anyone actually doing TLS inspection? </p><p>1:03:21 Is a SOC2 certificate enough to pass TPRM?</p><p></p><p><strong>Hitch Partners survey of CISOs</strong></p><p>The 2025 CISO Security Leadership Survey by Hitch Partners highlights key trends in CISO compensation, reporting structures, and industry disparities. Public company CISOs see higher cash compensation and equity growth, with a 6.1% increase year-over-year, while private company CISOs face tighter financial conditions and fewer benefits like D&amp;O insurance. CISOs in larger organizations are less likely to report directly to the CEO, instead aligning with CIOs as company size increases. Compliance, business impact, and ROI are the top budget justification factors, and signing bonuses are more common in public companies. With an average tenure of 39 months, organizations looking to attract top security leaders must focus on competitive compensation, equity incentives, and comprehensive protections.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.hitchpartners.com/ciso-security-leadership-survey-results-25">https://www.hitchpartners.com/ciso-security-leadership-survey-results-25</a></p><p></p><p><strong>Dangling S3 buckets</strong></p><p>watchTowr Labs detailed how they identified approximately 150 abandoned Amazon S3 buckets previously utilized by various organizations, including governments and cybersecurity firms. Upon registering these buckets, they monitored over 8 million HTTP requests within two months, revealing ongoing attempts to access software updates, binaries, and other critical resources.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/">https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/</a></p><p></p><p><strong>Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity</strong> The outgoing Biden administration issues an executive order aimed at enhancing cybersecurity innovation in the U.S. The order focuses on strengthening national cybersecurity infrastructure, promoting technological advancements, and ensuring robust defenses against cyber threats.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.hitchpartners.com/ciso-security-leadership-survey-results-25">https://web.archive.org/web/20250119001804/https://www.whitehouse.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/</a></p><p></p><p><strong>Layoffs at Okta</strong></p><p>On February 4, 2025, Okta, a U.S. access and identity management company, laid off 180 employees, marking its second workforce reduction in just over a year. This follows a previous layoff of approximately 400 employees in February 2024. The Enterprise Security team was affected.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://techcrunch.com/2025/02/04/okta-lays-off-180-employees-nearly-one-year-after-last-workforce-reduction/">https://techcrunch.com/2025/02/04/okta-lays-off-180-employees-nearly-one-year-after-last-workforce-reduction/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1891483</link>
      <enclosure url="https://content.rss.com/episodes/110710/1891483/lifeafterciso/2025_02_11_06_43_44_05b7dbe7-bff7-4a66-9ddd-339a832aba5d.mp3" length="66794360" type="audio/mpeg"/>
      <guid isPermaLink="false">0304045c-c4e5-414e-a44c-f10ded6e3c62</guid>
      <itunes:duration>4174</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>17</itunes:episode>
      <podcast:episode>17</podcast:episode>
      <pubDate>Tue, 11 Feb 2025 13:12:01 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1891483/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 16 - Cyber policy wishlist, RedNote/TikTok, Marsh's cyber insurance report, do CISOs need deep technical skills?]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 16 - Cyber policy wishlist, RedNote/TikTok, Marsh's cyber insurance report, do CISOs need deep technical skills?]]></itunes:title>
      <description><![CDATA[<p>⬇️ See below for timestamps/summaries/references for each topic</p><p>00:00 Intro</p><p>01:33 Biden's Executive Order on Cyber Security</p><p>05:18 Cyber policy wishlist</p><p>21:30 TikTok and RedNote</p><p>29:36 Marsh's report on cyber insurance</p><p>49:21 Do CISOs need to be highly technical?</p><p></p><p><strong>Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity</strong> The outgoing Biden administration issues an executive order aimed at enhancing cybersecurity innovation in the U.S. The order focuses on strengthening national cybersecurity infrastructure, promoting technological advancements, and ensuring robust defenses against cyber threats.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://web.archive.org/web/20250119001804/https://www.whitehouse.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/">https://web.archive.org/web/20250119001804/https://www.whitehouse.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/</a></p><p></p><p><strong>TikTok Refugees Flock to China’s RedNote Amid U.S. Ban Concerns</strong> Following increased scrutiny and potential bans on TikTok in the U.S., over half a million users migrate to China’s RedNote platform. This shift highlights growing concerns over data privacy, national security, and the geopolitical tensions surrounding Chinese-owned apps.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/technology/over-half-million-tiktok-refugees-flock-chinas-rednote-2025-01-14/">https://www.reuters.com/technology/over-half-million-tiktok-refugees-flock-chinas-rednote-2025-01-14/</a></p><p></p><p><strong>Using Cybersecurity Analytics to Prioritize Cybersecurity Investments</strong> This article by Marsh explores how organizations can leverage cybersecurity analytics to make informed decisions about where to allocate resources for maximum impact. By analyzing data on threats, vulnerabilities, and past incidents, businesses can prioritize investments in areas that will most effectively reduce risk and enhance their overall security posture.</p><p>📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.marsh.com/en/services/cyber-risk/insights/using-cybersecurity-analytics-to-prioritize-cybersecurity-investments.html">https://www.marsh.com/en/services/cyber-risk/insights/using-cybersecurity-analytics-to-prioritize-cybersecurity-investments.html</a></p><p></p><p><strong>No, you probably don't need a technical CISO</strong> An article argues that organizations may not necessarily require a highly technical Chief Information Security Officer (CISO). Instead, it emphasizes the importance of leadership, strategic thinking, and the ability to manage risk effectively in the role. 📖 References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/pulse/you-probably-dont-need-technical-ciso-shaun-marion-u0pmc">https://www.linkedin.com/pulse/you-probably-dont-need-technical-ciso-shaun-marion-u0pmc</a></p><p></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1868814</link>
      <enclosure url="https://content.rss.com/episodes/110710/1868814/lifeafterciso/2025_01_28_03_53_36_81581d8c-67b0-4230-9564-5923d12cc60c.mp3" length="62752705" type="audio/mpeg"/>
      <guid isPermaLink="false">b3fd0150-cb8c-45e9-8074-77d51c117651</guid>
      <itunes:duration>3921</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>16</itunes:episode>
      <podcast:episode>16</podcast:episode>
      <pubDate>Tue, 28 Jan 2025 14:24:11 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <itunes:image href="https://media.rss.com/lifeafterciso/ep_cover_20250128_100140_297b10b950ae0bad1040472a69a19a61.png"/>
      <podcast:transcript url="https://transcripts.rss.com/110710/1868814/transcript" type="application/x-subrip"/>
      <podcast:chapters url="https://apollo.rss.com/chapters/1868814" type="application/json+chapters"/>
      <psc:chapters>
        <psc:chapter start="0" title="Intro"/>
        <psc:chapter start="1:33" title="Biden's Executive Order on Cyber Security" image="https://media.rss.com/lifeafterciso/20250128_110157_ce339172c425bd604083742e04a8945f.png"/>
        <psc:chapter start="5:18" title="Cyber Policy Wishlist" image="https://media.rss.com/lifeafterciso/20250128_110120_3563b60dbe6ee8a35a56411007a0b040.png"/>
        <psc:chapter start="21:30" title="TikTok and RedNote" image="https://media.rss.com/lifeafterciso/20250128_110158_e25963552f264a91b8d6067ea1ebdf0c.png"/>
        <psc:chapter start="29:36" title="Marsh's report on cyber insurance" image="https://media.rss.com/lifeafterciso/20250128_110154_de6df787efc926c5f85f3ed67735acdd.png"/>
        <psc:chapter start="49:21" title="Do CISOs need to be highly technical?"/>
      </psc:chapters>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 15 - US-China-Taiwan cyber relations, mobile app ads facilitating spying, holiday DoS vulnerabilities]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 15 - US-China-Taiwan cyber relations, mobile app ads facilitating spying, holiday DoS vulnerabilities]]></itunes:title>
