Decipher Security Podcast
4.4(9)

Decipher Security Podcast

by Decipher

374 episodesLatest 2 days agoEN

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.

Hosts

  • Dennis Fisher
  • Lindsey O’Donnell-Welch

Decipher

Recent reviews on Apple Podcasts (1)
  • Like it but HORRIBLE audio issues

    Particularly in ep12 there are multiple examples where there are people talking over one another and then periods of silence. There’s some very annoying background noise like someone has a TV or Radio on while recording. Dudes. Clean it up... 🙃

    btaroli ·

View all reviews on Apple Podcasts

Episodes (374)

  1. The Politics of Hacking Back, the Origins of ExploitGym, and Water Plant Attacks

    Aug 21, 202644m

    This week we discuss the new White House memo on using private sector operators in offensive cyber operations, Lindsey's deep dive into the origins of the ExploitGym AI benchmark, and the rash of attacks on water utiliti

  2. How AI is reshaping attacker and defender behavior | Adam Meyers

    Aug 19, 202653m

    Adam Meyers of CrowdStrike joins Dennis to dive into the rapidly changing nature of both attacker and defender behavior in the AI age and how organizations need to shift their priorities to combat agentic threats. Then w

  3. The truth about AI model security and what's coming next | Gary McGraw

    Aug 10, 202639m

    AI security pioneer and machine learning expert Gary McGraw helps Dennis separate the facts from fiction about the recent OpenAI, Meta, and Anthropic model escapes, what the real risks to enterprises are from agentic AI,

  4. More AI Model Escapes and New Backdoored Chinese Routers

    Aug 5, 202637m

    We can't go a week without an AI model escaping its bounds, and this week we talk about a new test by the AI Security Institute in which OpenAI and Anthropic models escaped the evaluation environment and tried to start a

  5. The OpenAI and Hugging Face Intrusion Wasn't Enough, So Now Anthropic Wants In

    Jul 31, 202635m

    This week we talk about the OpenAI-Hugging Face incident and what it means for those companies and the way that AI models are tested, and then we discuss Anthropic's entry into the race with its own admission that some o

  6. Project Hail Mary is a Hacker Movie. Amaze Amaze Amaze.

    Jul 29, 202648m

    Project Hail Mary is many things: an instant classic, a heartwarming buddy movie, a brilliant scientific tale. And it's also a pure hacker movie. Wendy Nather and David Mortman join Dennis and Lindsey to talk about Rylan

  7. How Cybercrime Groups Have Become APTs | Michael Sweeney

    Jul 27, 202648m

    Cybercrime has become professionalized and industrialized to the point that these groups are essentially at the level of state-backed APTs. Mike Sweeney of Silent Push joins Dennis Fisher to talk about this evolution, ho

  8. JADEPUFFER: The Era of Agentic Ransomware Has Begun | Michael Clark

    Jul 20, 202626m

    Michael Clark, director of Threat Research at Sysdig, talks about a recent LLM-driven extortion campaign dubbed JADEPUFFER, touching on how the team discovered it, how attackers’ “intent is now legible,” and what that me

  9. The Cursor Bug Drama, Microsoft's Massive Patch Tuesday, and Scattered Spider Takes a Hit

    Jul 17, 202640m

    This week we have some old-school disclosure drama when a researcher used full disclosure after months of silence from Cursor, then we discuss the enormous Patch Tuesday from Microsoft--662 bugs--and what it might mean g

  10. Industrial Cybersecurity and Malware Archaeology with Lesley Carhart

    Jul 14, 202636m

    Old malware like Conficker never really dies, and in industrial control and SCADA environments it can live forever undisturbed. Lesley Carhart of Dragos joins Dennis Fisher to talk about the myriad challenges of incident

  11. Our AI Coding Future with Jack Cable

    Jul 7, 202623m

    Jack Cable, co-founder and CEO of Corridor and a former senior technical advisor at CISA, discusses AI's impact on cybersecurity, vulnerability discovery, and coding practices.

