Decipher Security Podcast
4.4(9)

Decipher Security Podcast

by Decipher

388 episodesLatest 2 days agoEN

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.

Hosts

  • Dennis Fisher
  • Lindsey O’Donnell-Welch

Decipher

Episodes (388)

  1. Catch Me If You Can with Shea Serrano!

    Oct 6, 202651m

    Bestselling author, podcaster, and all around great guy Shea Serrano joins Dennis Fisher and Lindsey O’Donnell-Welch to explore why Catch Me If You Can is more than a con-artist story: it’s a hacker classic and master cl

  2. Edge Devices Under Attack, a Threatcon Preview, and Communication Breakdowns

    Oct 2, 202631m

    Today we have for you a buffet of zero days being exploited in edge security products, including Citrix and Fortinet, then we discuss the importance of communications from vendors when bad things happen, and finally we p

  3. The Citrix NetScaler Zero Day Saga | Ben Harris

    Oct 2, 202622m

    Ben Harris of watchTowr joins Dennis Fisher to walk through the Citrix NetScaler zero days that emerged over the weekend, from first detection of exploitation to reporting to finally some patches and why vendor communica

  4. The Malware That Asks AI What to Do Next | Ryan Fetterman

    Sep 29, 202630m

    Ryan Fetterman from Cisco Talos sits down with Decipher’s Lindsey O’Donnell-Welch to talk about ClosedQuorum, the first reported malware binary with an autonomous command-and-control. They talk about the wide range of wa

  5. FBI Hack Fallout, EvilTokens Takedown, and the F5 Zero Day

    Sep 27, 202632m

    This week we dig into the ShinyHunters hack of the FBI and what it means not just for the FBI personnel but for the attackers, then we discuss the disruption of the EvilTokens phishing operation by Microsoft, and finally

  6. Assessing AI Model Security From the Outside In | Matt Fredrikson

    Sep 22, 202637m

    The security and reliability of the code in AI models is a huge question mark, because the models are black boxes that aren't accessible to outsiders. Matt Fredrikson, professor at Carnegie Mellon University and founder

  7. The Real Story on AI Security Live From LabsCon!

    Sep 18, 202629m

    Dennis joins from the last LabsCon conference, which featured amazing keynotes from Prof. James Mickens on AI reality and myths, Katie Moussouris on why humans are more vital than ever in security, and Dino Dai Zovi on u

  8. The Vulnpocalypse Myth | Jeremiah Grossman

    Sep 15, 202652m

    You've heard all of the hysteria around the vulnpocalypse caused by AI-assisted bug hunting and the shrinking time to exploit window. Now Jeremiah Grossman dispels those myths and shows exactly what the data reveals abou

  9. Anthropic's Threat Report, AI's Effect on Cybercrime, and How 9/11 Changed Cybersecurity

    Sep 11, 202658m

    This week we dive into Anthropic's new threat intelligence report, how cybercriminals are using AI in their campaigns, and the profound effect that 9/11 had on the cybersecurity industry. Then, Dennis is joined by Ryan N

  10. Securing Communications in an AI-Assisted World | Christine Gadsby

    Sep 7, 202645m

    Christine Gadsby of BlackBerry, a longtime security executive, joins Dennis to talk about her extensive experience in cybersecurity, the evolution of security practices, the challenges of securing mobile communications,

  11. Microsoft Teams Phishing, a Botnet Takedown 23 Years in the Making, and The Cuckoo's Egg's Lessons

    Sep 4, 20261h 2m

    It's our one year anniversary! This week we talk about the highlights of the last year, a new high-level phishing campaign that uses Microsoft Teams as an initial access vector, and the takedown of the ancient Sality P2P

  12. Cybercrime Disruption: Making a “Real Impact” | Ken Bagnall

    Sep 1, 202627m

    Ken Bagnall, founder and CEO of Silent Push, talks about the August National Security Presidential Memorandum (NSPM) on transnational cyber-enabled crime, how organizations can make “real impact” with cybercriminal disru

