Down the Security Rabbithole Podcast (DtSR)
by Rafal (Wh1t3Rabbit) Los
This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show.
On Twitter/X: https://twitter.com/@DtSR_Podcast
On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
On LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
© 2026 Down the Security Rabbithole Podcast (DtSR)
Sep 15, 2026Recent reviews on Apple Podcasts (5)
Real infosec knowledge
Raf does an excellent job of providing insight and advice around the difficult task of balancing security and business sensitivity. One of my favorites- highly recommend.
raxis ·
Entertaining, insightful and actionable! 👏👏👏
Whether you’re well established as someone who can translate creative energy into the impact you want to have on the data security world, or just getting started as a catalyst for change - this is a must-listen podcast for you! Rafal does an incredible job leading conversations that cover a huge breadth of topics related to the ins and outs of navigating an ever changing cyber security landscape - with leaders who’ve actually walked the path. Highly recommend listening and subscribing!
obacker19 ·
The Go-to sec podcast
DtSR is a go-to resource for the latest in the security world. Top-notch guests providing true insight into our industry. A wide variety of topic which cover trends, tools, trapdoors, and something else that starts with the letter ’t’. You’ll think of something. Jump down the hole and see the light!
futurethnkr ·
It’s all about that intro
This is by far my fav cyber podcast. Thank you James and Ralf.
Phantom Physics ·
Mostly marketing for vendors
In truth, I've only listened to 3 podcasts so maybe I just got unlucky. But they've all been vendor hype. The recent Episode 358 No more crappy jobs is an example. Leaving aside that the guest, Diedre's favorite word is "I", the show was 80% what her "platform" could do and how it's impossible to hire people without it. Essentially, this was a marketing show for whatever she's selling and how many buzzwords she can say. If you want more than this, try Darknet Diaries. No marketing or hype and well told cyber stories with good detail.
Samson38$ ·
Episodes (760)

DtSR Episode 723 - Richard Bird Security is Built Wrong
Sep 15, 202639m#723
TL;DR: This week's guest is Richard Bird, who has a new book coming out. He says, "Cybersecurity measures activity while its adversaries measure opportunity," and thirty years of spending has been priced against the wron

DtSR Episode 722 - Vulnerability Math Ain't Mathing
Sep 9, 202648m#722
TL;DR: Robert "RSnake" Hansen & Jeremiah Grossman join the pod to talk about the "Vuln-pocalypse", or rather, the lack thereof. We do some math, discuss whether it's worth patching vulnerabilities attackers don't exploit

DtSR Episode 721 - Finance Masterclass for Cyber (Part 2)
Sep 1, 20261h 6m#721
TL;DR: This pod is part 2 of a 2-part series in which Patrick shares his insights on the world of finance as it relates to cyber startups and financing. As promised, the tracksuit shows up, and it's an epic episode! Gues

DtSR Episode 720 - Finance Masterclass for Cyber (Part 1)
Aug 25, 202646m#720
TL;DR: This week's pod features a Masterclass on finance for Cyber folks, led by Patrick Dennis, where we ask all kinds of questions and go from idea to the pre-growth stage of a company. What's next? Check out part 2 co

DtSR Episode 719 - Budget Season for CISOs
Aug 18, 202637m#719
Guests Jack Korzeniowski Ken Foster TL;DR: Budget season is upon us, and Rafal & James sit down with Ken Foster and Jack Korzeniowski to get some insights into how CISOs deal with budgets, separate truth from fiction, an

DtSR Episode 718 - Black Hat Recap And The Rush To Rebrand Everything
Aug 11, 202635m
Guest : Dr. Chase "ZeroTrust" Cunningham TL;DR: AI Marketing slop took over Black Hat Las Vegas 2026, and Rafal sits down for a one-on-one with Chase Cunningham. Featuring their patented level of snark, real analysis, an

DtSR Episode 717 - Your UI is Bullshit
Aug 4, 202640m
Guests: Michael Farnum , Sam Van Ryder TL;DR: Most cybersecurity dashboards don’t fail because they’re ugly. They fail because they don’t change what we do next. Description In Episode 717, Rafal sits down with Michael F

DtSR Episode 716 - What if Context Replaced Alerts Entirely
Jul 28, 202632m#716
Guests: Jason Vest & Josh Neil TL;DR: Alert fatigue is still a problem; detection isn't generationally better - but we have all this AI. So what gives? Description Alert fatigue is not just a workload problem; it is a pr

DtSR Episode 715 - Reducing The Toil of the SOC Analyst
Jul 21, 202639m#715
TL;DR: David Kennedy & Larry Whiteside, Jr. join the podcast to talk about how 'alerts' are a terrible measure of work in the SOC, and what we're doing about it. We discuss the analyst experience, why it's so difficult a