      <description><![CDATA[<p>Join former CISOs Jerry, Mario, and Sounil as they dissect the latest cybersecurity news, discuss evolving threats, and share their seasoned perspectives on infosec. </p><p>00:00 Highlight</p><p>00:32 Intro</p><p>1:48 China accuses US of stealing trade secrets</p><p>10:05 Taiwan reports 2.4M Chinese cyberattacks/day</p><p>18:21 Christmas day Chrome Extension hacks, including Cyberhaven</p><p>23:28 Krebs: U.S. Army Soldier arrested for Snowflake customer extortions</p><p>26:40 Wired: Popular apps hijacked to spy on locations through ad tracking</p><p>33:28 Holiday DoS vulnerabilities in Palo Alto and Windows LDAP</p><p>34:36 Are DoS vulnerabilities neglected by security programs?</p><p>40:37 TI news feeds are noisy and vulnerabilities are overhyped</p><p>49:37 Are Passkeys ready for prime time?</p><p>54:49 Adversarial Podcast YouTube comments </p><p>57:06 YouTube comment cryptowallet scams</p><p>59:24 What should security teams try to accomplish during offsites?</p><p>China Accuses US of Cyberattacks: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/world/china/chinas-internet-emergency-center-says-it-dealt-with-two-us-cyber-attacks-against-2024-12-18/">https://www.reuters.com/world/china/chinas-internet-emergency-center-says-it-dealt-with-two-us-cyber-attacks-against-2024-12-18/</a></p><p>Taiwan Reports 2.4M Chinese Cyberattacks Daily: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/technology/cybersecurity/chinese-cyberattacks-taiwan-government-averaged-24-mln-day-2024-report-says-2025-01-06/">https://www.reuters.com/technology/cybersecurity/chinese-cyberattacks-taiwan-government-averaged-24-mln-day-2024-report-says-2025-01-06/</a></p><p>Christmas Day Chrome Extension Hacks: <a target="_blank" rel="noopener noreferrer nofollow" href="https://thehackernews.com/2024/12/16-chrome-extensions-hacked-exposing.html">https://thehackernews.com/2024/12/16-chrome-extensions-hacked-exposing.html</a> <a target="_blank" rel="noopener noreferrer nofollow" href="https://adversarialgroup.slack.com/archives/C073BTZ6ZSR/p1735336226170729">https://adversarialgroup.slack.com/archives/C073BTZ6ZSR/p1735336226170729</a></p><p>U.S. Army Soldier Arrested for AT&amp;T and Verizon Extortions: <a target="_blank" rel="noopener noreferrer nofollow" href="https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/">https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/</a></p><p>Geo-Data Privacy and App Hijacks: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wired.com/story/gravy-location-data-app-leak-rtb/">https://www.wired.com/story/gravy-location-data-app-leak-rtb/</a></p><p>Holiday DoS Vulnerabilities: <a target="_blank" rel="noopener noreferrer nofollow" href="https://security.paloaltonetworks.com/CVE-2024-3393">https://security.paloaltonetworks.com/CVE-2024-3393</a> <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.securityweek.com/exploit-code-published-for-potentially-dangerous-windows-ldap-vulnerability/">https://www.securityweek.com/exploit-code-published-for-potentially-dangerous-windows-ldap-vulnerability/</a></p><p>Passkeys: Are They Ready for Prime Time: <a target="_blank" rel="noopener noreferrer nofollow" href="https://arstechnica.com/security/2024/12/passkey-technology-is-elegant-but-its-most-definitely-not-usable-security/">https://arstechnica.com/security/2024/12/passkey-technology-is-elegant-but-its-most-definitely-not-usable-security/</a></p><p>Cryptowallet Scams and YouTube Comments: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.kaspersky.com/blog/cryptowallet-free-seed-phrase-scam/52810">https://www.kaspersky.com/blog/cryptowallet-free-seed-phrase-scam/52810</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1846134</link>
      <enclosure url="https://content.rss.com/episodes/110710/1846134/lifeafterciso/2025_01_14_02_09_33_f19ed6b3-e6d9-4cfe-9f82-d521980a4026.mp3" length="64980705" type="audio/mpeg"/>
      <guid isPermaLink="false">d570d52a-fa85-444a-a740-138862b5b6a0</guid>
      <itunes:duration>4061</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>15</itunes:episode>
      <podcast:episode>15</podcast:episode>
      <pubDate>Tue, 14 Jan 2025 12:50:41 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <itunes:image href="https://media.rss.com/lifeafterciso/ep_cover_20250115_030103_f20943dc667b0eaa06c9b2276bb187e2.png"/>
      <podcast:transcript url="https://transcripts.rss.com/110710/1846134/transcript" type="application/x-subrip"/>
      <podcast:chapters url="https://apollo.rss.com/chapters/1846134" type="application/json+chapters"/>
      <psc:chapters>
        <psc:chapter start="1:48" title="China accuses US of stealing trade secrets"/>
        <psc:chapter start="10:05" title="Taiwan reports 2.4M Chinese cyberattacks/day"/>
        <psc:chapter start="18:21" title="Krebs: U.S. Army Soldier arrested for Snowflake customer extortions"/>
        <psc:chapter start="26:40" title="Wired: Popular apps hijacked to spy on locations through ad tracking"/>
        <psc:chapter start="33:28" title="Holiday DoS vulnerabilities in Palo Alto and Windows LDAP"/>
        <psc:chapter start="34:36" title="TI news feeds are noisy and vulnerabilities are overhyped"/>
        <psc:chapter start="40:37" title="TI news feeds are noisy and vulnerabilities are overhyped"/>
        <psc:chapter start="49:37" title="Are Passkeys ready for prime time?"/>
        <psc:chapter start="54:49" title="Adversarial Podcast YouTube comments"/>
        <psc:chapter start="57:06" title="YouTube comment cryptowallet scams"/>
        <psc:chapter start="59:24" title="What should security teams try to accomplish during offsites?"/>
      </psc:chapters>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 14 - Future of CISA/SEC under Trump, US Telco news, DAO faces $50M hack]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 14 - Future of CISA/SEC under Trump, US Telco news, DAO faces $50M hack]]></itunes:title>
      <description><![CDATA[<p>In this episode of <em>The Adversarial Podcast</em>, Jerry Perullo, Mario Duarte, and Sounil Yu discuss the latest developments in cybersecurity, geopolitical threats, and emerging trends as 2025 approaches.</p><p>00:00 Introduction </p><p>02:06 Trump 2.0's effect on security </p><p>03:25 Future of CISA </p><p>09:00 Future of SEC cyber reports </p><p>15:57 Possible Trump 2.0 priorities </p><p>19:40 Spying on US Telco </p><p>20:20 What is SS7? </p><p>24:04 SS7 vs. SMS interception </p><p>25:40 Privacy impact of SS7 attacks </p><p>30:12 National security </p><p>31:17 CISA's guidance for telco </p><p>36:58 DPRK targets DAO network, $50M heist using macOS malware</p><p>46:30 DOJ indicts 14 DPRK nationals </p><p></p><p><strong>The Future of SEC/CISA under Trump 2.0. </strong>With Trump returning to office, the hosts discuss possible changes to SEC-mandated cybersecurity disclosures and the potential of priorities shifting away from CISA as Jenny Easterly’s resignation looms.</p><p>References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cfodive.com/news/sec-cybersecurity-enforcement-outlook-uncertain-as-trump-returns/735728/">https://www.cfodive.com/news/sec-cybersecurity-enforcement-outlook-uncertain-as-trump-returns/735728/</a>, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bankinfosecurity.com/cisa-faces-uncertain-future-under-trump-a-26829">https://www.bankinfosecurity.com/cisa-faces-uncertain-future-under-trump-a-26829</a></p><p></p><p><strong>China, Russia, and Iran spying on US Telco networks.</strong> Adversaries are abusing SS7 vulnerabilities and are hacking into Telco networks to spy on U.S. citizens. The hosts unpack CISA's new recommendations for encrypted communications and discuss the history of SS7 vulnerabilities.</p><p>References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.404media.co/dhs-says-china-russia-iran-and-israel-are-spying-on-people-in-us-with-ss7/">https://www.404media.co/dhs-says-china-russia-iran-and-israel-are-spying-on-people-in-us-with-ss7/</a>, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/technology/cybersecurity/china-affiliated-actors-compromised-networks-multiple-telecom-companies-us-says-2024-11-13/">https://www.reuters.com/technology/cybersecurity/china-affiliated-actors-compromised-networks-multiple-telecom-companies-us-says-2024-11-13/</a>, <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf">https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf</a></p><p></p><p><strong>DPRK Targets macOS hosts in $50M heist from DAO network.</strong> The hosts discuss recent DPRK-aligned Mac malware involved in a $50M cryptocurrency heist. The team discusses the sophistication of the attack, parallels to the attacks against US financial services companies, and why the crypto space remains a goldmine for state-sponsored cybercriminals.</p><p>References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e">https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e</a></p><p></p><p><strong>DOJ indicts 14 DPRK nationals for fraudulent worker scheme and extortions. </strong>We return to the ongoing surge in DPRK-funded actors illegallying work in IT roles within the US using false identities. The hosts unpack raise questions about insider threats and remote work challenges.</p><p>References: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.justice.gov/opa/pr/fourteen-north-korean-nationals-indicted-carrying-out-multi-year-fraudulent-information?&amp;web_view=true">https://www.justice.gov/opa/pr/fourteen-north-korean-nationals-indicted-carrying-out-multi-year-fraudulent-information?&amp;web_view=true</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1813465</link>
      <enclosure url="https://content.rss.com/episodes/110710/1813465/lifeafterciso/2024_12_23_07_39_20_7fdfc15a-b298-4ab6-a2c2-e3d5f941d447.mp3" length="52219588" type="audio/mpeg"/>
      <guid isPermaLink="false">8adb975f-05aa-4b24-961e-fcf737f85468</guid>
      <itunes:duration>3263</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>14</itunes:episode>
      <podcast:episode>14</podcast:episode>
      <pubDate>Mon, 23 Dec 2024 10:20:06 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1813465/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 13 - East/west coast CISOs, top CISO expenses in 2024, crypto regulation]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 13 - East/west coast CISOs, top CISO expenses in 2024, crypto regulation]]></itunes:title>
