PLAY PODCASTS
The Cybersecurity Defenders Podcast

The Cybersecurity Defenders Podcast

348 episodes — Page 1 of 7

Intel Chat: AI patches fail, LiteLLM supply chain, Claude eval incidents & DPRK npm [345]

Aug 14, 202634 min

Proving the value of security operations with Christopher Crowley [344]

Aug 13, 202642 min

Intel Chat: Shai-Hulud is back, model pinning & the token spend problem [343]

Aug 8, 202635 min

Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

Jul 30, 202630 min

Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

Jul 30, 202630 min

Building trustworthy AI with Rob van der Veer [341]

Jul 29, 202635 min

Building trustworthy AI with Rob van der Veer [341]

Jul 29, 202635 min

AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]

Jul 23, 202635 min

AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]

Jul 14, 202623 min

Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline & HalluSquatting [338]

Jul 9, 202634 min

Ransomware in the age of agentic AI with Behnaz Karimi [337]

Jul 8, 202633 min

Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

Jul 3, 202633 min

Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]

Jul 1, 202630 min

The evolving fraud landscape in the age of AI with Tamas Kadar [#334]

Jun 30, 202642 min

Anthropic restriction, ServiceNow incident, Fortinet credential harvesting & Ukraine accesses EU cyber reserve / Intel Chat [#333]

Jun 28, 202634 min

Last call for Defenders - How we're actually using AI in the SOC with Eric Capuano / Defender Fridays [#332]

Jun 20, 202637 min

FFmpeg's 21 zero-days, Ruby cooldown feature, Microsoft disrupted by Shai-Hulud worm & Meta AI tool compromise / Intel Chat [#331]

Jun 15, 202628 min

AI-assisted SOC training with Carlo Anez / Defender Fridays [#330]

Jun 12, 202632 min

Building practical blue team skills using AI-assisted SOC training with Bobby Ford/ Defender Fridays [#329]

Jun 5, 202630 min

"Megalodon" Malware in GitHub, Malware-Slop steals from Claude AI, 7-Eleven breach & CISA cPanel vulnerability / Intel Chat [#328]

Jun 1, 202629 min

From PentestGPT to production: The state of AI-assisted offensive security with Charles Grandjean / Defender Fridays [#327]

May 30, 202630 min

GitHub repositories compromised, Webworm targets Europe, fake Outlook & cybercriminal VPN / Intel Chat [326]

May 29, 202624 min

How analysts use cognitive reasoning in investigations with Chris Sanders / Defender Fridays [#325]

May 22, 202632 min

"Dirty Frag", Canvas ransomware attack, “Mini Shai-Hulud” malware campaign & AI-developed zero-day exploit / Intel Chat [#324]

May 18, 202628 min

How to handle increasing vulnerabilities with AI-assistants? With Shane Warden from ActiveState / Defender Fridays [#232]

May 15, 202631 min

Does the rise of AI mean human-led SOCs are obsolete? With Dr. Adeel Shaikh Muhammad [#322]

May 13, 202625 min

Daily breach attempts target UAE, fake ransomware attack, PAN-OS vulnerability & Microsoft’s Phone Link attack / Intel Chat [#321]

May 12, 202627 min

AI: The Hero's Journey with Ken Westin from LimaCharlie / Defender Fridays [#320]

May 8, 202631 min

Power systems under threat, Claude Mythos, suspicious KICS activity & JFrog / Intel Chat [#319]

May 6, 202631 min

How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318]

May 4, 202636 min

Cybersecurity is a core leadership issue & opportunity with David Chernitzky from Armour Cybersecurity [#317]

Apr 29, 202635 min

Millions in crypto stolen, Vercel breach, Mastodon DDoS attack, North Korean IT workers at 100s of U.S. companies & ransomware negotiator pleads guilty / Intel Chat [#316]

Apr 27, 202631 min

Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315]

Apr 27, 202632 min

How can we improve global security? With J. Michael Daniel from Cyber Threat Alliance [#314]

Apr 22, 202640 min

China-linked group targets cloud workflows, Russian cyber espionage, agentic AI systems flaw & Nginx vulnerability / Intel Chat [#313]

Apr 20, 202631 min

How do you know your AI agents are actually correct? With Dylan Williams from Spectrum Security / Defender Fridays [#312]

