
Cyberside Chats: Cybersecurity Insights from the Experts
Chatcyberside
Show overview
Cyberside Chats: Cybersecurity Insights from the Experts has been publishing since 2024, and across the 2 years since has built a catalogue of 84 episodes. That works out to roughly 25 hours of audio in total. Releases follow a weekly cadence.
Episodes typically run ten to twenty minutes — most land between 14 min and 23 min — though episode length varies meaningfully from one episode to the next. None of the episodes are flagged explicit by the publisher. It is catalogued as a EN-language Technology show.
The show is actively publishing — the most recent episode landed 6 days ago, with 32 episodes already out so far this year. The busiest year was 2025, with 51 episodes published. Published by Chatcyberside.
From the publisher
Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more! Join us monthly for an interactive Cyberside Chats: Live! Our next session will be announced soon.
Latest Episodes
View all 84 episodesZoomsday: Anyone in Your Meeting Can Own You
AI vs. AI: Hacking the Agent, Not the Human
We don’t break in, we badge in (rerun)
The OpenAI – Hugging Face Autonomous Agent Breach
Data Is Hazardous Material: How Data Brokers Telematics and Over-Collection Are Reshaping Cyber Risk
600 Payloads, Zero Humans
RMISC 2026 Recap: Twenty Years In — Who's Holding the Leash?
Poisoned on Open: The New Worm Hacking Your AI
The Meta AI Hack: Just Ask Nicely
Washington Calls AI a Weapon: Ghosts of the Crypto Wars
Damaged Goods: When your new hire is already compromised
The CRM Goldmine: Inside the Salesforce Breach Wave
Shadow Agents: When Your AI Workforce Has No Boss
Better Than Google, Still Risky: The OpenEvidence Story
Finals Week Fallout: The Canvas Hack That Shook Education
9 Seconds to Zero: Misbehaving AI
Security Debt: The Risk Nobody is Reporting
Claude Code Leak: What Security Leaders Need to Know About AI Coding Agents
The “Hacking Ray” Is Here: AI, Project Glasswing, and the End of Hidden Vulnerabilities
Ep 67We don’t break in, we badge in
In this episode, Matt interviews Tom and Derek from our pen test team to break down why attackers often don’t need to hack their way in at all. While most organizations invest heavily in tools like EDR and SIEM, Tom and Derek share how they regularly get inside buildings using nothing more than confidence, a good story, and sometimes even a box of donuts. From posing as copier technicians to tailgating behind employees, their experiences show that people are often the easiest way into an organization. And once they’re in, things escalate fast. Physical access can quickly turn into network access, whether it’s plugging in a device, jumping on an unlocked workstation, or moving through the environment with far fewer restrictions than an external attacker would face. The big takeaway is simple. Real-world testing exposes what audits miss. Doors get propped open, employees try to be helpful, and small gaps add up in ways most organizations never see on paper. If you’re not testing your people and your physical controls, you’re only testing part of your security. Key takeaways: 1. Attackers target people first, not systems - Social engineering consistently bypasses even mature technical controls. 2. Physical access equals full compromise - Once inside your facility, most security controls can be circumvented quickly. 3. Un-tested controls are assumed to fail - If you’re not running social engineering or physical assessments, you don’t know your real risk. 4. Culture is a security control - Employees must feel empowered to challenge, verify, and report suspicious behavior. 5. Real-world testing reveals what audits miss - Offensive social engineering exposes how attacks succeed, not just theoretical vulnerabilities.