      <description><![CDATA[<p>In this episode of The Adversarial Podcast, Jerry, Mario, and Sounil bring their adversarial insights to a packed discussion of the latest topics in enterprise cybersecurity. </p><p>- East Coast vs. West Coast CISOs: The trio explores the divide between East Coast and West Coast CISOs. Is the East too focused on risk? Does the West overfit to AppSec and "shift-left" practices? </p><p>- 2024 CISO Budget Report: Where are CISOs spending their increasing budgets in 2024? The hosts chat about the increasing expenses in identity management and generative AI security. Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://news.crunchbase.com/cybersecurity/ciso-budgets-rising-generative-ai-ellis-yl-ventures/">https://news.crunchbase.com/cybersecurity/ciso-budgets-rising-generative-ai-ellis-yl-ventures/</a> </p><p>- AI and Crypto Regulation: A discussion of AI and crypto regulation, emphasizing the need for clarity in regulatory goals while raising questions about their broader implications. </p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/world/us/trump-appoints-former-paypal-coo-david-sacks-ai-crypto-czar-2024-12-06/">https://www.reuters.com/world/us/trump-appoints-former-paypal-coo-david-sacks-ai-crypto-czar-2024-12-06/</a> </p><p>- The GitHub Security Gap: The hosts discuss securing GitHub environments in increasingly BYOD environments. </p><p>- Pegasus Malware: The group examines modern attack vectors, from sophisticated supply chain threats to Pegasus malware's unexpected victims. </p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/endpoint-security/pegasus-spyware-infections-ios-android-devices">https://www.darkreading.com/endpoint-security/pegasus-spyware-infections-ios-android-devices</a> </p><p>- Deep Fakes and Vishing: Staying on the topic of mobile attacks, the hosts debate how to best hinder deep fake-powered vishing attacks. </p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.nasdaq.com/articles/scammers-are-using-low-tech-tactic-access-peoples-bank-accounts">https://www.nasdaq.com/articles/scammers-are-using-low-tech-tactic-access-peoples-bank-accounts</a> </p><p>- South Korean CEO arrested for adding DDoS feature to satellite receivers: A discussion of a recent story involving supply chain injection of DDoS features in Korea. </p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/">https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1794678</link>
      <enclosure url="https://content.rss.com/episodes/110710/1794678/lifeafterciso/2024_12_10_07_41_58_e5850f56-c9cb-4152-8d38-32fd9166937c.mp3" length="69317463" type="audio/mpeg"/>
      <guid isPermaLink="false">a8e9ec67-c557-4415-8977-a430e4d64073</guid>
      <itunes:duration>4332</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <pubDate>Tue, 10 Dec 2024 19:43:53 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1794678/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 12 - RSA Conference making competition winners accept investment, inefficacy of phishing training]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 12 - RSA Conference making competition winners accept investment, inefficacy of phishing training]]></itunes:title>
      <description><![CDATA[<p>In this episode of <em>The Adversarial Podcast</em>, former CISOs Jerry Perullo, Mario Duarte, and Sounil Yu explore critical topics shaping the cybersecurity landscape.</p><p><strong>1. Crosspoint Capital’s RSA Innovation Sandbox Model</strong> The hosts discuss Crosspoint Capital's controversial $5 million SAFE investment requirement for Innovation Sandbox finalists. They examine the implications for startups, founders, and the cybersecurity ecosystem as a whole, weighing its potential to drive innovation against the risks of stifling participation.</p><p>Reference: RSA’s Innovation Sandbox: Cybersecurity Startups Must Accept $5 Million Investment - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.securityweek.com/rsa-conference-will-take-equity-in-innovation-sandbox-startup-finalists/">https://www.securityweek.com/rsa-conference-will-take-equity-in-innovation-sandbox-startup-finalists/</a></p><p><strong>2. The Effectiveness of Phishing Simulations and Training</strong> Phishing simulations are dissected, from their role in training effectiveness to their limitations. The hosts share personal experiences, propose smarter testing methods, and stress the need for customized, relevant security awareness programs.</p><p>Reference: Understanding the Efficacy of Phishing Training in Practice - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.computer.org/csdl/proceedings-article/sp/2025/223600a076/21B7RjYyG9q">https://www.computer.org/csdl/proceedings-article/sp/2025/223600a076/21B7RjYyG9q</a></p><p><strong>3. Insights from a CISA Red Team Report</strong> A recent CISA red team assessment of critical infrastructure prompts discussions on systemic security flaws, logging and monitoring challenges, and the importance of infrastructure segmentation. The team critiques current approaches and highlights the risks of improper cleanup after penetration testing.</p><p>Reference: Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-326a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-326a</a></p><p><strong>4. Cookie Theft and FBI Warnings</strong> The conversation shifts to session cookie theft, a rising threat targeting big identity providers like Google and Microsoft. The hosts explore technical solutions like device-bound session cookies and discuss why such attacks bypass MFA, affecting both enterprises and public users.</p><p>Reference: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.fbi.gov/contact-us/field-offices/atlanta/news/cybercriminals-are-stealing-cookies-to-bypass-multifactor-authentication">https://www.fbi.gov/contact-us/field-offices/atlanta/news/cybercriminals-are-stealing-cookies-to-bypass-multifactor-authentication</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1772098</link>
      <enclosure url="https://content.rss.com/episodes/110710/1772098/lifeafterciso/2024_11_26_06_38_35_cfdad4b5-cda0-4613-9749-246ce1118025.mp3" length="68744871" type="audio/mpeg"/>
      <guid isPermaLink="false">62626a1f-16ba-49f6-ab51-2a8f9633e2d5</guid>
      <itunes:duration>4296</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <pubDate>Tue, 26 Nov 2024 12:19:45 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1772098/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 11 - Incoming Trump administration, Microsoft's leaked SaaS creds, and software liability policy]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 11 - Incoming Trump administration, Microsoft's leaked SaaS creds, and software liability policy]]></itunes:title>
      <description><![CDATA[<p><strong>Introduction</strong>:</p><ul><li>The episode opens with a discussion on securing devices for employees traveling to high-risk countries, like China, as a way to protect corporate data and maintain customer trust.</li><li>Hosts Jerry, Sounil, and Mario welcome listeners and discuss recent events, including the FS-ISAC Fall Summit in Atlanta and geopolitical implications of the recent election.</li></ul><p><strong>Key Topics</strong>:</p><ol><li><strong>Geopolitical Risks</strong>:<ul><li>The group explores China's espionage activities and Russia's geopolitical maneuvers, predicting shifts in attacker strategies depending on U.S. political leadership.</li><li>Concerns about China's possible invasion of Taiwan and its implications for global tech, particularly chip manufacturing, are highlighted.</li></ul></li><li><strong>Cybersecurity and Crypto</strong>:<ul><li>The hosts discuss the post-election stock market bump, particularly in the tech and crypto sectors, and note the growing reliance on platforms like Coinbase.</li><li>They debate the perception and reality of cryptocurrency stability.</li></ul></li><li><strong>Travel Security Policies</strong>:<ul><li>The panel critiques outdated views on China-focused security policies and suggests broadening these policies to apply to all non-extradition countries.</li><li>Anecdotes on “burner laptops” and espionage myths are shared, emphasizing a need for realistic threat modeling.</li></ul></li><li><strong>InfoStealers and SaaS Security</strong>:<ul><li>Rising threats from InfoStealer malware, which targets stored credentials, are explored.</li><li>A specific case involving Snowflake and ServiceNow platforms highlights vulnerabilities tied to single-factor authentication and API misuse.</li><li>Debate on whether such findings should be within the scope of bug bounty programs arises.</li></ul></li><li><strong>Shift Toward Hybrid and On-Prem Models</strong>:<ul><li>Discussion on whether critical applications are moving back on-premises due to high cloud costs, especially for AI workloads.</li><li>The hosts argue the shift is likely economic rather than security-driven.</li></ul></li><li><strong>EU Product Liability Directive</strong>:<ul><li>The EU’s new directive introduces potential liability for software developers and companies, even extending to individual coders.</li><li>The implications for open source and global software markets are debated, with concerns about increased costs for doing business in the EU.</li></ul></li><li><strong>CrowdStrike vs. Delta Lawsuit</strong>:<ul><li>The CrowdStrike-Delta legal battle is analyzed, focusing on issues like the discovery of risk registers and internal chats, and how this might expose Delta's cybersecurity weaknesses.</li><li>Potential ripple effects for CrowdStrike's reputation and customer base are considered.</li></ul></li></ol><p><strong>Closing Thoughts</strong>:</p><ul><li>The episode ends with reflections on regulatory landscapes, including GDPR and how enforcement levels shape software innovation and compliance strategies.</li><li>The hosts tease ongoing developments in the CrowdStrike case as a topic to watch closely.</li></ul><p>This episode combines high-level geopolitical discussions with detailed analysis of pressing cybersecurity trends, offering a mix of technical insights and industry perspectives.</p><p></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1760931</link>