  12. Fable 5 Export Controls, the Dual Use Paradox, and the ARToken Phishing Framework

    Jul 2, 202637m

    It's a pre-July 4th extravaganza! To celebrate, we dive into a little cybersecurity history with a story about the MySpace Samy worm, then we jumpe into the news of the week, including an update on the Fable 5 export con

  13. The (Bug) Disclosure Day Conundrum and How AI is Changing the Game with Katie Moussouris

    Jun 29, 202657m

    Hacker and legendary vulnerability disclosure expert Katie Moussouris of Luta Security joins Dennis to talk about the Fable 5 munitions classification controversy, the recent re-emergence of the disclosure debate, how AI

  14. The Gaslight macOS Backdoor, Cisco Zero Day Exploit, and Operation Endgame

    Jun 26, 202631m

    It's a non-AI podcast! This week we dig into the new Gaslight macOS implant that tries to trick security researchers with some anti-forensics techniques, then we discuss the Operation Endgame takedown of some malware inf

  15. How Much Do Data Breaches Really Cost? | Alex Pinto

    Jun 16, 202641m

    Alex Pinto, one of the lead authors of the Verizon Data Breach Investigations Report, joins Dennis to talk about his organization's newest publication, the Breach Impact Study, which digs into the real world cost of brea

  16. The Shrinking Exploit Window, Patch Schedule Changes, and the Vulnpocalypse

    Jun 12, 202632m

    This week was blessedly free of any major supply chain compromises, so we start by talking about new research from Anthropic on the shrinking window between bug disclosure and exploitation, then we discuss the changing p

  17. How The Conversation Predicted Our Surveillance Society 50 Years Ago

    Jun 8, 202658m

    Perhaps no film captures the paranoia and anxiety of the 1970s better than The Conversation, Francis Ford Copolla's masterpiece about reclusive surveillance expert Harry Caul, a man who it's safe to say has some demons.

  18. Shai Hulud Returns, How Attackers are Using AI, and More Weird MSRC Behavior

    Jun 5, 202636m

    We regret to inform you that there are more npm supply chain attacks this week, and a new variant of the Shai Hulud worm is involved. We also talk about the new analysis from Anthropic on a year of data relating to how a

  19. Microsoft Has Forgotten Its Vulnerability Disclosure History

    May 29, 202645m

    The recent Nightmare-Eclipse zero day drop and attendant drama has stirred up all kinds of trouble and unfortunately spurred Microsoft to publish a post scolding security researchers for not using the "proper channels" t

  20. Lessons in Resilience, Perseverance, and Leadership With Matt Eversmann

    May 25, 20261h 18m

    After being caught in one of the more notorious battles in modern American history, Matt Eversmann's military career has become the stuff of legend. The Battle of Mogadishu, immortalized in the book and movie Black Hawk

  21. Chain Chain Chain of Compromises

    May 22, 202622m

    In the spring, a young attacker's fancy turns to supply chain compromises, and this season's crop includes the GitHub breach and the Grafana intrusion, which are connected and trace back to the TanStack supply chain atta

  22. What the Data Tells Us About Claude Mythos and Bug Exploitability | Jay Jacobs and Michael Roytman

    May 19, 202643m

    Finding a huge pile of bugs with Claude Mythos is great, but the logical next step is figuring out how many of those vulnerabilities are likely to be exploited in the near future. Jay Jacobs and Michael Roytman of Empiri

  23. Solving Hard Security Problems With an Outsider's Perspective | Sravish Sridhar

    May 15, 202653m

    Unlike a lot of founders in the industry, Sravish Sridhar hasn't spent his career in the security world. He comes from a background in distributed computing and advanced math, and is a successful entrepreneur who's now b

  24. AI Has a Security Measurement Problem | Gary McGraw

    May 13, 202638m

    Few people (if any) have spent more time thinking about and working on the hard problems in security and software than Gary McGraw, and he also happens to have a PhD in cognitive science and computer science and has been

  25. Inside the $285M Drift Protocol Heist | Ari Redbord

    May 11, 202634m

    Ari Redbord, Global Head of Policy at TRM Labs, talks about the insane background behind the $285 million Drift Protocol crypto heist, how law enforcement agencies are investigating ransomware-linked cryptocurrency walle