The Cyber Threat Perspective
5.0(16)

The Cyber Threat Perspective

by SecurIT360

234 episodesLatest 7 days agoEN-US

Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.

[email protected]

Hosts

  • Spencer Alessi
  • Brad Causey

© 2026 The Cyber Threat Perspective

Episodes (234)

  1. [Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers

    Sep 11, 202631m

    Replay of Episode 178, originally published April 22, 2026. We are re-running this one because it is the question we get asked most on internal pen test debriefs: of everything on the list, what actually slows an attacke

  2. Every IT Team Has a Joe | Ep 195

    Sep 4, 202627m#195

    Interested in a pen test? Visit securit360.com. Every organization has a Joe. He is the long tenured engineer or admin who built half the environment, maintains the other half, and keeps most of it in his head. Everybody

  3. Service Accounts: The Shortest Path to Domain Admin | Ep 194

    Aug 27, 202632m#194

    Service accounts are one of the easiest paths to domain admin on an internal pen test, and one of the most neglected accounts in Active Directory. In this episode, Spencer and Tyler break down why service accounts keep f

  4. Your IT Job Doubled. Nobody Told Your Boss. | Ep 193

    Aug 20, 202639m#193

    In July 2026, Microsoft alone released 622 CVEs. In the 2010s, the monthly average was about a dozen. Nobody handed IT teams more time, budget, or headcount to match, and that gap is what burnout is actually made of. Som

  5. Subtractive Security: Stop Adding Tools and Start Deleting Attack Paths | Ep 192

    Aug 14, 202638m#192

    Work with us --> https://www.securit360.com/#contact-anchor The OWASP Subtractive Security Top 10 Project --> https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10 The OWASP Subtractive Security Top 10 Project is a

  6. The CrowdStrike Settings That Actually Stop Us | Ep 191

    Aug 6, 202638m#191

    Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned. In this episode, Spencer and Tyler open up the

  7. Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures

    Jul 31, 202622m#190

    Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them? In this episode of the Cyber Threat Perspective, Br

  8. Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

    Jul 24, 202627m#189

    Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category t

  9. Guaranteed way to catch threat actors | Ep 188

    Jul 17, 202631m#188

    In this episode, Spencer and Tyler discuss why deception is one of the best ways to catch threat actors. Resources Spencer's Cyber Deception Webinar Spencer's X posts on the topic of cyber deception https://thinkst.com/

  10. Avoid this cyber leadership trap | Ep 187

    Jul 10, 202616m#187

    Need a pentest or vCISO? Work with us! https://www.securit360.com/ A major leadership failure in Cybersecurity is l buying tools first then figuring out where they fit and how to use them. That’s super backwards. Here’s

  11. Episode 186: Real Life Active Directory Attack Paths

    Jul 3, 202635m#186

    In this episode Spencer and Tyler discuss real life Active Directory attack paths, taken from real internal pentest engagements over the last several years. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cy

  12. [Replay] Episode 172: The Biggest Security Blind Spots in Midsized Companies

    Jun 25, 202633m

    Some of the most dangerous security gaps aren't sophisticated — they're the ones hiding in plain sight. In this replay, Brad and Spencer break down the biggest blind spots they see over and over in mid-size companies: po

  13. Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

    Jun 18, 202645m

    AI agents can search the web, manipulate files, run commands, make API requests, access cloud platforms, and operate fully autonomously. They are powerful, they are here, and most organizations have no security controls

  14. Episode 184 | Active Directory Isn't Dead. It's Just Undefended.

    Jun 11, 202628m#184

    Think Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ year

  15. Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked

    Jun 5, 202628m#183

    Security misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Nat

  16. Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR)

    May 27, 202630m#182

    Hosts Brad Causey and Spencer Alessi break down the 2026 Verizon Data Breach Investigations Report, focusing on the findings that actually matter for IT and security teams. The biggest surprise: vulnerability exploitatio

  17. [Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works

    May 20, 202644m

    We're re-releasing one of our most practical episodes this week — originally published November 2025, and still one of the best roadmap conversations we've had on the show. Brad and Spencer share no-fluff advice for brea

  18. Episode 181: AI Zero Days (Google Threat Intelligence Report)

    May 12, 202641m#181

    Brad and Spencer break down Google Threat Intelligence Group's latest report on how adversaries are weaponizing AI across the entire attack lifecycle. The big takeaway isn't that AI has magically replaced attackers, but

  19. Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry

    May 7, 202629m#180

    In Episode 180, hosts Brad Causey and Spencer Alessi tackle a critical but often overlooked issue in cybersecurity: the echo chambers that can undermine critical thinking and effective security programs. Inspired by rece

  20. Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained

    Apr 30, 202628m#179

    In Episode 179 of the Cyber Threat Perspective podcast, host Brad Causey and web app pen tester Jordan Natter kick off a multi-part series on the OWASP Top 10, the newly updated list of the most common and critical web a

  21. Episode 178: Internal Security Controls That Actually Frustrate Attackers

    Apr 22, 202631m#178

    In Episode 178 of the Cyber Threat Perspective podcast, hosts Spencer and Tyler take a practitioner-first look at the internal security controls that genuinely make attackers' lives difficult, drawing directly from their

  22. Episode 177: Claude Mythos — What It Actually Does, What It Doesn't, and What Your Organization Should Do Now

    Apr 14, 202641m#177

    In Episode 177 of the Cyber Threat Perspective podcast, host Brad Causey and virtual CISO Daniel Perkins take a clear-eyed look at Claude Mythos — Anthropic's AI model that's generating serious buzz in the cybersecurity

  23. Episode 176: Cybersecurity Advice That Sounds Smart But Fails in Practice

    Apr 9, 202638m#176

    In Episode 176 of the Cyber Threat Perspective podcast, Brad and Spencer break down some of the most repeated cybersecurity best practices in the industry and explain why, despite sounding solid on paper, they consistent

  24. Episode 175: NetTools - The Free Active Directory Swiss Army Knife for IT Admins & Pen Testers

    Apr 2, 202624m#175

    In Episode 175, Spencer and Tyler break down NetTools — a free, self-contained Active Directory management and troubleshooting tool that’s become a go-to for their internal penetration testing engagements. They start wit

  25. Episode 174: Web Application Penetration Testing Tools & Techniques with Jordan

    Mar 26, 202628m#174

    In Episode 174, host Brad Causey is joined by guest Jordan Natter for a practical, tool-focused conversation on web application penetration testing. Together they break down the essential tools and Burp Suite Pro extensi