Skip to content
Artwork for Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
TechnologyNewsTech NewsBusiness News

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

Jerry Bell and Andrew Kalat

Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.

Play
  • 25 episodes
  • Avg 59 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • September 29 · 33 min

    Defensive Security Podcast Episode 360

    Please consider supporting the DefSec podcast here. 1. AI agents broke into 395 organisations, including ones their operator ruled out https://www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/ 2. A nuclear agency lost reactor data to an ownCloud bug patched two years earlier https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency 3. One in ten exposed AI gateways still accept the example key from the setup guide https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html 4. Click rate falls when your phishing tests get easier, not when your people get better https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/ 5. Microsoft ships 974 fixes, and the bottleneck moves to whoever has to test them https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/

  • September 29 · 36 min

    Defensive Security Podcast Episode 359

    Please consider supporting the DefSec podcast here. 1. CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html 2. CISA: Most exploited vulnerabilities should have been eradicated decades ago https://www.theregister.com/security/2026/08/28/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/5293194 3. North Korean Fake Employees Move Into Sales, Marketing and Healthcare Roles https://www.helpnetsecurity.com/2026/08/28/north-korean-remote-workers-jobs-sales-and-marketing/ 4. Unit 42 says one attacker chained 50 vulns and attack paths in 10 hours https://www.cybersecuritydive.com/news/frontier-ai-tipping-scales-cyber-adversaries/829088/ 5. AI Bug Report Flood Is Cratering Bounty Prices and Triage Queues https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy

  • September 29 · 31 min

    Defensive Security Podcast Episode 358

    Please consider supporting the DefSec podcast here. Stories: Weak IAM affects up to 98% of cloud environments https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/ China-Linked Storm-1175 Debuts New StormEncryptor Ransomware via N-central Flaw https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html ‘City-Forum’ Campaign Quietly Mines Salesforce/ServiceNow Guest Access Since March 2025 https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow LiteLLM ‘Supply Chain Attack’ Was Mostly Fallout From Trivy Compromise Days Earlier https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/ ChainDrop Worm Spreads Through npm, Slips Past Standard Security Tooling https://www.theregister.com/security/2026/08/15/chaindrop-worm-crawls-into-npm-supply-chain-evades-standard-defenses/5287958

  • August 15 · 59 min· Video

    Defensive Security Podcast Episode 357

    Please consider supporting the DefSec podcast here. Stories: 1. Ransomware Gangs Bypass the CEO, Target the 40-Something IT Manager https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499 2. Ransomware Attacks Spike While Industry Attention Shifts to AI https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934 3. ChainDrop supply chain compromise: Anatomy of a self-propagating worm https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/ 4. AI Agent Tried to Backdoor a Real Open-Source Repo During a Security Test https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html 5. Cloudflare Ditches Most Third-Party Security Tools — But Says Don’t Copy Them https://www.theregister.com/security/2026/08/04/cloudflare-has-mostly-ditched-third-party-security-tools-suggests-not-trying-that-at-home/5282600

  • August 15 · 54 min

    Defensive Security Podcast Episode 356

    Please consider supporting the DefSec podcast here. Stories: https://www.cybersecuritydive.com/news/anthropic-claude-ai-hacking-test/826708 https://thecybersecguru.com/news/openai-ai-agent-containment-escapes-hugging-face-investigation/ https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/ https://www.darkreading.com/endpoint-security/why-resetting-passwords-no-longer-stop-attacks https://cybersecuritynews.com/adform-advertising-platform-compromised/

  • August 8 · 1 hr 7 min

    Defensive Security Podcast Episode 355

    https://www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/ https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html https://openai.com/index/hugging-face-model-evaluation-security-incident/ https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause https://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/

  • July 26 · 50 min

    Defensive Security Podcast Episode 354

    Please consider supporting the DefSec podcast here. Stories: https://www.theregister.com/security/2026/07/07/enterprise-ai-still-smarting-from-leaping-before-looking/5267353 https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-private-repos-when-asked-nicely/5267924 https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/ https://databreaches.net/2026/07/04/adapthealth-says-attackers-sweet-talked-their-way-into-cloud-systems-and-stole-patient-data https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html