      <enclosure url="https://content.rss.com/episodes/110710/1760931/lifeafterciso/2024_11_19_06_32_26_78a31a25-387b-4ce5-b76d-fbd175651b4b.mp3" length="51448048" type="audio/mpeg"/>
      <guid isPermaLink="false">24445614-425e-4bcd-ba0e-08cb719afc70</guid>
      <itunes:duration>3215</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <pubDate>Tue, 19 Nov 2024 12:21:10 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1760931/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 10 - the CISO job market, CRQ, beg bounties, and cryptography]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 10 - the CISO job market, CRQ, beg bounties, and cryptography]]></itunes:title>
      <description><![CDATA[<p>(00:00) Intro </p><p>(5:15) The CISO job market: present and future </p><p>(25:57) Handling beg bounties and VDP </p><p>(41:30) Quantum cryptography – how important is cryptography, really?  </p><p></p><p>Stories: </p><ul><li>“Chinese Researchers Reportedly Crack Encryption With Quantum Computer” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.pcmag.com/news/chinese-researchers-reportedly-crack-encryption-with-quantum-computer">https://www.pcmag.com/news/chinese-researchers-reportedly-crack-encryption-with-quantum-computer</a>  </li></ul><p></p><p>Hosts:</p><ul><li>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a></li><li>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a></li><li>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></li></ul><p>Producer: Tillson Galloway (<a target="_blank" rel="noopener noreferrer nofollow" href="http://linkedin.com/in/tillson">linkedin.com/in/tillson</a>)</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1714449</link>
      <enclosure url="https://content.rss.com/episodes/110710/1714449/lifeafterciso/2024_10_22_06_11_50_bd4caad5-c235-430c-bf24-1c0257ca06f3.mp3" length="52689361" type="audio/mpeg"/>
      <guid isPermaLink="false">2db2dedc-4284-4be0-a4f8-65a35dccfd35</guid>
      <itunes:duration>3293</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <pubDate>Tue, 22 Oct 2024 08:20:07 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1714449/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 9 - NIST password guidelines, CUPS vulnerabilities, breach vs. hack]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 9 - NIST password guidelines, CUPS vulnerabilities, breach vs. hack]]></itunes:title>
      <description><![CDATA[<p>(00:00) Intro &amp; NIST’s new password complexity requirements</p><p>(13:19) CUPS vulnerability: critical or a distraction</p><p>(31:26) Federal standards for cybersecurity in health care: should legal responsibility fall on individuals?</p><p>(47:30) What constitutes a hack vs a breach?</p><p></p><p>Stories:</p><ul><li>“NIST Drops Password Complexity, Mandatory Reset Rules” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/identity-access-management-security/nist-drops-password-complexity-mandatory-reset-rules">https://www.darkreading.com/identity-access-management-security/nist-drops-password-complexity-mandatory-reset-rules</a></li><li>“Critical Linux CUPS Printing System Flaws Could Allow Remote Command Execution” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://thehackernews.com/2024/09/critical-linux-cups-printing-system.html">https://thehackernews.com/2024/09/critical-linux-cups-printing-system.html</a></li><li>“Wyden and Warner Introduce Bill to Set Strong Cybersecurity Standards for American Health Care System” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.finance.senate.gov/chairmans-news/wyden-and-warner-introduce-bill-to-set-strong-cybersecurity-standards-for-american-health-care-system">https://www.finance.senate.gov/chairmans-news/wyden-and-warner-introduce-bill-to-set-strong-cybersecurity-standards-for-american-health-care-system</a></li></ul><p></p><p>Hosts:</p><ul><li>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a></li><li>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a></li><li>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></li></ul>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1691634</link>
      <enclosure url="https://content.rss.com/episodes/110710/1691634/lifeafterciso/2024_10_10_05_26_42_38ee85eb-8ce1-47f9-b8f4-cf24b7da3e92.mp3" length="58832107" type="audio/mpeg"/>
      <guid isPermaLink="false">25abf5e6-add4-4ba0-9219-2c2d00b44492</guid>
      <itunes:duration>3676</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <pubDate>Tue, 08 Oct 2024 07:10:21 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1691634/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 8 - Pagers and Supply Chain Attacks, GitHub stealers, “Founder Mode”]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 8 - Pagers and Supply Chain Attacks, GitHub stealers, “Founder Mode”]]></itunes:title>
      <description><![CDATA[<p>(00:00) Intro </p><p>(02:24) Exploding pagers: are psychological attacks worse than breaches? </p><p>(20:21) Are credit card breaches still a concern in 2024? </p><p>(24:57) Infostealer delivered through GitHub Issues: how are trustworthy services being abused? </p><p>(31:45) Founder mode: when is it time to switch from "founder mode" to "manager mode?"</p><p>(44:02) Is open-source more secure than closed-source? </p><p></p><p>Stories and books mentioned: </p><ul><li>“Israel planted explosives in Hezbollah's Taiwan-made pagers, say sources” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/world/middle-east/israel-planted-explosives-hezbollahs-taiwan-made-pagers-say-sources-2024-09-18/">https://www.reuters.com/world/middle-east/israel-planted-explosives-hezbollahs-taiwan-made-pagers-say-sources-2024-09-18/</a> </li><li>Darkwire, by Joseph Cox - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691/?lens=publicaffairs">https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691/?lens=publicaffairs</a> </li><li>Kingpin, by Kevin Poulsen - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.kingpin.cc/">https://www.kingpin.cc/</a> </li><li>“Clever 'GitHub Scanner' campaign abusing repos to push malware” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bleepingcomputer.com/news/security/clever-github-scanner-campaign-abusing-repos-to-push-malware/">https://www.bleepingcomputer.com/news/security/clever-github-scanner-campaign-abusing-repos-to-push-malware/</a> </li><li>“Founder Mode” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://paulgraham.com/foundermode.html">https://paulgraham.com/foundermode.html</a> </li><li>“On Pioneers, Settlers, Town Planners and Theft” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.gardeviance.org/2015/03/on-pioneers-settlers-town-planners-and.html">https://blog.gardeviance.org/2015/03/on-pioneers-settlers-town-planners-and.html</a> </li></ul><p></p><p>Hosts: </p><ul><li>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a> </li><li>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a> </li><li>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></li></ul>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1669854</link>
      <enclosure url="https://content.rss.com/episodes/110710/1669854/lifeafterciso/2024_09_24_07_40_21_2cb3066f-6bd7-498e-8f34-bac916a825ab.mp3" length="54909560" type="audio/mpeg"/>
      <guid isPermaLink="false">47ef2f0b-c5b5-4aac-805c-3dad0849876d</guid>
      <itunes:duration>3431</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <pubDate>Tue, 24 Sep 2024 13:15:45 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1669854/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 7 - Security Certs, Vulnerability Disclosure, and Effective Security Controls]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 7 - Security Certs, Vulnerability Disclosure, and Effective Security Controls]]></itunes:title>
      <description><![CDATA[<p>Listen as CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss the value of security exams and question the relevance of certain certifications in today’s industry. Then, they debate into the vulnerability disclosure process, exploring how CVEs impact companies outside the SaaS world and whether CISA’s "Secure by Design" initiative is truly effective across industries. Finally, they discuss security misprioritization, from school systems to corporate desktops, and the evolving role of account management in protecting digital crown jewels.</p><p></p><p>Stories</p><ul><li>LinkedIn Post on ISC2 exams - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/posts/mlockhart_hate-to-see-how-isc2-has-devolved-over-the-activity-7234368996647604225-tKVp">https://www.linkedin.com/posts/mlockhart_hate-to-see-how-isc2-has-devolved-over-the-activity-7234368996647604225-tKVp</a></li></ul><ul><li>“Is the vulnerability disclosure process glitched? How CISOs are being left in the dark” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.csoonline.com/article/3491353/is-the-vulnerability-disclosure-process-a-glitch-in-itself-how-cisos-are-being-left-in-the-dark.html">https://www.csoonline.com/article/3491353/is-the-vulnerability-disclosure-process-a-glitch-in-itself-how-cisos-are-being-left-in-the-dark.html</a></li><li>LinkedIn Post on Chrome DevTools blocked in schools - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/posts/perullo_im-lucky-enough-to-have-my-6th-grade-daughter-activity-7237092980996632577-5T62">https://www.linkedin.com/posts/perullo_im-lucky-enough-to-have-my-6th-grade-daughter-activity-7237092980996632577-5T62</a></li></ul><p></p><p>00:00 Intro</p><p>01:00 ISC2 Exams</p><p>20:39 VDP and Secure by Design</p><p>35:29 Security controls</p><p>49:06 Admin accounts</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1653612</link>