Apr 17, 202633 min

Understanding how attackers think & helping you avoid threats with Terry Bradley from Mile High Cyber [#311]

Apr 15, 202638 min

Iran-linked cyber attacks U.S. critical infrastructure, FlamingChina, Node.js targeted & Storm-1175 / Intel Chat [#310]

Apr 13, 202639 min

Levelling up your AI SOC with Joshua Neil from Alpha Level / Defender Fridays [#309]

Apr 10, 202634 min

Why cyber analysts are crucial in protecting public infrastructure with Michael Hamilton from PISCES International [#308]

Apr 8, 202645 min

Iran’s IRGC threatens U.S. tech companies, FBI Director hacked, Venom Stealer & Hasbro cyber attack / Intel Chat [#307]

Apr 6, 202623 min

S5 Ep 306Malicious geopolitical cyber activity, cyberattacks tied to conflict in Iran, open source supply chain attack & AI autonomous espionage / Intel Chat [#306]

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Since the onset of the conflict in the Gulf region, cybersecurity researchers have observed a noticeable rise in malicious cyber activity tied to geopolitical events.Unit 42 researchers are warning about an increased risk of destructive cyberattacks tied to the conflict involving Iran.The hacking group known as TeamPCP has expanded a large-scale supply chain campaign targeting widely used open source software ecosystems.In September 2025, Anthropic disclosed an incident in which a state-sponsored threat actor used an AI coding agent to conduct an autonomous cyber espionage campaign targeting 30 organizations worldwide.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Mar 30, 202635 min

S5 Ep 305What makes a strong security team? With Andrew Cook from Recon InfoSec / Defender Fridays [#305]

This week on Defender Friday we are joined by Andrew Cook, CTO of Recon InfoSec, to talk about what it means to build a strong security team and why hiring builders is always a good bet.As the CTO of Recon InfoSec, a leading provider of managed security operations, Andrew oversees the technical vision, strategy, and execution of their services and solutions. He has more than a decade of experience in threat hunting, digital forensics, network defense, and capability development.Andrew's mission is to provide customers with the expertise they need to confidently and effectively respond to incidents, protect their organizations, and enhance their resilience. He has a proven track record of delivering high-quality results, leading and mentoring teams, and collaborating with partners across the industry and the government. Andrew is also a former Air Force officer, with national-level contributions and a passion for technical leadership.Learn more at reconinfosec.comRegister for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

Mar 27, 202632 min

S5 Ep 304Bringing 40+ year old industrial security systems into the 21st century with Justin Searle from InGuardians [#304]

Justin Searle, Director of ICS Security at InGuardians, joins us today to talk about the challenges facing industrial control system security. With increased attack surface areas and maintaining and updating decades-old systems, Justin's dedication to informing and educating newcomers and experts alike is more important now than ever before.As the Director of ICS Security at InGuardians, Justin specializes in ICS security architecture design and penetration testing. He led the Smart Grid Security Architecture group in creating the NIST Interagency Report 7628 and has played key roles in the Advanced Security Acceleration Project for the Smart Grid (ASAP-SG), National Electric Sector Cybersecurity Organization Resources (NESCOR), and Smart Grid Interoperability Panel (SGIP). Justin is the owner of ControlThings LLC, a member of the SANS faculty, and an instructor at BlackHat. He has authored and taught numerous courses such as ICS410: ICS/SCADA Security Essentials, Assessing and Exploiting Control Systems and IIoT, Assessing and Exploiting Web Applications with SamuraiWTF, and SEC542: Web App Penetration Testing and Ethical Hacking. Justin also presents on a range of cybersecurity topics at leading security conferences across the globe.Learn more at: controlthings.ioSupport our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

Mar 25, 202631 min

S5 Ep 303Is it smart to have AI agents act as employees? With David Burkett from Corelight / Defender Fridays [#303]