  13. TeamPCP Arrests, the QTFY Attacks, and the OpenAI Post-Mortem

    Aug 28, 202640m

    This week we discuss the two arrests in Australia of alleged members of the TeamPCP cybercrime group that has targeted the open source ecosystem, the US government's disclosure of intrusion activity by the Chinese QTFY t

  14. The Future of Surveillance and Privacy in the Age of AI | Nicole Ozer

    Aug 25, 202636m

    Nicole Ozer, who took the helm this year as the new executive director at the Electronic Frontier Foundation (EFF), talks to Lindsey O’Donnell-Welch about the fine line between AI empowering us and undermining our rights

  15. The Politics of Hacking Back, the Origins of ExploitGym, and Water Plant Attacks

    Aug 21, 202644m

    This week we discuss the new White House memo on using private sector operators in offensive cyber operations, Lindsey's deep dive into the origins of the ExploitGym AI benchmark, and the rash of attacks on water utiliti

  16. How AI is reshaping attacker and defender behavior | Adam Meyers

    Aug 19, 202653m

    Adam Meyers of CrowdStrike joins Dennis to dive into the rapidly changing nature of both attacker and defender behavior in the AI age and how organizations need to shift their priorities to combat agentic threats. Then w

  17. The truth about AI model security and what's coming next | Gary McGraw

    Aug 10, 202639m

    AI security pioneer and machine learning expert Gary McGraw helps Dennis separate the facts from fiction about the recent OpenAI, Meta, and Anthropic model escapes, what the real risks to enterprises are from agentic AI,

  18. More AI Model Escapes and New Backdoored Chinese Routers

    Aug 5, 202637m

    We can't go a week without an AI model escaping its bounds, and this week we talk about a new test by the AI Security Institute in which OpenAI and Anthropic models escaped the evaluation environment and tried to start a

  19. The OpenAI and Hugging Face Intrusion Wasn't Enough, So Now Anthropic Wants In

    Jul 31, 202635m

    This week we talk about the OpenAI-Hugging Face incident and what it means for those companies and the way that AI models are tested, and then we discuss Anthropic's entry into the race with its own admission that some o

  20. Project Hail Mary is a Hacker Movie. Amaze Amaze Amaze.

    Jul 29, 202648m

    Project Hail Mary is many things: an instant classic, a heartwarming buddy movie, a brilliant scientific tale. And it's also a pure hacker movie. Wendy Nather and David Mortman join Dennis and Lindsey to talk about Rylan

  21. How Cybercrime Groups Have Become APTs | Michael Sweeney

    Jul 27, 202648m

    Cybercrime has become professionalized and industrialized to the point that these groups are essentially at the level of state-backed APTs. Mike Sweeney of Silent Push joins Dennis Fisher to talk about this evolution, ho

  22. JADEPUFFER: The Era of Agentic Ransomware Has Begun | Michael Clark

    Jul 20, 202626m

    Michael Clark, director of Threat Research at Sysdig, talks about a recent LLM-driven extortion campaign dubbed JADEPUFFER, touching on how the team discovered it, how attackers’ “intent is now legible,” and what that me

  23. The Cursor Bug Drama, Microsoft's Massive Patch Tuesday, and Scattered Spider Takes a Hit

    Jul 17, 202640m

    This week we have some old-school disclosure drama when a researcher used full disclosure after months of silence from Cursor, then we discuss the enormous Patch Tuesday from Microsoft--662 bugs--and what it might mean g

  24. Industrial Cybersecurity and Malware Archaeology with Lesley Carhart

    Jul 14, 202636m

    Old malware like Conficker never really dies, and in industrial control and SCADA environments it can live forever undisturbed. Lesley Carhart of Dragos joins Dennis Fisher to talk about the myriad challenges of incident

  25. Our AI Coding Future with Jack Cable

    Jul 7, 202623m

    Jack Cable, co-founder and CEO of Corridor and a former senior technical advisor at CISA, discusses AI's impact on cybersecurity, vulnerability discovery, and coding practices.