DtSR Episode 714 - Limitations and Expectations for AI SOC Part 2
Jul 14, 202632m#714
TL;DR: This week's pod is the conclusion to the 2-part series on AI SOC with Anton Chuvakin, Daniel Miessler, Rock Lambros, Erik Bloch, and Raja Mukerji. We talk about the rational application of AI to cybersecurity and

DtSR Episode 713 - Limitations and Expectations for AI SOC Part 1
Jul 7, 202631m#713
TL;DR: Join Raja Mukerji , Anton Chuvakin , Daniel Miessler , Rock Lambros , and Erik Bloch for a banger of an episode (part 1 of 2) where we debate the potential of AI and the current state of delivery for SOC and secur

DtSR Episode 712 - Lies My AI SOC Salesman Tells
Jun 30, 202632m#712
TL;DR: Seth Summersett of Embed Security joins the podcast to talk about the snake oil that's coming from the AI SOC sellers. There's such a significant gap between what you're being sold and what's real. Seth and the ga

DtSR Episode 711 - Tim Chase Boring but Necessary
Jun 23, 202634m#711
TL;DR: This week's pod features Tim Chase , a field CISO and, by background, a practitioner. We talk about "prioritization", a topic that's boring but incredibly necessary, as I am confident nobody out here has this solv

DtSR Episode 710 - Leading and Innovating in Security
Jun 16, 202647m#710
TL;DR: This week's podcast features Adam Ely - innovator, leader, and founder. Adam's led some of the world's largest security orgs, and started a tiny start-up. He's got knowledge and wisdom to share, so take it in. You

DtSR Episode 709 - Zero Trusting OT
Jun 9, 202615m#709
TL;DR: Phillip Wylie joins Rafal live from Zero Trust World 2026 in Orlando, FL, to talk about Operational Technologies (OT) in the context of Zero Trust. As the Joker once said, "Hubba Hubba, who do you trust?" YouTube:

DtSR Episode 708 - Does AI Give Threat Actors an Advantage
Jun 2, 202652m#708
TL;DR: This week's pod features Karim Hijazi, Adam Meyers, and Will Gragido on AI and the potential advantages for adversaries . It's a fascinating discussion with in-depth analysis, commentary, and relatable stories tha

DtSR Episode 707 - Impact of AI on the Intelligence Game
May 26, 202644m#707
TL;DR: Today's pod features Will Gragido , a multi-time returning guest with deep expertise in cyber intelligence, threat actors, and related activity. Will shares his expertise with us on how AI will impact the gatherin

DtSR Episode 706 - Practical AppSec for the AI Vulnpocalypse
May 19, 202638m#706
TL;DR: How are organizations like the Motley Fool handling AppSec right now ? How are companies building sustainable, measurable, and resilient software security programs, even as AI looms overhead? Catch Paolo del Mundo

DtSR Episode 705 - Idiocracy or Star Trek
May 12, 202638m#705
TL;DR: Howard Holton's back for part 2 of this 2-part special on the cybersecurity market, procurement's role, innovation, and now with 100% more AI discussion (drink up). Will it be Idiocracy? Or Star Trek? I know what

DtSR Episode 704 - Market Saturation, Innovation and Procurement
May 5, 202634m#704
TL;DR: Buckle up. Howard Holton, CEO of GigaOm , joins for a 2-part special on the cybersecurity market, innovation, market saturation, and more. What an absolute blast of a podcast. YouTube video (apologies for the crap

DtSR Episode 703 - The Myth and Reality of Mythos
Apr 28, 202639m#703
TL;DR: Returning guest Gadi Evron joins the crew to talk about the latest bomb dropped by Anthropic - "Mythos". Allegedly, this model could bring about the vulnerability apocalypse, or something. Let's dive into it. YouT

DtSR Episode 702 - Trust Issues with Trusted Advisors
Apr 21, 202646m#702
TL;DR: Do you have a trusting relationship with your cyber VAR, reseller, or integrator? Most of us don't, and that's because the erosion of trust has been ongoing for the last decade. So when Josh Jones , Chris Roche ,

DtSR Episode 701 - Adrian Sanabria AI Cant Replace Jobs
Apr 14, 202635m#701
TL;DR: Starting off the 700 series is Adrian Sanabria , long-time analyst, and industry insider. Adrian's SubStack post ( https://substack.com/home/post/p-189699798 ) makes an interesting distinction between 'work' and '

DtSR Episode 700 - An Unreal Milestone
Apr 7, 202644m#700
TL;DR: THANK YOU. I can't believe I'm dropping episode 700. It's been a journey since September 2011 - so many amazing and unbelievable guests, conversations, and life lessons. So much incredible content that ages like f

DtSR Episode 699 - Marcus Hutchins Hot Takes and AI
Mar 31, 202622m#699
TL;DR: As I continue to post content recorded in Orlando at Zero Trust World 2026, I bring you a live recorded episode with Marcus Hutchins. It's an interesting discussion that is no doubt polarizing, but no less interes