David Burkett, Cloud Security Researcher at Corelight, is back on Defender Fridays this week to discuss thinking in pipelines for AI agents.As a dedicated and highly experienced Cloud Detection Engineer and Security Architect, David has the privilege of working at a Fortune 50 Company where he leverages his extensive background in cybersecurity to protect digital assets. With a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.David's expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. He's proud to have been part of a large overall security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. Our security operations center was recognized as being among the top 1% of cybersecurity programs for all cleared facilities.In addition to his hands-on experience, David has consulted for over 40 Fortune 500 Companies and Large Federal Organizations, helping them manage their SOAR platforms and playbooks. As a strong believer in knowledge sharing and collaboration, he's also an active contributor to the open-source detection security project known as Sigma. Learn more at https://corelight.com/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

Mar 20, 202635 min

S5 Ep 302How to think long-term growth in an AI-dominated industry with Stel Valavanis from onShore Networks [#302]

Today we're speaking with Stel Valavanis, Founder and Chairman at onShore Networks and Co-Founder at The Gallery Building, about sustaining a security company over three decades of industry changes. We also dive into investing in start ups and how founders can think long term about governance and growth.Stel has over 40 years of experience ranging from software development to network design and cybersecurity. He's founded 8 companies, invested in 10 more, and sit on various boards. His goal is to build the best tech stack for his customers but also wants to pay forward and make investments in startups, leveraging his knowledge and resources. Stel is always open to board positions and speaking engagements on cybersecurity, media technology, startup investing, and entrepreneurship.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io

Mar 19, 202638 min

S5 Ep 301Cyber Strategy for America, new targets in war in Iran, Camaro Dragon & medical manufacturer Stryker attacked / Intel Chat [#301]

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.The White House released President Trump’s Cyber Strategy for America, outlining a national framework to strengthen both defensive and offensive cybersecurity capabilities.Iran has expanded the scope of potential targets in the ongoing conflict with Israel and the United States by identifying infrastructure tied to major American technology companies in the Middle East as “legitimate targets.”Chinese-linked threat actors have launched cyberattacks against organizations in Qatar shortly after the initial US-Israel strikes on Iran, indicating a shift in regional targeting strategy.An Iranian-linked hacking group has claimed responsibility for a cyberattack on U.S.-based medical equipment manufacturer Stryker, which disrupted the company’s technology operations across its global offices.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Mar 17, 202632 min

S5 Ep 300Drones damage data centers, Iranian cyber retaliation, Sloppy Lemming & Honeywell vulnerability / Intel Chat [#300]

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Iranian drone strikes damaged three Amazon Web Services data center facilities in the Middle East, highlighting the physical risks associated with large-scale cloud infrastructure.Cyber activity linked to Iran and pro-Iranian actors has intensified following a joint US–Israeli military strike on Iran that killed Supreme Leader Ayatollah Ali Khamenei and several other government officials.The India-linked advanced persistent threat group known as “Sloppy Lemming” has significantly increased its cyber operations over the past year, targeting organizations in Pakistan, Bangladesh, and other parts of South and Southeast Asia.A cybersecurity researcher has reported a potentially serious vulnerability in Honeywell’s IQ4 building management controller, though the vendor disputes both the severity and practical impact of the issue.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Mar 9, 202635 min

S5 Ep 299Learning how to trust that AI is secure with Saurabh Shintre from Realm Labs / Defender Fridays [#299]

Saurabh Shintre, Founder and CEO of Realm Labs, is on Defender Fridays today to discuss securing AI from within.Saurabh previously led the AI security research at Splunk and Symantec. He has been at the forefront of AI security research for nearly a decade with multiple publications and patents and regularly features on public forums on issues regarding security and AI. Saurabh holds a PhD from Carnegie Mellon. Learn more at https://www.realmlabs.ai/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

Mar 9, 202630 min

S5 Ep 298North Korean malware interviews, FortiGate firewall compromised, Cisco zero-day & Citrini Research AI future / Intel Chat [#298]

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.GitLab’s Threat Intelligence Team published detailed findings on North Korean activity associated with the Contagious Interview campaign and broader IT worker operations.A financially motivated, Russian-speaking threat actor used generative AI tools to compromise more than 600 Fortinet FortiGate firewall instances between January and February, according to Amazon Web Services.Cisco has released emergency patches for a critical zero-day vulnerability in its Catalyst SD-WAN products that has been actively exploited in the wild.Citrini Research presents a forward-looking scenario framed as a June 2028 macro memo describing a “Global Intelligence Crisis” triggered by abundant AI-driven intelligence.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

Mar 3, 202642 min