      <enclosure url="https://content.rss.com/episodes/110710/1653612/lifeafterciso/2024_09_12_05_30_59_496f5ade-792d-4e80-8ad3-4d38730e984a.mp3" length="64311552" type="audio/mpeg"/>
      <guid isPermaLink="false">79b788f8-7d44-4c61-a920-1a3a2b565831</guid>
      <itunes:duration>4019</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <pubDate>Thu, 12 Sep 2024 12:16:34 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1653612/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 6 - SSN Leaks, Cloud Misconfigurations, and Passkeys]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 6 - SSN Leaks, Cloud Misconfigurations, and Passkeys]]></itunes:title>
      <description><![CDATA[<p>Join former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu as they debate the impact of SSN leaks, discuss the effectiveness of recently implemented ransom payment bans in Miami, and recently reported AWS misconfigurations. Then, listen as they debate passkeys, vulnerability management, and board reporting.</p><p></p><p>00:00 Intro </p><p>02:17 Social Security Number breach </p><p>14:48 Ransomware payment bans </p><p>21:47 AWS environments </p><p>39:55 Passkeys </p><p>52:30 Maturity assessments</p><p></p><p>Stories: </p><ul><li>“2.9 billion people may have had Social Security numbers, other financial data compromised. What it means for you” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cnbc.com/2024/08/15/billions-people-social-security-numbers-and-data-stolen-allegedly.html">https://www.cnbc.com/2024/08/15/billions-people-social-security-numbers-and-data-stolen-allegedly.html</a> </li><li>“Hack on North Miami Tests Ransom Payment Bans” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/articles/hack-on-north-miami-tests-ransom-payment-bans-077be398">https://www.wsj.com/articles/hack-on-north-miami-tests-ransom-payment-bans-077be398</a> </li><li>“AWS environments compromised through exposed .env files” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.csoonline.com/article/3488207/aws-environments-compromised-through-exposed-env-files.html">https://www.csoonline.com/article/3488207/aws-environments-compromised-through-exposed-env-files.html</a> </li><li>"An AWS Configuration Issue Could Expose Thousands of Web Apps" - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wired.com/story/aws-application-load-balancer-implementation-compromise/">https://www.wired.com/story/aws-application-load-balancer-implementation-compromise/</a></li></ul><p></p><p>Hosts: </p><p>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a> </p><p>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a> </p><p>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1627363</link>
      <enclosure url="https://content.rss.com/episodes/110710/1627363/lifeafterciso/2024_08_26_04_34_48_1334dd51-3e5c-4782-8952-b4cbae3009c8.mp3" length="62246834" type="audio/mpeg"/>
      <guid isPermaLink="false">e9f52c91-c3fe-4b4b-9113-a55cc4c49ce8</guid>
      <itunes:duration>3890</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <pubDate>Mon, 26 Aug 2024 06:40:34 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1627363/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 5 - Why Boards want more Joe Sullivans and Tim Browns and less CISOs - Jerry Perullo live at Evanta]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 5 - Why Boards want more Joe Sullivans and Tim Browns and less CISOs - Jerry Perullo live at Evanta]]></itunes:title>
      <description><![CDATA[<p>Speaking live at the Evanta CISO Summit in Atlanta in June 2024, host Jerry Perullo talks candidly about why CISOs are failing to land Board Director roles.</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1614884</link>
      <enclosure url="https://content.rss.com/episodes/110710/1614884/lifeafterciso/2024_08_16_17_03_07_e308f0cc-0ec0-4b0c-80c7-f9bf3ee7b5f4.mp3" length="25613418" type="audio/mpeg"/>
      <guid isPermaLink="false">5179b7cd-6a72-4a34-8e60-7baab65d75ef</guid>
      <itunes:duration>1600</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <pubDate>Fri, 16 Aug 2024 17:03:53 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1614884/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 4 - CrowdStrike Lawsuits, Overhyped Exploits, and Fake Remote Employees]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 4 - CrowdStrike Lawsuits, Overhyped Exploits, and Fake Remote Employees]]></itunes:title>
      <description><![CDATA[<p>Join former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu as they discuss upcoming lawsuits related to the recent CrowdStrike outage, switching costs, overhyped security vulnerabilities and their effect on practitioners' responsibilities, fake employees from North Korea, the information stealers and the state of password managers, and the increasing threat of deepfakes.</p><p></p><p>Stories</p><ul><li>“CrowdStrike is sued by shareholders over huge software outage” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reuters.com/legal/crowdstrike-is-sued-by-shareholders-over-huge-software-outage-2024-07-31/">https://www.reuters.com/legal/crowdstrike-is-sued-by-shareholders-over-huge-software-outage-2024-07-31/</a></li><li>“Delta CEO says CrowdStrike-Microsoft outage cost the airline $500 million” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cnbc.com/2024/07/31/delta-ceo-crowdstrike-microsoft-outage-cost-the-airline-500-million.html">https://www.cnbc.com/2024/07/31/delta-ceo-crowdstrike-microsoft-outage-cost-the-airline-500-million.html</a></li><li>“Microsoft And AWS Outages: A Wake-Up Call For Cloud Dependency“ - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.forbes.com/sites/emilsayegh/2024/07/31/microsoft-and-aws-outages-a-wake-up-call-for-cloud-dependency/">https://www.forbes.com/sites/emilsayegh/2024/07/31/microsoft-and-aws-outages-a-wake-up-call-for-cloud-dependency/</a></li><li>“Microsoft confirms Azure, 365 outage linked to DDoS attack” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cybersecuritydive.com/news/microsoft-azure-365-outage-ddos/722920/">https://www.cybersecuritydive.com/news/microsoft-azure-365-outage-ddos/722920/</a></li><li>“Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/endpoint-security/millions-of-devices-vulnerable-to-pkfail-secure-boot-bypass-issue">https://www.darkreading.com/endpoint-security/millions-of-devices-vulnerable-to-pkfail-secure-boot-bypass-issue</a></li><li>“Who Knew? Domain Hijacking Is So Easy” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/">https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/</a></li><li>“Security Firm Alarmed to Discover Their Remote Employee Is a North Korean Hacker” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://futurism.com/the-byte/security-firm-remote-employee-north-korean-hacker">https://futurism.com/the-byte/security-firm-remote-employee-north-korean-hacker</a></li><li>“The Evolution and Rise of Stealer Malware” (Josh Lefowitz/Flashpoint) <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/posts/activity-7209733860715098114-ZgYQ">https://www.linkedin.com/posts/activity-7209733860715098114-ZgYQ</a> / <a target="_blank" rel="noopener noreferrer nofollow" href="https://flashpoint.io/blog/evolution-stealer-malware/">https://flashpoint.io/blog/evolution-stealer-malware/</a></li><li>‘I Need to Identify You': How One Question Saved Ferrari From a Deepfake Scam - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo">https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo</a></li><li>“AI-Powered Deepfake Tools Becoming More Accessible Than Ever” - <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.trendmicro.com/en_us/research/24/g/ai-deepfake-cybercrime.html">https://www.trendmicro.com/en_us/research/24/g/ai-deepfake-cybercrime.html</a></li></ul>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1598753</link>
      <enclosure url="https://content.rss.com/episodes/110710/1598753/lifeafterciso/2024_08_05_06_09_34_a29d68a0-3a43-42b9-aabe-65ac45b8a4ad.mp3" length="82873537" type="audio/mpeg"/>
      <guid isPermaLink="false">d0b99116-7be9-40e0-807a-a524dd00a449</guid>
      <itunes:duration>5179</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <pubDate>Mon, 05 Aug 2024 11:30:25 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1598753/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 3 - CrowdStrike, Wiz Acquisition Rumors, and SolarWinds]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 3 - CrowdStrike, Wiz Acquisition Rumors, and SolarWinds]]></itunes:title>
