Skip to content
Artwork for Secure AF - A Cybersecurity Podcast
TechnologyBusinessEducation

Secure AF - A Cybersecurity Podcast

Alias Cybersecurity

Think like a hacker. Defend like a pro.

Welcome to the Secure AF Cybersecurity Podcast — your tactical edge in the ever-evolving cyber battlefield. Hosted by industry veterans including Donovan Farrow and Jonathan Kimmitt, this podcast dives deep into real-world infosec challenges, red team tactics, blue team strategies, and the latest tools shaping the cybersecurity landscape.


Whether you're a seasoned pentester, a SOC analyst, or just breaking into the field, you'll find actionable insights, expert interviews, and unfiltered discussions with Alias team members and top-tier guests from across the cybersecurity spectrum.


Stay sharp. Stay informed. Stay Secure AF.

Play
  • 29 episodes
  • weekly
  • Avg 18 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • September 24 · 14 min

    BlueMoon: When the Patch Becomes the Exploit Roadmap

    Got a question or comment? Message us here! Patches are meant to strengthen security, but they can also give attackers valuable clues. In this episode, we explore how threat actors analyze updates, reverse-engineer fixes, and weaponize vulnerabilities before organizations have time to patch. #CyberSecurity #PatchManagement #ThreatIntelligence #BlueMoon Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • September 22 · 22 min

    Seccon: 2026

    Got a question or comment? Message us here! SECCON may be over, but the conversations are just getting started. Join us as we recap this year's conference, share key takeaways, favorite moments, and the cybersecurity trends that had everyone talking. Tune in now! 🔐 #SECCON #Cybersecurity #Podcast #InfoSec Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • September 17 · 11 min

    When Your RMM Becomes the Target – The N-able Zero-Day

    Got a question or comment? Message us here! When your trusted RMM platform becomes the target, the consequences can ripple across thousands of systems. In this episode, we break down the N-able Zero-Day, examine how attackers exploit vulnerabilities in remote management tools, and discuss the critical lessons MSPs and IT teams can take away to strengthen their security posture and reduce risk. #CyberSecurity #Nable #RMM #ZeroDay Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • September 15 · 19 min

    Operation Security: How to keep your family safe when posting about them.

    Got a question or comment? Message us here! In a world where our lives are increasingly digital, protecting your family's privacy has never been more important. Join us as we dive into OPSEC (Operational Security), practical online safety tips, and simple strategies to reduce your digital footprint and keep your loved ones safe from cyber threats. 🔒 Learn how to safeguard personal information 👨‍👩‍👧‍👦 Protect your family from online risks 💻 Build smarter digital habits Listen now and take the first step toward a more secure online life. #OPSEC #CyberSecurity #OnlineSafety #DigitalPrivacy Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • September 11 · 54 min

    How Defenders Can Secure Enterprise AI Before Attackers Find the Gaps

    Got a question or comment? Message us here! In this episode, we explore the hidden risks of enterprise AI and the strategies organizations can use to close security gaps before attackers exploit them. #EnterpriseAI #Cybersecurity #AIGovernance #SecurityLeadership Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • September 8 · 10 min

    FalconFlank: When Your EDR Becomes the Attack Surface.

    Got a question or comment? Message us here! 🎙️ New Episode Alert: FalconFlank: When Your EDR Becomes the Attack Surface EDR solutions are designed to protect organizations from modern threats, but what happens when attackers target the very tools meant to stop them? Join us as we explore how security platforms can become part of the attack surface and what defenders need to know to stay ahead. #CyberSecurity #EDR #ThreatIntelligence #InfoSec #SOC #CyberDefense #FalconFlank Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • August 25 · 54 min

    Defcon 2026

    Got a question or comment? Message us here! A recap of DEFCON 2026 featuring the Latest in cybersecurity, hacking, AI, and digital defense. Don't miss the highlights from one of the world's most influential security conferences. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • August 20 · 5 min

    Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders

    Got a question or comment? Message us here! Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • July 8 · 4 min

    Windows BlueHammer Flaw Now Actively Exploited by Ransomware Gangs

    Got a question or comment? Message us here! Ransomware operators are leveraging the BlueHammer privilege escalation flaw to gain SYSTEM-level access and disable security controls. Get the latest insights and response recommendations. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • July 1 · 4 min