  • July 11 · 59 min

    Defensive Security Podcast Episode 353

    Please consider supporting the DefSec podcast here. Links to stories: https://www.securityweek.com/massive-password-spray-campaign-targeting-azure-cli/ https://thehackernews.com/2026/07/2026-cybersecurity-assessment-gap.html https://www.cybersecuritydive.com/news/klue-investigating-supply-chain-attack-salesforce-integrations/823532/ https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks https://www.darkreading.com/cyber-risk/third-party-breaches-teaches-education-lesson-vendor-risk

  • July 3 · 1 hr 2 min

    Defensive Security Podcast Episode 352

    Please consider supporting the DefSec podcast here. This week’s stories: https://www.securityweek.com/npm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks/ https://www.bleepingcomputer.com/news/security/openclaw-ai-agent-found-falling-for-phishing-attacks-spills-user-data/ https://www.cybersecuritydive.com/news/cisa-vulnerability-remediation-prioritization-directive/822504/ https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/ https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4

  • June 27 · 1 hr 11 min

    Defensive Security Podcast Episode 351

    Please consider supporting the DefSec podcast here. Links to this week’s stories: https://www.theregister.com/cyber-crime/2026/06/05/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks/5251891 https://thehackernews.com/2026/06/only-10-of-socs-say-theyre-getting.html?m=1 https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaults/ https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/ https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/ https://www.cybersecuritydive.com/news/ai-cybersecurity-hype-reality-check-gartner/821867/0:0

  • June 10 · 1 hr 7 min

    Defensive Security Podcast Episode 350

    Please consider supporting the DefSec podcast here. Links to this week’s stories: https://www.darkreading.com/threat-intelligence/ai-assisted-exploit-development-scanner-detection https://www.bleepingcomputer.com/news/security/california-ag-sues-23andme-over-2023-breach-exposing-health-data/ https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/ https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation/ https://www.darkreading.com/application-security/megalodon-malware-infects-thousands-github-repos

  • June 4 · 1 hr 5 min

    Defensive Security Podcast Episode 349

    Please consider supporting the DefSec podcast here. Links to this week’s stories: https://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.html https://www.tenable.com/blog/key-findings-from-the-verizon-dbir-2026 https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/ https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/ https://www.bleepingcomputer.com/news/security/github-links-repo-breach-to-tanstack-npm-supply-chain-attack/ https://thehackernews.com/2026/05/npm-adds-2fa-gated-publishing-and.html

  • May 24 · 56 min

    Defensive Security Podcast Episode 348

    Please consider supporting the DefSec podcast here. Links to this week’s stories: https://www.securityweek.com/openai-hit-by-tanstack-supply-chain-attack/ https://thehackernews.com/2026/05/developer-workstations-are-now-part-of.html https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html https://www.theregister.com/cyber-crime/2026/05/14/security-pros-doubt-canvas-attackers-really-deleted-stolen-student-data/5240799 https://www.theregister.com/cyber-crime/2026/05/14/security-pros-doubt-canvas-attackers-really-deleted-stolen-student-data/5240799

  • May 22 · 56 min

    Defensive Security Podcast Episode 347

    Please consider supporting the DefSec podcast here. Links to this week’s stories: https://www.bleepingcomputer.com/news/security/instructure-reaches-agreement-with-shinyhunters-to-stop-data-leak/ https://www.theregister.com/security/2026/05/06/1-in-8-workers-say-selling-company-logins-is-justifiable/5231104 https://www.theregister.com/security/2026/05/02/ai-digs-up-decades-of-code-debt-patch-up/5219734 https://www.theregister.com/security/2026/05/11/anthropics-bug-hunting-mythos-was-greatest-marketing-stunt-ever-says-curl-creator/5238111 https://www.securityweek.com/cyber-insurance-data-gives-cisos-new-ammo-for-budget-talks/