      <description><![CDATA[<p>In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss the recent Crowdstrike outages, PR in the recent Wiz acquisition rumors, stakeholder value in Rapid7, and the SEC dropping charges in the SolarWinds case.</p><p></p><p>Stories: </p><p>- Activist Jana has a stake in Rapid7. There are two paths to bolster value at the cybersecurity company: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cnbc.com/2024/06/29/two-paths-for-jana-to-bolster-shareholder-value-at-rapid7.html">https://www.cnbc.com/2024/06/29/two-paths-for-jana-to-bolster-shareholder-value-at-rapid7.html</a> </p><p>- Google Near $23 Billion Deal for Cybersecurity Startup Wiz: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.wsj.com/business/deals/google-near-23-billion-deal-for-cybersecurity-startup-wiz-622edf1a">https://www.wsj.com/business/deals/google-near-23-billion-deal-for-cybersecurity-startup-wiz-622edf1a</a> </p><p>- Most SEC charges dismissed in SolarWinds hack case: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.axios.com/2024/07/18/sec-solarwinds-cyberattack-case-dismissal">https://www.axios.com/2024/07/18/sec-solarwinds-cyberattack-case-dismissal</a> </p><p></p><p>Hosts: </p><p>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a> </p><p>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a> </p><p>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1583519</link>
      <enclosure url="https://content.rss.com/episodes/110710/1583519/lifeafterciso/2024_07_26_07_34_56_b3f6f858-ce0a-4d06-9c08-a04533d54c79.mp3" length="72365208" type="audio/mpeg"/>
      <guid isPermaLink="false">cd1edd87-19d7-4e37-8bc3-3228febd0ec4</guid>
      <itunes:duration>4522</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <pubDate>Fri, 26 Jul 2024 10:58:07 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1583519/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 2 - Chrome Extension Vulns, Cyber Job Market, Mouse Jigglers, and the Ransomware Plague]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 2 - Chrome Extension Vulns, Cyber Job Market, Mouse Jigglers, and the Ransomware Plague]]></itunes:title>
      <description><![CDATA[<p>In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss malicious Chrome extensions, the cybersecurity job market, mouse jigglers and security policy, and the impact of the recent ransomware wave. They share insights from their experiences, exploring the challenges of managing browser security policies, job burnout, and banning ransom payments.</p><p>Stories:</p><ul><li><strong>Millions under threat from malicious browser extensions — what to do: </strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.tomsguide.com/news/millions-under-threat-from-malicious-browser-extensions-what-to-do">https://www.tomsguide.com/news/millions-under-threat-from-malicious-browser-extensions-what-to-do</a></li></ul><p></p><ul><li><strong>Demand for better cybersecurity fuels a booming job market</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.washingtonpost.com/business/2024/06/21/cybersecurity-job-demand-boot-camps/">https://www.washingtonpost.com/business/2024/06/21/cybersecurity-job-demand-boot-camps/</a></li></ul><p></p><ul><li><strong>Wells Fargo Fires Over a Dozen for ‘Simulation of Keyboard Activity’</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.bloomberg.com/news/articles/2024-06-13/wells-fires-over-a-dozen-for-simulation-of-keyboard-activity">https://www.bloomberg.com/news/articles/2024-06-13/wells-fires-over-a-dozen-for-simulation-of-keyboard-activity</a></li></ul><p></p><ul><li><strong>London hospitals cancel nearly 1,600 operations and appointments in one week due to hack: </strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.theguardian.com/technology/article/2024/jun/14/london-hospitals-cancelled-nearly-1600-operations-and-appointments-in-one-week-due-to-hack">https://www.theguardian.com/technology/article/2024/jun/14/london-hospitals-cancelled-nearly-1600-operations-and-appointments-in-one-week-due-to-hack</a></li></ul><p></p><ul><li><strong>Cyberattacks crippled thousands of car dealers. Here's what to know. </strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.washingtonpost.com/business/2024/06/21/car-dealers-cyberattack-cdk-global/">https://www.washingtonpost.com/business/2024/06/21/car-dealers-cyberattack-cdk-global/</a></li></ul><p></p><ul><li><strong>Ticketmaster hackers send death threats to cybercrime investigators: </strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.thetimes.com/uk/technology-uk/article/ticketmaster-hackers-death-threats-cybercrime-unc5537-msjgqw92w">https://www.thetimes.com/uk/technology-uk/article/ticketmaster-hackers-death-threats-cybercrime-unc5537-msjgqw92w</a></li></ul><p></p><ul><li><strong>CVE-2024-5806: Progress MOVEit Transfer Authentication Bypass Vulnerability</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.tenable.com/blog/cve-2024-5806-progress-moveit-transfer-authentication-bypass-vulnerability">https://www.tenable.com/blog/cve-2024-5806-progress-moveit-transfer-authentication-bypass-vulnerability</a></li></ul><p></p><p>Hosts:</p><p>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a></p><p>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a></p><p>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1562685</link>
      <enclosure url="https://content.rss.com/episodes/110710/1562685/lifeafterciso/2024_07_10_05_57_48_98b7a335-a337-4b98-8226-b244372f4295.mp3" length="60254840" type="audio/mpeg"/>
      <guid isPermaLink="false">9e389c29-bd6c-4dc3-b84c-8af763b892df</guid>
      <itunes:duration>3765</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <pubDate>Wed, 10 Jul 2024 14:00:45 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1562685/transcript" type="application/x-subrip"/>
      <podcast:chapters url="https://apollo.rss.com/chapters/1562685" type="application/json+chapters"/>
      <psc:chapters>
        <psc:chapter start="0" title="Introduction"/>
        <psc:chapter start="42" title="Malicious browser extensions"/>
        <psc:chapter start="11:09" title="Cybersecurity job market"/>
        <psc:chapter start="29:37" title="Mouse jigglers"/>
        <psc:chapter start="38:02" title="Ransomware"/>
        <psc:chapter start="56:14" title="MoveIT Vulnerability"/>
      </psc:chapters>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Pilot – Cybersecurity Investments, Secure Configurations vs. Code, and Risk Management]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Pilot – Cybersecurity Investments, Secure Configurations vs. Code, and Risk Management]]></itunes:title>
      <description><![CDATA[<p>Join former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu as they reflect on the state of cybersecurity investments in 2024, debate the importance of configuration vs. code security, and discuss the importance of governance in risk management.</p><p></p><p>Stories:</p><ul><li><strong>‘There’s A Lot Of Noise’ — VCs Trying To Find Clarity In Cluttered Cyber AI Landscape</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://news.crunchbase.com/cybersecurity/venture-funding-ai-wiz-ma-rsa/">https://news.crunchbase.com/cybersecurity/venture-funding-ai-wiz-ma-rsa/</a></li><li><strong>Wiz raises $1B at a $12B valuation to expand its cloud security platform through acquisitions</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://techcrunch.com/2024/05/07/wiz-raises-1b-at-12b-valuation-expanding-through-acquisitions/">https://techcrunch.com/2024/05/07/wiz-raises-1b-at-12b-valuation-expanding-through-acquisitions/</a></li><li><strong>CyberArk Signs Definitive Agreement to Acquire Machine Identity Management Leader Venafi from Thoma Bravo</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.cyberark.com/press/cyberark-signs-definitive-agreement-to-acquire-machine-identity-management-leader-venafi-from-thoma-bravo/">https://www.cyberark.com/press/cyberark-signs-definitive-agreement-to-acquire-machine-identity-management-leader-venafi-from-thoma-bravo/</a></li><li><strong>A review of zero-day in-the-wild exploits in 2023</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://blog.google/technology/safety-security/a-review-of-zero-day-in-the-wild-exploits-in-2023/">https://blog.google/technology/safety-security/a-review-of-zero-day-in-the-wild-exploits-in-2023/</a></li></ul><p></p><p>Hosts:</p><p>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a></p><p>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a></p><p>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1548277</link>
      <enclosure url="https://content.rss.com/episodes/110710/1548277/lifeafterciso/2024_06_28_10_04_47_54bc430c-a342-48d5-a4fa-6891abd58e06.mp3" length="46783180" type="audio/mpeg"/>
      <guid isPermaLink="false">8128391e-0203-4710-bf77-5aa69a5c8bb9</guid>
      <itunes:duration>2923</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <pubDate>Fri, 19 Jul 2024 05:00:51 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1548277/transcript" type="application/x-subrip"/>
    </item>
    <item>
      <title><![CDATA[The Adversarial Podcast Ep. 1 - Snowflake, Shared Fate, and the Gili Ra’anan Model]]></title>
      <itunes:title><![CDATA[The Adversarial Podcast Ep. 1 - Snowflake, Shared Fate, and the Gili Ra’anan Model]]></itunes:title>
