Skip to content
Artwork for Decipher Security Podcast

Decipher Security Podcast

Decipher

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.

Play
  • 32 episodes
  • a few times a week
  • Avg 42 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Friday · 29 min

    The Real Story on AI Security Live From LabsCon!

    Dennis joins from the last LabsCon conference, which featured amazing keynotes from Prof. James Mickens on AI reality and myths, Katie Moussouris on why humans are more vital than ever in security, and Dino Dai Zovi on using hardware to break attack chains,

  • September 15 · 52 min

    The Vulnpocalypse Myth | Jeremiah Grossman

    You've heard all of the hysteria around the vulnpocalypse caused by AI-assisted bug hunting and the shrinking time to exploit window. Now Jeremiah Grossman dispels those myths and shows exactly what the data reveals about how many bugs are actually exploited and how long it takes for attackers to target them.

  • September 11 · 58 min

    Anthropic's Threat Report, AI's Effect on Cybercrime, and How 9/11 Changed Cybersecurity

    This week we dive into Anthropic's new threat intelligence report, how cybercriminals are using AI in their campaigns, and the profound effect that 9/11 had on the cybersecurity industry. Then, Dennis is joined by Ryan Naraine to preview LabsCon and talk about the keynotes by Katie Moussouris, Dino Dai Zovi, and James Mickens. Anthropic report: https://www.anthropic.com/threat-inte...LabsCon agenda: https://events.sentinelone.com/event/...Mickens essay: https://www.usenix.org/system/files/1...

  • September 7 · 45 min

    Securing Communications in an AI-Assisted World | Christine Gadsby

    Christine Gadsby of BlackBerry, a longtime security executive, joins Dennis to talk about her extensive experience in cybersecurity, the evolution of security practices, the challenges of securing mobile communications, and the impact of AI on the security industry.

  • September 4 · 1 hr 2 min

    Microsoft Teams Phishing, a Botnet Takedown 23 Years in the Making, and The Cuckoo's Egg's Lessons

    It's our one year anniversary! This week we talk about the highlights of the last year, a new high-level phishing campaign that uses Microsoft Teams as an initial access vector, and the takedown of the ancient Sality P2P botnet. Then we offer some book and TV recommendations for the long weekend. LinksOne year of the new Decipher: https://decipher.sc/2026/09/02/one-ye...Microsoft Teams phishing: https://decipher.sc/2026/09/03/new-ca...Sality botnet takedown: https://www.justice.gov/usao-cdca/pr/...

  • September 1 · 27 min

    Cybercrime Disruption: Making a “Real Impact” | Ken Bagnall

    Ken Bagnall, founder and CEO of Silent Push, talks about the August National Security Presidential Memorandum (NSPM) on transnational cyber-enabled crime, how organizations can make “real impact” with cybercriminal disruption, and the challenges of measuring success in disrupting the cybercriminal ecosystem.

  • August 28 · 40 min

    TeamPCP Arrests, the QTFY Attacks, and the OpenAI Post-Mortem

    This week we discuss the two arrests in Australia of alleged members of the TeamPCP cybercrime group that has targeted the open source ecosystem, the US government's disclosure of intrusion activity by the Chinese QTFY threat actor, and finally the long report from OpenAI on the Hugging Face incident.

  • August 25 · 36 min

    The Future of Surveillance and Privacy in the Age of AI | Nicole Ozer

    Nicole Ozer, who took the helm this year as the new executive director at the Electronic Frontier Foundation (EFF), talks to Lindsey O’Donnell-Welch about the fine line between AI empowering us and undermining our rights and privacy – and where the tipping point is.

  • August 21 · 44 min

    The Politics of Hacking Back, the Origins of ExploitGym, and Water Plant Attacks

    This week we discuss the new White House memo on using private sector operators in offensive cyber operations, Lindsey's deep dive into the origins of the ExploitGym AI benchmark, and the rash of attacks on water utilities in the U.S.LinksInside ExploitGym: https://decipher.sc/2026/08/20/inside...White House memo: https://www.whitehouse.gov/presidenti...OpenAI post: https://openai.com/index/the-defender...

  • August 19 · 53 min

    How AI is reshaping attacker and defender behavior | Adam Meyers

    Adam Meyers of CrowdStrike joins Dennis to dive into the rapidly changing nature of both attacker and defender behavior in the AI age and how organizations need to shift their priorities to combat agentic threats. Then we talk about the new White House policy loosening the restrictions on private sector operators doing offensive cyper ops.

  • August 10 · 39 min

    The truth about AI model security and what's coming next | Gary McGraw

    AI security pioneer and machine learning expert Gary McGraw helps Dennis separate the facts from fiction about the recent OpenAI, Meta, and Anthropic model escapes, what the real risks to enterprises are from agentic AI, and what he sees as the true threats on the horizon.

  • August 5 · 37 min

    More AI Model Escapes and New Backdoored Chinese Routers

    We can't go a week without an AI model escaping its bounds, and this week we talk about a new test by the AI Security Institute in which OpenAI and Anthropic models escaped the evaluation environment and tried to start a supply chain attack, then we discuss news of Zbtlink routers having a persistent backdoor.

  • July 31 · 35 min

    The OpenAI and Hugging Face Intrusion Wasn't Enough, So Now Anthropic Wants In

    This week we talk about the OpenAI-Hugging Face incident and what it means for those companies and the way that AI models are tested, and then we discuss Anthropic's entry into the race with its own admission that some of its models escaped the playground and attacked outside organizations. LinksOpenAI-Hugging Face intrusion: https://decipher.sc/2026/07/29/openai...Anthropic blog: https://www.anthropic.com/news/invest...Ringer piece on the Hugging Face incident: https://www.theringer.com/2026/07/24/...

  • July 29 · 48 min

    Project Hail Mary is a Hacker Movie. Amaze Amaze Amaze.

    Project Hail Mary is many things: an instant classic, a heartwarming buddy movie, a brilliant scientific tale. And it's also a pure hacker movie. Wendy Nather and David Mortman join Dennis and Lindsey to talk about Ryland Grace's hacker ethos and why he and Rocky typify the can-do attitude of hackers everywhere. It's time go!

  • July 27 · 48 min

    How Cybercrime Groups Have Become APTs | Michael Sweeney

    Cybercrime has become professionalized and industrialized to the point that these groups are essentially at the level of state-backed APTs. Mike Sweeney of Silent Push joins Dennis Fisher to talk about this evolution, how AI is enabling this shift, and how defenders and vendors are working to take incremental bites out of their ecosystem.

  • July 20 · 26 min

    JADEPUFFER: The Era of Agentic Ransomware Has Begun | Michael Clark

    Michael Clark, director of Threat Research at Sysdig, talks about a recent LLM-driven extortion campaign dubbed JADEPUFFER, touching on how the team discovered it, how attackers’ “intent is now legible,” and what that means for defenders. LinkSysdig research: https://www.sysdig.com/blog/jadepuffe...

  • July 14 · 36 min

    Industrial Cybersecurity and Malware Archaeology with Lesley Carhart

    Old malware like Conficker never really dies, and in industrial control and SCADA environments it can live forever undisturbed. Lesley Carhart of Dragos joins Dennis Fisher to talk about the myriad challenges of incident response in ICS networks, how ancient malware can cause trouble for years on end, and why we need more ICS security engineers desperately.

  • July 7 · 23 min

    Our AI Coding Future with Jack Cable

    Jack Cable, co-founder and CEO of Corridor and a former senior technical advisor at CISA, discusses AI's impact on cybersecurity, vulnerability discovery, and coding practices.

Showing 1–20 of 32 episodes