    FortiBleed Attacks: Turning Fortinet Firewalls into Credential Stealers

    Got a question or comment? Message us here! FortiBleed is turning perimeter defenses into attack infrastructure. In this episode, we unpack how adversaries exploit FortiOS vulnerabilities, harvest credentials directly from firewalls, and pivot deeper into networks, plus detection strategies, threat hunting tips, and mitigation guidance for SOC teams. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 24 · 5 min

    Arch Linux AUR Compromise – Supply Chain Risks in the Open Source World

    Got a question or comment? Message us here! This #SOCBrief episode explores a recent Arch Linux AUR supply chain compromise, where malicious community packages were used to steal credentials and gain persistence. It highlights the risks of third-party repositories and offers key detection and mitigation strategies for security teams to better protect against similar attacks. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 17 · 4 min

    Qilin Ransomware Exploiting VPN Zero-Days: What SOCs Need to Do Now

    Got a question or comment? Message us here! A single unpatched VPN could be all it takes. Qilin ransomware is actively exploiting VPN zero-days to breach networks and accelerate ransomware deployment. We walk through the tactics, the real risk to your organization, and actionable SOC strategies to stay ahead. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 16 · 43 min

    You're Probably Not Hacked, You're Being Tracked

    Got a question or comment? Message us here! You probably haven’t been hacked, you’ve been tracked. This episode breaks down how ad tech, mobile apps, and data brokers create massive behavioral profiles without ever touching your phone’s security. Learn how tracking really works, why it matters, and what you can actually do about it. 📱👁️📡 Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 10 · 13 min

    The SOC Brief Turns One 🎂 Insights, Stories & Lessons Learned

    Got a question or comment? Message us here! It’s our 1-year anniversary! 🎂 From bite-sized cyber insights to growing a passionate listener base, this episode reflects on the journey, the challenges, and the wins along the way. Expect laughs, lessons, and behind-the-scenes stories you won’t want to miss. 🚀 Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 3 · 5 min

    Kali365 Phishing-as-a-Service: FBI Warns of New M365 Credential Theft Tool

    Got a question or comment? Message us here! The FBI is warning about Kali365, a new phishing‑as‑a‑service tool designed to steal Microsoft 365 credentials and enable account takeovers at scale. In this episode, we break down how it works, why it’s so effective, and what your SOC can do right now to detect and defend against it. 🎧 Tune in now at secureafpodcast.com Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • June 2 · 37 min

    Incident Response 101: What to Do When You’re Under Attack

    Got a question or comment? Message us here! What actually happens when a company gets hacked? In this episode, we break down real-world incident response, from initial access and ransomware tactics to forensic investigation and common mistakes that make things worse. If your organization had an incident tomorrow, would you know what to do? Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 27 · 4 min

    First Known AI-Powered Zero-Day Exploit: What SOCs Need to Know 🤖

    Got a question or comment? Message us here! In this episode of the #SOCBrief, we dive into the first confirmed case of an AI-powered zero-day exploit. With attackers leveraging AI to discover vulnerabilities, generate exploit code, and bypass defenses faster than ever, this marks a major shift in how threats are developed and deployed. We break down how the attack worked, what made the exploit unique, and the key detection and defense strategies SOC teams need to start adopting now to keep pace with AI-driven adversaries. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 20 · 5 min

    ShinyHunters Breach of Instructure Canvas LMS 📚✏️: Lessons for SOCs on Third-Party Vendor Risks

    Got a question or comment? Message us here! In this episode of the #SOCBrief, we break down the ShinyHunters breach of Instructure’s Canvas LMS and what it means for security teams everywhere. From exploiting a lesser-monitored service to exfiltrating millions of records, this attack highlights the growing risk of third-party vendors and supply chain exposure. We walk through how the breach unfolded, key indicators of compromise, and the practical steps SOC teams can take to detect, monitor, and reduce vendor-related risk before it becomes a crisis. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
  • May 19 · 55 min

    Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS Risk

    Got a question or comment? Message us here! When the Canvas LMS went down, thousands of institutions came to a halt, right in the middle of finals. In this episode, we break down what really happened, what data may have been exposed, and why this incident is a wake-up call for every organization relying on SaaS platforms. From vendor risk and contract blind spots to business continuity failures, we unpack the real lessons security leaders need to hear, and what you should be doing right now to prepare for the next breach. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

    • Transcript
Showing 1–20 of 29 episodes