      <description><![CDATA[<p>In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss the recent wave of cyber-attacks using Snowflake and the model of shared fate. They debate the effectiveness of banning ransom payments and explore the complexities of cybersecurity regulation, using recent events involving UnitedHealth and Jerry's former employer as case studies. The conversation also touches on the ethical dilemmas CISOs face when interacting with venture capital, highlighting personal experiences and the fine line between advisory roles and conflicts of interest.</p><p></p><p>Stories:</p><ul><li><strong>UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion">https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion</a></li><li><strong>SEC Charges Intercontinental Exchange and Nine Affiliates Including the New York Stock Exchange with Failing to Inform the Commission of a Cyber Intrusion</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.sec.gov/news/press-release/2024-63">https://www.sec.gov/news/press-release/2024-63</a></li><li><strong>Why cybercriminals are targeting small businesses</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.marketplace.org/2024/05/30/why-cybercriminals-are-targeting-small-businesses/">https://www.marketplace.org/2024/05/30/why-cybercriminals-are-targeting-small-businesses/</a></li><li><strong>UnitedHealth leaders 'should be held responsible' for installing inexperienced CISO, senator says</strong>: <a target="_blank" rel="noopener noreferrer nofollow" href="https://therecord.media/unitedhealth-ciso-wyden-letter-sec-ftc">https://therecord.media/unitedhealth-ciso-wyden-letter-sec-ftc</a></li><li><strong>The Gili Ra’anan model: Questions emerging from Cyberstarts' remarkable success: </strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.calcalistech.com/ctechnews/article/b1a1jn00hc">https://www.calcalistech.com/ctechnews/article/b1a1jn00hc</a></li></ul><p></p><p>Hosts:</p><p>Jerry Perullo: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/perullo/">https://www.linkedin.com/in/perullo/</a></p><p>Mario Duarte: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/mario-duarte-7855237/">https://www.linkedin.com/in/mario-duarte-7855237/</a></p><p>Sounil Yu: <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/sounil/">https://www.linkedin.com/in/sounil/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1548281</link>
      <enclosure url="https://content.rss.com/episodes/110710/1548281/lifeafterciso/2024_06_28_10_07_35_d4837d0f-af71-4af0-af52-a3925ceaeeba.mp3" length="69852049" type="audio/mpeg"/>
      <guid isPermaLink="false">5ee23117-a217-479e-a9b8-5751f7df744e</guid>
      <itunes:duration>4365</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <pubDate>Mon, 01 Jul 2024 11:30:25 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1548281/transcript" type="application/x-subrip"/>
      <podcast:chapters url="https://apollo.rss.com/chapters/1548281" type="application/json+chapters"/>
      <psc:chapters>
        <psc:chapter start="0" title="Intro"/>
        <psc:chapter start="1:16" title="Snowflake and Shared Fate"/>
        <psc:chapter start="20:51" title="SEC Fines for Cyber Intrusion Reporting"/>
        <psc:chapter start="31:11" title="Cybercriminals Target Small Businesses"/>
        <psc:chapter start="42:41" title="Responsibility with CISO vs. Board"/>
        <psc:chapter start="53:41" title="The Gili Ra’anan model and Conflicts of Interest"/>
      </psc:chapters>
    </item>
    <item>
      <title><![CDATA[Season 02 Episode 02 - The Interim CISO]]></title>
      <itunes:title><![CDATA[Season 02 Episode 02 - The Interim CISO]]></itunes:title>
      <description><![CDATA[<p>Joined by fellow Interim CISO veterans Yael Nagler of Yass Partners and Aurobindo Sundaram of RELX, host Jerry Perullo reflects on his experience as the Interim CISO of Silicon Valley Bank and explores the challenges of the role from hiring manager and candidate perspectives.</p><p>Yael Nagler: <a href="https://www.linkedin.com/in/yaelnagler/">https://www.linkedin.com/in/yaelnagler/</a></p><p>Aurobindo Sundaram: <a href="https://www.linkedin.com/in/aurobindosundaram/">https://www.linkedin.com/in/aurobindosundaram/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1312766</link>
      <enclosure url="https://content.rss.com/episodes/110710/1312766/lifeafterciso/2024_01_23_15_19_43_87e3607e-8aa3-4d7b-842c-0e40afb5e841.mp3" length="53799478" type="audio/mpeg"/>
      <guid isPermaLink="false">5e33c6e9-a853-4282-a94a-678c02bb201c</guid>
      <itunes:duration>3362</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <pubDate>Tue, 23 Jan 2024 15:23:32 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:soundbite startTime="990" duration="270">Why hire an Interim CISO?</podcast:soundbite>
      <podcast:soundbite startTime="1260" duration="570">Is there such a thing as KTLO in the CISO role?</podcast:soundbite>
      <podcast:soundbite startTime="1830" duration="210">CISO purgatory and waiting for promises</podcast:soundbite>
      <podcast:soundbite startTime="2040" duration="660">Cheerleading for the team you woudn't join</podcast:soundbite>
      <podcast:soundbite startTime="2700" duration="420">The future of Interim CISOs</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 02 Episode 01 - Board/CISO Interaction]]></title>
      <itunes:title><![CDATA[Season 02 Episode 01 - Board/CISO Interaction]]></itunes:title>
      <description><![CDATA[<p>Returning from 6 months as the interim CISO of Silicon Valley Bank, host Jerry Perullo speaks about Board/CISO interaction on the FS-ISAC Insights podcast. Full video interview at fsisac.com/insights</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/1060719</link>
      <enclosure url="https://content.rss.com/episodes/110710/1060719/lifeafterciso/2023_08_02_17_14_15_30f2f954-f4fc-477c-9b03-91228a672045.mp3" length="29996262" type="audio/mpeg"/>
      <guid isPermaLink="false">148bb1cf-17a2-479f-8b52-2c5777f4e97b</guid>
      <itunes:duration>1874</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <pubDate>Wed, 02 Aug 2023 19:11:57 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/1060719/transcript" type="application/x-subrip"/>
      <podcast:soundbite startTime="0" duration="275">Intro</podcast:soundbite>
      <podcast:soundbite startTime="275" duration="121">Being the Interim CISO of SVB through the crisis</podcast:soundbite>
      <podcast:soundbite startTime="396" duration="444">The CISO “seat at the table”</podcast:soundbite>
      <podcast:soundbite startTime="840" duration="210">Board TRIC 1: Threats </podcast:soundbite>
      <podcast:soundbite startTime="1050" duration="120">Board TRIC 2: Risks</podcast:soundbite>
      <podcast:soundbite startTime="1170" duration="110">Board TRIC 3: Incidents</podcast:soundbite>
      <podcast:soundbite startTime="1280" duration="280">Board TRIC 4: Compliance</podcast:soundbite>
      <podcast:soundbite startTime="1560" duration="314">CISOs as Board Directors</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 01 Episode 07 - Bug Bounties with guest Casey Ellis]]></title>
      <itunes:title><![CDATA[Season 01 Episode 07 - Bug Bounties with guest Casey Ellis]]></itunes:title>
      <description><![CDATA[<p>Bugcrowd founder Casey Ellis joins #lifeafterCISO to talk about bug bounty programs in the wake of the Joe Sullivan Uber trial. Whether you've been running bounty programs for years or just learned of them last week, this conversation will take you from basics straight into the most interesting and controversial bits.</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/663773</link>
      <enclosure url="https://content.rss.com/episodes/110710/663773/lifeafterciso/2022_10_20_11_49_58_f70e0173-cf6d-4802-a068-16a8cfe45a10.mp3" length="140917027" type="audio/mpeg"/>
      <guid isPermaLink="false">c19fdd9e-4589-4b1d-a883-fc839a7b893f</guid>
      <itunes:duration>3522</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <pubDate>Thu, 20 Oct 2022 11:52:21 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:soundbite startTime="85" duration="545">The Joe Sullivan Uber trial and its impact on bug bounties</podcast:soundbite>
      <podcast:soundbite startTime="630" duration="310">Clearing assurance debt: The initial bounty wave</podcast:soundbite>
      <podcast:soundbite startTime="940" duration="435">Ostrich Risk Management</podcast:soundbite>
      <podcast:soundbite startTime="1375" duration="1265">VDPs as a proxy for security program maturity</podcast:soundbite>
      <podcast:soundbite startTime="2640" duration="882">Take 10% or 10 rows of my data - whichever is smaller</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 01 Episode 06 - Retire Many Times with guest Sounil Yu]]></title>
      <itunes:title><![CDATA[Season 01 Episode 06 - Retire Many Times with guest Sounil Yu]]></itunes:title>
      <description><![CDATA[<p>Sounil Yu joins the #lifeafterCISO podcast and shares the idea of "retiring many times". Sounil is the renowned author of the Cyber Defense Matrix and lauded by the CISO community for his ability to step back and view problems in a new light. Host Jerry Perullo and Sounil go on to look at the Equifax breach from a new angle, talk about CISO accountability, and finally offer up their early thoughts on the Twitter whistleblower report.</p><p>01:43 Returning to work as a CISO</p><p>10:30 Do CISOs spend too much time on tech?</p><p>11:38 CDM and the Equifax breach</p><p>15:00 CISO accountability</p><p>19:45 The Twitter whistleblower complaint</p><p>Learn more about Sounil and his work at <a href="https://www.cyberdefensematrix.com/">https://www.cyberdefensematrix.com/</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/608034</link>
      <enclosure url="https://content.rss.com/episodes/110710/608034/lifeafterciso/20220906_030931_2e141a6bbd22869ae8ea728aea1d944a.mp3" length="46455405" type="audio/mpeg"/>
      <guid isPermaLink="false">a2407b4c-0077-4a38-a5e0-15eadf1586a8</guid>
      <itunes:duration>2134</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <pubDate>Tue, 06 Sep 2022 15:26:33 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:soundbite startTime="32" duration="71">The Cyber Defense Matrix</podcast:soundbite>
      <podcast:soundbite startTime="103" duration="527">Retiring Many Times</podcast:soundbite>
      <podcast:soundbite startTime="630" duration="68">Do CISOs spend too much time on tech?</podcast:soundbite>
      <podcast:soundbite startTime="698" duration="202">CDM and the Equifax Breach</podcast:soundbite>
      <podcast:soundbite startTime="900" duration="285">CISO Accountability</podcast:soundbite>