  • May 15 · 1 hr 12 min

    Defensive Security Podcast Episode 346

    Please consider supporting the DefSec podcast here. Links to this week’s stories: https://www.darkreading.com/cloud-security/csa-cisos-prepare-post-mythos-exploit-storm https://www.csoonline.com/article/4159292/insurance-carriers-quietly-back-away-from-covering-ai-outputs.html https://www.livescience.com/technology/artificial-intelligence/hackers-used-ai-to-steal-hundreds-of-millions-of-mexican-government-and-private-citizen-records-in-one-of-the-largest-cybersecurity-breaches-ever https://www.bleepingcomputer.com/news/security/payouts-king-ransomware-uses-qemu-vms-to-bypass-endpoint-security/ https://cybermagazine.com/news/how-cybercriminals-breached-gta-maker-rockstar

  • April 22 · 1 hr

    Defensive Security Podcast Episode 345

    Please consider supporting the DefSec podcast here. Links to this week’s stories: https://www.darkreading.com/threat-intelligence/axios-attack-complex-social-engineering-industrialized https://www.bleepingcomputer.com/news/security/new-venom-phishing-attacks-steal-senior-executives-microsoft-logins/ https://www.bleepingcomputer.com/news/security/google-new-unc6783-hackers-steal-corporate-zendesk-support-tickets/ https://www.darkreading.com/vulnerabilities-threats/bluehammer-windows-exploit-microsoft-bug-disclosure-issues https://www.businessinsider.com/mercor-lawsuits-data-breach-2026-4

  • April 14 · 56 min

    Defensive Security Podcast Episode 344

    Please consider supporting the DefSec podcast here. Links to stories: https://www.computerweekly.com/news/366640648/Emergency-Microsoft-Oracle-patches-point-to-wider-cyber-issues https://www.theregister.com/2026/03/27/security_boffins_harvest_bumper_crop/ https://thehackernews.com/2026/03/the-hidden-cost-of-cybersecurity.html?m=1 https://www.theregister.com/2026/03/24/trivy_compromise_litellm/ https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?m=1

  • April 4 · 1 hr 22 min

    Defensive Security Podcast Episode 343

    Please consider supporting the DefSec podcast here. Here are the links we discuss this week: https://www.darkreading.com/identity-access-management-security/more-attackers-logging-in-not-breaking-in https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/ https://www.csoonline.com/article/4147833/cisa-urges-it-to-harden-endpoint-management-systems-after-cyberattack-by-pro-iranian-group.html https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/ https://techcrunch.com/2026/03/21/delve-accused-of-misleading-customers-with-fake-compliance/

  • March 28 · 1 hr 4 min

    Defensive Security Podcast Episode 342B

    This time it’s not a rerun! ]Please consider supporting the DefSec podcast here. Here are the links we discuss this week: https://www.bleepingcomputer.com/news/security/ransomware-payment-rate-drops-to-record-low-as-attacks-surge/ https://www.securityweek.com/recent-cisco-catalyst-sd-wan-vulnerability-now-widely-exploited/ https://www.darkreading.com/cyberattacks-data-breaches/nation-state-actor-ai-malware-assembly-line https://www.cybersecuritydive.com/news/ransomware-identity-ai-cloudflare/813319/ https://thehackernews.com/2026/03/anthropic-finds-22-firefox.html?m=1

  • March 9 · 1 hr 6 min

    Defensive Security Podcast Episode 341

    Please consider supporting the DefSec podcast here. Here are the links we discuss this week: https://www.bleepingcomputer.com/news/security/amazon-ai-assisted-hacker-breached-600-fortigate-firewalls-in-5-weeks/ https://www.theregister.com/2026/02/16/open_source_registries_fund_security/ https://www.bleepingcomputer.com/news/security/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/ https://www.securityweek.com/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/ https://www.theregister.com/2026/02/19/rmm_rat_trustconnect/

Showing 1–20 of 25 episodes