      <podcast:soundbite startTime="1185" duration="949">The Twitter whistleblower complaint</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 01 Episode 05 - Deciding When It's Time to Go with guest Jason Chan]]></title>
      <itunes:title><![CDATA[Season 01 Episode 05 - Deciding When It's Time to Go with guest Jason Chan]]></itunes:title>
      <description><![CDATA[<p>An essential part of moving on from a long tech career is just figuring out when the time is right. Join host Jerry Perullo and retired Netflix CISO Jason Chan for a discussion about picking your time, "Identity Management" after retirement, and the Psychology of Happiness.</p><p>Links to the material discussed by Jason Chan include:</p><p><a href="https://arthurbrooks.com/podcast_show/the-art-of-happiness-with-arthur-brooks/">https://arthurbrooks.com/podcast_show/the-art-of-happiness-with-arthur-brooks/</a></p><p><a href="https://www.coursera.org/learn/the-science-of-well-being">https://www.coursera.org/learn/the-science-of-well-being</a></p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/592363</link>
      <enclosure url="https://content.rss.com/episodes/110710/592363/lifeafterciso/20220823_030854_458ddd59256c484a88288fa026395f4d.mp3" length="91311542" type="audio/mpeg"/>
      <guid isPermaLink="false">b81fc066-3b80-4507-b5e7-8597cb4bbce3</guid>
      <itunes:duration>2283</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <pubDate>Tue, 23 Aug 2022 15:58:01 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/592363/transcript" type="application/x-subrip"/>
      <podcast:soundbite startTime="66" duration="420">The West Coast CISO Concept</podcast:soundbite>
      <podcast:soundbite startTime="486" duration="400">The Three Pillars of Retention Model</podcast:soundbite>
      <podcast:soundbite startTime="886" duration="364">Staying Connected &amp; FOMO</podcast:soundbite>
      <podcast:soundbite startTime="1250" duration="340">DIY Retirement Planning v. Using Professionals</podcast:soundbite>
      <podcast:soundbite startTime="1590" duration="540">Identity Management after Retirement</podcast:soundbite>
      <podcast:soundbite startTime="2130" duration="153">The Psychology of Happiness</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 01 Episode 04 - The CISO Professor]]></title>
      <itunes:title><![CDATA[Season 01 Episode 04 - The CISO Professor]]></itunes:title>
      <description><![CDATA[<p>In this Episode host Jerry Perullo talking about cybersecurity in higher education. A Professor of the Practice in the Georgia Tech School of Cyber Security and Privacy, Perullo thinks aloud on the challenges that have prevented cyber from taking off at the undergraduate level before focusing on specific steps you might take to pursue this career path.</p><p><strong>00:00:55 A Brief History of Cyber in Higher Ed </strong> </p><p><strong>00:03:11 The Archetype Cyber Curriculum </strong> </p><p><strong>00:08:03 Enter the CISO: t-5</strong></p><p><strong>00:13:25 When You Are Ready to Take the Leap</strong> </p><p><strong>00:16:01 Is It Worth It?</strong> </p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/522101</link>
      <enclosure url="https://content.rss.com/episodes/110710/522101/lifeafterciso/20220616_020650_bf857b9299ccc51c9bff3fb86ed70621.mp3" length="56259395" type="audio/mpeg"/>
      <guid isPermaLink="false">acbe1d21-78b3-4542-9c42-ba338362afa7</guid>
      <itunes:duration>1407</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <pubDate>Thu, 16 Jun 2022 14:36:52 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/522101/transcript" type="application/x-subrip"/>
      <podcast:soundbite startTime="55" duration="136">A Brief History of Cyber in Higher Ed</podcast:soundbite>
      <podcast:soundbite startTime="191" duration="292">The Archetype Cyber Curriculum</podcast:soundbite>
      <podcast:soundbite startTime="483" duration="322">Enter the CISO: t-5</podcast:soundbite>
      <podcast:soundbite startTime="805" duration="156">When You Are Ready to Take the Leap</podcast:soundbite>
      <podcast:soundbite startTime="961" duration="446">Is It Worth It?</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 01 Episode 03 - Angel Investing and Advisory Work]]></title>
      <itunes:title><![CDATA[Season 01 Episode 03 - Angel Investing and Advisory Work]]></itunes:title>
      <description><![CDATA[<p>In this episode we are talking about Angel Investing, Advisory Work, and how they are essentially the same thing when you get down to it. Hear some details about evaluating opportunities, structuring "deals", and avoiding mistakes along the way.</p><p>00:05:37 Don’t Screw Up - Riding VC Paper, the FAST Agreement, Option Vesting,...</p><p> 00:21:26 Win - Playing to your Strengths</p><p> 00:24:11 Diversify - Frequency and Volume to Avoid Black Swans</p><p> 00:30:17 Conflicts &amp; Disclosure</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/459412</link>
      <enclosure url="https://content.rss.com/episodes/110710/459412/lifeafterciso/20220418_080455_8a4f5fe2a53bea43bcd007059a34493b.mp3" length="84608521" type="audio/mpeg"/>
      <guid isPermaLink="false">df5b3b03-04cf-4e4d-8abf-06bc1f83e592</guid>
      <itunes:duration>2116</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <pubDate>Mon, 18 Apr 2022 20:11:02 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/459412/transcript" type="application/x-subrip"/>
      <podcast:soundbite startTime="337" duration="949">Don’t Screw Up: Riding VC Paper, the FAST Agreement, Option Vesting...</podcast:soundbite>
      <podcast:soundbite startTime="1286" duration="165">Win: Playing to your Strengths</podcast:soundbite>
      <podcast:soundbite startTime="1451" duration="366">Diversify: Frequency and Volume to Avoid Black Swans</podcast:soundbite>
      <podcast:soundbite startTime="1817" duration="299">Conflicts &amp; Disclosures</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 01 Episode 02 - The CISO Board Director]]></title>
      <itunes:title><![CDATA[Season 01 Episode 02 - The CISO Board Director]]></itunes:title>
      <description><![CDATA[<p>In this episode, host Jerry Perullo explores the opportunities and challenges for retiring tech executives and CISOs in the Board room. Hear about how Boards need business leaders first and specialists second, and what you can do today to groom yourself in that very direction.</p><p>01:57 Background</p><p>07:45 The Traditional Board Director</p><p>09:50 Episode BLUF</p><p>10:19 Landing a Seat</p><p>14:32 Your Board Profile</p><p>16:08 t-3: What You Should do Now</p><p>28:40 Recap</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/435333</link>
      <enclosure url="https://content.rss.com/episodes/110710/435333/lifeafterciso/20220328_040359_82bb3624353ca9f9672daa351c3062c7.mp3" length="71767770" type="audio/mpeg"/>
      <guid isPermaLink="false">2eaf3eca-b846-41bb-8ebd-3dbd4a44150b</guid>
      <itunes:duration>1795</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <pubDate>Mon, 28 Mar 2022 16:18:14 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:transcript url="https://transcripts.rss.com/110710/435333/transcript" type="application/x-subrip"/>
      <podcast:soundbite startTime="117" duration="348">Background</podcast:soundbite>
      <podcast:soundbite startTime="465" duration="125">The Traditional Board Director</podcast:soundbite>
      <podcast:soundbite startTime="590" duration="29">BLUF</podcast:soundbite>
      <podcast:soundbite startTime="619" duration="253">Landing a Board Seat</podcast:soundbite>
      <podcast:soundbite startTime="872" duration="96">Your Board Profile</podcast:soundbite>
      <podcast:soundbite startTime="968" duration="752">t-3: What to do Today</podcast:soundbite>
    </item>
    <item>
      <title><![CDATA[Season 01 Episode 01 - The Portfolio Life]]></title>
      <itunes:title><![CDATA[Season 01 Episode 01 - The Portfolio Life]]></itunes:title>
      <description><![CDATA[<p>In this introductory episode, host Jerry Perullo talks about the range of opportunities available to tech executives after the day job. Perullo leverages his 20 years of experience as the founding CISO of ICE and the New York Stock Exchange to discuss what you can do 3-5 years before leaving your post to get prepared.</p><p>00:08:43 Advisory Work</p><p>00:13:20 Consulting</p><p>00:16:00 Angel Investing</p><p>00:25:05 Board Directorship</p><p>00:35:12 Entrepreneurship</p><p>00:37:06 Teaching</p><p>00:39:12 Volunteering</p>]]></description>
      <link>https://rss.com/podcasts/lifeafterciso/399829</link>
      <enclosure url="https://content.rss.com/episodes/110710/399829/lifeafterciso/20220222_090215_2316ec0fc94750d10833debe067d87f6.mp3" length="100420962" type="audio/mpeg"/>
      <guid isPermaLink="false">6b741413-6cd6-4ca1-b35f-40e9740b8b21</guid>
      <itunes:duration>2511</itunes:duration>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <pubDate>Wed, 23 Feb 2022 13:10:05 GMT</pubDate>
      <itunes:explicit>false</itunes:explicit>
      <podcast:soundbite startTime="523" duration="10">Advisory Work</podcast:soundbite>
      <podcast:soundbite startTime="800" duration="10">Consulting</podcast:soundbite>
      <podcast:soundbite startTime="960" duration="10">Angel Investing</podcast:soundbite>
      <podcast:soundbite startTime="1505" duration="10">Board Directorship</podcast:soundbite>
      <podcast:soundbite startTime="2112" duration="10">Entrepreneurship</podcast:soundbite>
      <podcast:soundbite startTime="2226" duration="10">Teaching</podcast:soundbite>
      <podcast:soundbite startTime="2352" duration="10">Volunteering</podcast:soundbite>
    </item>
  </channel>
</rss>